mirror of
https://github.com/Sea-Haven-Industries/sh-mcp.git
synced 2026-09-30 03:03:15 +00:00
ci(deploy): switch deploy trigger from push-to-main to manual workflow_dispatch (#39)
Remove the push-to-main trigger from .github/workflows/deploy.yaml so merges no longer deploy automatically; deploys now run only via the Actions "Run workflow" button (workflow_dispatch). No job content, permissions, or reusable-workflow inputs changed. README and the auth deploy runbook updated to match.
This commit is contained in:
parent
989b726022
commit
1bfa2a85c9
3 changed files with 14 additions and 13 deletions
4
.github/workflows/deploy.yaml
vendored
4
.github/workflows/deploy.yaml
vendored
|
|
@ -1,9 +1,7 @@
|
|||
name: deploy
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
|
|
|||
|
|
@ -63,7 +63,8 @@ npx cdk deploy sh-mcp-auth \
|
|||
```
|
||||
|
||||
CI runs `npx cdk synth` at the repo root on every PR (the `ci-typescript-cdk` reusable workflow with
|
||||
`run-cdk-synth: true`); merges to `main` deploy via the `cd-cdk` reusable workflow over the
|
||||
`run-cdk-synth: true`); deploys are triggered manually (Actions → deploy → Run workflow on
|
||||
`main`, i.e. `workflow_dispatch`) via the `cd-cdk` reusable workflow over the
|
||||
per-repo `githubdeploy-sh-mcp` OIDC role. **Nothing is deployed to AWS yet** — see status above.
|
||||
|
||||
## Auth substrate (Phase 2a — `infra/` + `auth/`)
|
||||
|
|
|
|||
|
|
@ -11,11 +11,11 @@ validated."
|
|||
- **Toolchain:** aws-cdk `2.1128.1` (CLI, root devDep), aws-cdk-lib `2.260.0`, constructs `10.6.0`.
|
||||
|
||||
> **CD is already wired and currently red.** `.github/workflows/deploy.yaml`
|
||||
> (push-to-`main` → org reusable `cd-cdk.yaml@main`, OIDC) has failed on every
|
||||
> merge so far (~4s) because the `githubdeploy-sh-mcp` deploy role does not exist
|
||||
> yet (Prereq 4). Once the prerequisites below are in place, CD deploys on the
|
||||
> next push to `main`; the first deploy is done **manually** (Step 2) so a human
|
||||
> watches the initial resource creation.
|
||||
> (manual `workflow_dispatch` → org reusable `cd-cdk.yaml@main`, OIDC) has failed
|
||||
> on every run so far (~4s) because the `githubdeploy-sh-mcp` deploy role does not
|
||||
> exist yet (Prereq 4). Once the prerequisites below are in place, CD is triggered
|
||||
> manually via the Actions "Run workflow" button on `main`; the first deploy is
|
||||
> done **manually** (Step 2) so a human watches the initial resource creation.
|
||||
|
||||
---
|
||||
|
||||
|
|
@ -162,12 +162,13 @@ grants). Note the stack outputs (exported for 2b cross-stack import):
|
|||
|
||||
## Step 3 — hand off to CD
|
||||
|
||||
After the manual first deploy succeeds and Prereq 4 is in place, every push to
|
||||
`main` deploys via `.github/workflows/deploy.yaml`. Re-run the last failed deploy
|
||||
After the manual first deploy succeeds and Prereq 4 is in place, deploys are
|
||||
triggered manually via `.github/workflows/deploy.yaml` (Actions → deploy → Run
|
||||
workflow on `main`, i.e. `workflow_dispatch`). Re-run the last failed deploy
|
||||
to confirm it now goes green:
|
||||
|
||||
```bash
|
||||
gh workflow run deploy.yaml --ref main # or push any commit to main
|
||||
gh workflow run deploy.yaml --ref main
|
||||
gh run watch $(gh run list --workflow=deploy.yaml --limit 1 --json databaseId --jq '.[0].databaseId')
|
||||
```
|
||||
|
||||
|
|
@ -221,7 +222,8 @@ aws dynamodb delete-item --table-name sh-mcp-deny-list --region us-east-1 \
|
|||
a later redeploy re-adopts them). Delete the tables manually only if you intend
|
||||
to lose revocation/freshness state.
|
||||
- A bad deploy rolls back automatically (CloudFormation). To revert code, revert
|
||||
the commit on `main`; CD redeploys the prior template.
|
||||
the commit on `main`, then run the deploy workflow manually (Actions → deploy →
|
||||
Run workflow) to redeploy the prior template.
|
||||
- **0a spike teardown is the LAST step, not part of this deploy.** The live 0a
|
||||
spike kit (Cognito pool `us-east-1_GsDbGe0pa`, probe Lambda/API, the SF
|
||||
`sh_mcp_0a` objects) stays up until `sh-mcp-auth` is deployed **and validated**
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue