diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index 32ca7b2..4278cf7 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -1,9 +1,7 @@ name: deploy on: - push: - branches: - - main + workflow_dispatch: permissions: contents: read diff --git a/README.md b/README.md index c3abd3a..6ed4028 100644 --- a/README.md +++ b/README.md @@ -63,7 +63,8 @@ npx cdk deploy sh-mcp-auth \ ``` CI runs `npx cdk synth` at the repo root on every PR (the `ci-typescript-cdk` reusable workflow with -`run-cdk-synth: true`); merges to `main` deploy via the `cd-cdk` reusable workflow over the +`run-cdk-synth: true`); deploys are triggered manually (Actions → deploy → Run workflow on +`main`, i.e. `workflow_dispatch`) via the `cd-cdk` reusable workflow over the per-repo `githubdeploy-sh-mcp` OIDC role. **Nothing is deployed to AWS yet** — see status above. ## Auth substrate (Phase 2a — `infra/` + `auth/`) diff --git a/docs/runbook-auth-deploy.md b/docs/runbook-auth-deploy.md index b5cc4b8..9ffe486 100644 --- a/docs/runbook-auth-deploy.md +++ b/docs/runbook-auth-deploy.md @@ -11,11 +11,11 @@ validated." - **Toolchain:** aws-cdk `2.1128.1` (CLI, root devDep), aws-cdk-lib `2.260.0`, constructs `10.6.0`. > **CD is already wired and currently red.** `.github/workflows/deploy.yaml` -> (push-to-`main` → org reusable `cd-cdk.yaml@main`, OIDC) has failed on every -> merge so far (~4s) because the `githubdeploy-sh-mcp` deploy role does not exist -> yet (Prereq 4). Once the prerequisites below are in place, CD deploys on the -> next push to `main`; the first deploy is done **manually** (Step 2) so a human -> watches the initial resource creation. +> (manual `workflow_dispatch` → org reusable `cd-cdk.yaml@main`, OIDC) has failed +> on every run so far (~4s) because the `githubdeploy-sh-mcp` deploy role does not +> exist yet (Prereq 4). Once the prerequisites below are in place, CD is triggered +> manually via the Actions "Run workflow" button on `main`; the first deploy is +> done **manually** (Step 2) so a human watches the initial resource creation. --- @@ -162,12 +162,13 @@ grants). Note the stack outputs (exported for 2b cross-stack import): ## Step 3 — hand off to CD -After the manual first deploy succeeds and Prereq 4 is in place, every push to -`main` deploys via `.github/workflows/deploy.yaml`. Re-run the last failed deploy +After the manual first deploy succeeds and Prereq 4 is in place, deploys are +triggered manually via `.github/workflows/deploy.yaml` (Actions → deploy → Run +workflow on `main`, i.e. `workflow_dispatch`). Re-run the last failed deploy to confirm it now goes green: ```bash -gh workflow run deploy.yaml --ref main # or push any commit to main +gh workflow run deploy.yaml --ref main gh run watch $(gh run list --workflow=deploy.yaml --limit 1 --json databaseId --jq '.[0].databaseId') ``` @@ -221,7 +222,8 @@ aws dynamodb delete-item --table-name sh-mcp-deny-list --region us-east-1 \ a later redeploy re-adopts them). Delete the tables manually only if you intend to lose revocation/freshness state. - A bad deploy rolls back automatically (CloudFormation). To revert code, revert - the commit on `main`; CD redeploys the prior template. + the commit on `main`, then run the deploy workflow manually (Actions → deploy → + Run workflow) to redeploy the prior template. - **0a spike teardown is the LAST step, not part of this deploy.** The live 0a spike kit (Cognito pool `us-east-1_GsDbGe0pa`, probe Lambda/API, the SF `sh_mcp_0a` objects) stays up until `sh-mcp-auth` is deployed **and validated**