fix(cd): honor reusable workflow inputs when resolving deploy target

This commit is contained in:
Adam Moussa 2026-09-18 11:33:34 -04:00
parent 7eaa7fb3f9
commit 396b1c690b
No known key found for this signature in database
2 changed files with 27 additions and 20 deletions

View file

@ -58,24 +58,28 @@ jobs:
GITHUB_SHA_IN: ${{ github.sha }}
run: |
set -euo pipefail
case "${EVENT_NAME}" in
workflow_call)
environment="${CALL_ENVIRONMENT}"
ref="${CALL_REF}"
;;
workflow_dispatch)
environment="${INPUT_ENVIRONMENT}"
ref="${INPUT_REF:-${GITHUB_SHA_IN}}"
;;
push)
environment=dev
ref="${GITHUB_SHA_IN}"
;;
*)
echo "unsupported event ${EVENT_NAME}" >&2
exit 1
;;
esac
# A called reusable workflow keeps the caller's github.event_name
# (push or workflow_dispatch), not workflow_call. Prefer the call
# inputs whenever they are set.
if [ -n "${CALL_ENVIRONMENT}" ]; then
environment="${CALL_ENVIRONMENT}"
ref="${CALL_REF:-${GITHUB_SHA_IN}}"
else
case "${EVENT_NAME}" in
workflow_dispatch)
environment="${INPUT_ENVIRONMENT}"
ref="${INPUT_REF:-${GITHUB_SHA_IN}}"
;;
push)
environment=dev
ref="${GITHUB_SHA_IN}"
;;
*)
echo "unsupported event ${EVENT_NAME}" >&2
exit 1
;;
esac
fi
case "${environment}" in
dev|staging|prod) ;;
*)

View file

@ -183,8 +183,11 @@ the same way as an empty allowlist.
branch.
Do not create the `prod` environment yet. Leave `PROD_APP_CD_ENABLED`
unset. Do not run Actions → Release with `environment=prod`; the first
prod dispatch would auto-create an unprotected environment.
unset. Until the `prod` environment exists with reviewers, do not run
Actions → Release with `environment=prod`, do not push a bare `vX.Y.Z`
tag, and do not `workflow_dispatch` deploy with `environment=prod`. Any
of those declares `environment: prod` and would auto-create an
unprotected environment.
## Pinned live identities