mirror of
https://github.com/Sea-Haven-Industries/sh-openswe-traces.git
synced 2026-09-30 16:13:17 +00:00
Storage-only SAM stack (S3 + KMS CMK + write-only IAM writer + Secrets Manager holder) as the S3 destination for LangSmith Bulk Export of Open SWE traces, for long-horizon auditing and prompt improvement (Athena over Parquet). - template.yaml: versioned SSE-KMS bucket, access-log bucket, TLS-only policy, DEEP_ARCHIVE lifecycle; least-privilege LangSmith writer (bucket-wide PutObject, ViaService-scoped KMS, no read/delete). - bootstrap.yaml: dedicated OIDC deploy role + least-privilege CFN exec role so CI never touches the shared execution role. - CI/CD via reusable ci-python-sam / cd-sam workflows. IAM passed GPT-4.1 cross-review + /sh-security-review (no blocking findings).
22 lines
553 B
YAML
22 lines
553 B
YAML
name: Deploy
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: deploy
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
deploy:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
|
with:
|
|
stack-name: sh-openswe-traces
|
|
cfn-role-arn: arn:aws:iam::328440206208:role/sh-openswe-traces-cfn-exec-role
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
|
parameter-overrides: ${{ secrets.SAM_PARAMETER_OVERRIDES }}
|