Add GitHub Actions deploy workflow #28
1 changed files with 18 additions and 0 deletions
18
.github/workflows/deploy.yaml
vendored
Normal file
18
.github/workflows/deploy.yaml
vendored
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
name: Deploy
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: deploy
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
|
|
||||
Reference in a new issue
Missing OIDC permission blocks deploy workflow
High Severity
This OIDC-based deploy workflow is missing the
permissionsblock withid-token: write. GitHub Actions does not grant theid-tokenpermission by default — it must be explicitly declared in the caller workflow. Without it, the reusablecd-cdk.yamlworkflow cannot request the JWT needed to assume the AWS deploy role, and every deployment will fail.Reviewed by Cursor Bugbot for commit
0302e6b021. Configure here.