From 396b1c690bfbc776ece47d5a609e48ffccbc860d Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 18 Sep 2026 11:33:34 -0400 Subject: [PATCH] fix(cd): honor reusable workflow inputs when resolving deploy target --- .github/workflows/deploy.yaml | 40 +++++++++++++++++++---------------- terraform/live/README.md | 7 ++++-- 2 files changed, 27 insertions(+), 20 deletions(-) diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index 59791dc..7ff766e 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -58,24 +58,28 @@ jobs: GITHUB_SHA_IN: ${{ github.sha }} run: | set -euo pipefail - case "${EVENT_NAME}" in - workflow_call) - environment="${CALL_ENVIRONMENT}" - ref="${CALL_REF}" - ;; - workflow_dispatch) - environment="${INPUT_ENVIRONMENT}" - ref="${INPUT_REF:-${GITHUB_SHA_IN}}" - ;; - push) - environment=dev - ref="${GITHUB_SHA_IN}" - ;; - *) - echo "unsupported event ${EVENT_NAME}" >&2 - exit 1 - ;; - esac + # A called reusable workflow keeps the caller's github.event_name + # (push or workflow_dispatch), not workflow_call. Prefer the call + # inputs whenever they are set. + if [ -n "${CALL_ENVIRONMENT}" ]; then + environment="${CALL_ENVIRONMENT}" + ref="${CALL_REF:-${GITHUB_SHA_IN}}" + else + case "${EVENT_NAME}" in + workflow_dispatch) + environment="${INPUT_ENVIRONMENT}" + ref="${INPUT_REF:-${GITHUB_SHA_IN}}" + ;; + push) + environment=dev + ref="${GITHUB_SHA_IN}" + ;; + *) + echo "unsupported event ${EVENT_NAME}" >&2 + exit 1 + ;; + esac + fi case "${environment}" in dev|staging|prod) ;; *) diff --git a/terraform/live/README.md b/terraform/live/README.md index 0c78f8f..a1bbdf4 100644 --- a/terraform/live/README.md +++ b/terraform/live/README.md @@ -183,8 +183,11 @@ the same way as an empty allowlist. branch. Do not create the `prod` environment yet. Leave `PROD_APP_CD_ENABLED` -unset. Do not run Actions → Release with `environment=prod`; the first -prod dispatch would auto-create an unprotected environment. +unset. Until the `prod` environment exists with reviewers, do not run +Actions → Release with `environment=prod`, do not push a bare `vX.Y.Z` +tag, and do not `workflow_dispatch` deploy with `environment=prod`. Any +of those declares `environment: prod` and would auto-create an +unprotected environment. ## Pinned live identities