mirror of
https://github.com/Sea-Haven-Industries/sh-mcp.git
synced 2026-09-30 03:03:15 +00:00
ci(deploy): switch deploy trigger from push-to-main to manual workflow_dispatch (#39)
Remove the push-to-main trigger from .github/workflows/deploy.yaml so merges no longer deploy automatically; deploys now run only via the Actions "Run workflow" button (workflow_dispatch). No job content, permissions, or reusable-workflow inputs changed. README and the auth deploy runbook updated to match.
This commit is contained in:
parent
989b726022
commit
1bfa2a85c9
3 changed files with 14 additions and 13 deletions
4
.github/workflows/deploy.yaml
vendored
4
.github/workflows/deploy.yaml
vendored
|
|
@ -1,9 +1,7 @@
|
||||||
name: deploy
|
name: deploy
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
workflow_dispatch:
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
|
|
||||||
|
|
@ -63,7 +63,8 @@ npx cdk deploy sh-mcp-auth \
|
||||||
```
|
```
|
||||||
|
|
||||||
CI runs `npx cdk synth` at the repo root on every PR (the `ci-typescript-cdk` reusable workflow with
|
CI runs `npx cdk synth` at the repo root on every PR (the `ci-typescript-cdk` reusable workflow with
|
||||||
`run-cdk-synth: true`); merges to `main` deploy via the `cd-cdk` reusable workflow over the
|
`run-cdk-synth: true`); deploys are triggered manually (Actions → deploy → Run workflow on
|
||||||
|
`main`, i.e. `workflow_dispatch`) via the `cd-cdk` reusable workflow over the
|
||||||
per-repo `githubdeploy-sh-mcp` OIDC role. **Nothing is deployed to AWS yet** — see status above.
|
per-repo `githubdeploy-sh-mcp` OIDC role. **Nothing is deployed to AWS yet** — see status above.
|
||||||
|
|
||||||
## Auth substrate (Phase 2a — `infra/` + `auth/`)
|
## Auth substrate (Phase 2a — `infra/` + `auth/`)
|
||||||
|
|
|
||||||
|
|
@ -11,11 +11,11 @@ validated."
|
||||||
- **Toolchain:** aws-cdk `2.1128.1` (CLI, root devDep), aws-cdk-lib `2.260.0`, constructs `10.6.0`.
|
- **Toolchain:** aws-cdk `2.1128.1` (CLI, root devDep), aws-cdk-lib `2.260.0`, constructs `10.6.0`.
|
||||||
|
|
||||||
> **CD is already wired and currently red.** `.github/workflows/deploy.yaml`
|
> **CD is already wired and currently red.** `.github/workflows/deploy.yaml`
|
||||||
> (push-to-`main` → org reusable `cd-cdk.yaml@main`, OIDC) has failed on every
|
> (manual `workflow_dispatch` → org reusable `cd-cdk.yaml@main`, OIDC) has failed
|
||||||
> merge so far (~4s) because the `githubdeploy-sh-mcp` deploy role does not exist
|
> on every run so far (~4s) because the `githubdeploy-sh-mcp` deploy role does not
|
||||||
> yet (Prereq 4). Once the prerequisites below are in place, CD deploys on the
|
> exist yet (Prereq 4). Once the prerequisites below are in place, CD is triggered
|
||||||
> next push to `main`; the first deploy is done **manually** (Step 2) so a human
|
> manually via the Actions "Run workflow" button on `main`; the first deploy is
|
||||||
> watches the initial resource creation.
|
> done **manually** (Step 2) so a human watches the initial resource creation.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -162,12 +162,13 @@ grants). Note the stack outputs (exported for 2b cross-stack import):
|
||||||
|
|
||||||
## Step 3 — hand off to CD
|
## Step 3 — hand off to CD
|
||||||
|
|
||||||
After the manual first deploy succeeds and Prereq 4 is in place, every push to
|
After the manual first deploy succeeds and Prereq 4 is in place, deploys are
|
||||||
`main` deploys via `.github/workflows/deploy.yaml`. Re-run the last failed deploy
|
triggered manually via `.github/workflows/deploy.yaml` (Actions → deploy → Run
|
||||||
|
workflow on `main`, i.e. `workflow_dispatch`). Re-run the last failed deploy
|
||||||
to confirm it now goes green:
|
to confirm it now goes green:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
gh workflow run deploy.yaml --ref main # or push any commit to main
|
gh workflow run deploy.yaml --ref main
|
||||||
gh run watch $(gh run list --workflow=deploy.yaml --limit 1 --json databaseId --jq '.[0].databaseId')
|
gh run watch $(gh run list --workflow=deploy.yaml --limit 1 --json databaseId --jq '.[0].databaseId')
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
@ -221,7 +222,8 @@ aws dynamodb delete-item --table-name sh-mcp-deny-list --region us-east-1 \
|
||||||
a later redeploy re-adopts them). Delete the tables manually only if you intend
|
a later redeploy re-adopts them). Delete the tables manually only if you intend
|
||||||
to lose revocation/freshness state.
|
to lose revocation/freshness state.
|
||||||
- A bad deploy rolls back automatically (CloudFormation). To revert code, revert
|
- A bad deploy rolls back automatically (CloudFormation). To revert code, revert
|
||||||
the commit on `main`; CD redeploys the prior template.
|
the commit on `main`, then run the deploy workflow manually (Actions → deploy →
|
||||||
|
Run workflow) to redeploy the prior template.
|
||||||
- **0a spike teardown is the LAST step, not part of this deploy.** The live 0a
|
- **0a spike teardown is the LAST step, not part of this deploy.** The live 0a
|
||||||
spike kit (Cognito pool `us-east-1_GsDbGe0pa`, probe Lambda/API, the SF
|
spike kit (Cognito pool `us-east-1_GsDbGe0pa`, probe Lambda/API, the SF
|
||||||
`sh_mcp_0a` objects) stays up until `sh-mcp-auth` is deployed **and validated**
|
`sh_mcp_0a` objects) stays up until `sh-mcp-auth` is deployed **and validated**
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue