ci(deploy): switch deploy trigger from push-to-main to manual workflow_dispatch (#39)

Remove the push-to-main trigger from .github/workflows/deploy.yaml so merges
no longer deploy automatically; deploys now run only via the Actions "Run
workflow" button (workflow_dispatch). No job content, permissions, or
reusable-workflow inputs changed. README and the auth deploy runbook updated
to match.
This commit is contained in:
Adam Moussa 2026-07-28 12:29:49 -04:00 • committed by GitHub
parent 989b726022
commit 1bfa2a85c9
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 14 additions and 13 deletions

View file

@ -1,9 +1,7 @@
name: deploy name: deploy
on: on:
push: workflow_dispatch:
branches:
- main
permissions: permissions:
contents: read contents: read

View file

@ -63,7 +63,8 @@ npx cdk deploy sh-mcp-auth \
``` ```
CI runs `npx cdk synth` at the repo root on every PR (the `ci-typescript-cdk` reusable workflow with CI runs `npx cdk synth` at the repo root on every PR (the `ci-typescript-cdk` reusable workflow with
`run-cdk-synth: true`); merges to `main` deploy via the `cd-cdk` reusable workflow over the `run-cdk-synth: true`); deploys are triggered manually (Actions → deploy → Run workflow on
`main`, i.e. `workflow_dispatch`) via the `cd-cdk` reusable workflow over the
per-repo `githubdeploy-sh-mcp` OIDC role. **Nothing is deployed to AWS yet** — see status above. per-repo `githubdeploy-sh-mcp` OIDC role. **Nothing is deployed to AWS yet** — see status above.
## Auth substrate (Phase 2a — `infra/` + `auth/`) ## Auth substrate (Phase 2a — `infra/` + `auth/`)

View file

@ -11,11 +11,11 @@ validated."
- **Toolchain:** aws-cdk `2.1128.1` (CLI, root devDep), aws-cdk-lib `2.260.0`, constructs `10.6.0`. - **Toolchain:** aws-cdk `2.1128.1` (CLI, root devDep), aws-cdk-lib `2.260.0`, constructs `10.6.0`.
> **CD is already wired and currently red.** `.github/workflows/deploy.yaml` > **CD is already wired and currently red.** `.github/workflows/deploy.yaml`
> (push-to-`main` → org reusable `cd-cdk.yaml@main`, OIDC) has failed on every > (manual `workflow_dispatch` → org reusable `cd-cdk.yaml@main`, OIDC) has failed
> merge so far (~4s) because the `githubdeploy-sh-mcp` deploy role does not exist > on every run so far (~4s) because the `githubdeploy-sh-mcp` deploy role does not
> yet (Prereq 4). Once the prerequisites below are in place, CD deploys on the > exist yet (Prereq 4). Once the prerequisites below are in place, CD is triggered
> next push to `main`; the first deploy is done **manually** (Step 2) so a human > manually via the Actions "Run workflow" button on `main`; the first deploy is
> watches the initial resource creation. > done **manually** (Step 2) so a human watches the initial resource creation.
--- ---
@ -162,12 +162,13 @@ grants). Note the stack outputs (exported for 2b cross-stack import):
## Step 3 — hand off to CD ## Step 3 — hand off to CD
After the manual first deploy succeeds and Prereq 4 is in place, every push to After the manual first deploy succeeds and Prereq 4 is in place, deploys are
`main` deploys via `.github/workflows/deploy.yaml`. Re-run the last failed deploy triggered manually via `.github/workflows/deploy.yaml` (Actions → deploy → Run
workflow on `main`, i.e. `workflow_dispatch`). Re-run the last failed deploy
to confirm it now goes green: to confirm it now goes green:
```bash ```bash
gh workflow run deploy.yaml --ref main # or push any commit to main gh workflow run deploy.yaml --ref main
gh run watch $(gh run list --workflow=deploy.yaml --limit 1 --json databaseId --jq '.[0].databaseId') gh run watch $(gh run list --workflow=deploy.yaml --limit 1 --json databaseId --jq '.[0].databaseId')
``` ```
@ -221,7 +222,8 @@ aws dynamodb delete-item --table-name sh-mcp-deny-list --region us-east-1 \
a later redeploy re-adopts them). Delete the tables manually only if you intend a later redeploy re-adopts them). Delete the tables manually only if you intend
to lose revocation/freshness state. to lose revocation/freshness state.
- A bad deploy rolls back automatically (CloudFormation). To revert code, revert - A bad deploy rolls back automatically (CloudFormation). To revert code, revert
the commit on `main`; CD redeploys the prior template. the commit on `main`, then run the deploy workflow manually (Actions → deploy →
Run workflow) to redeploy the prior template.
- **0a spike teardown is the LAST step, not part of this deploy.** The live 0a - **0a spike teardown is the LAST step, not part of this deploy.** The live 0a
spike kit (Cognito pool `us-east-1_GsDbGe0pa`, probe Lambda/API, the SF spike kit (Cognito pool `us-east-1_GsDbGe0pa`, probe Lambda/API, the SF
`sh_mcp_0a` objects) stays up until `sh-mcp-auth` is deployed **and validated** `sh_mcp_0a` objects) stays up until `sh-mcp-auth` is deployed **and validated**