fix(cd): honor reusable workflow inputs when resolving deploy target

This commit is contained in:
Adam Moussa 2026-09-18 11:33:34 -04:00
parent 7eaa7fb3f9
commit 396b1c690b
No known key found for this signature in database
2 changed files with 27 additions and 20 deletions

View file

@ -58,11 +58,14 @@ jobs:
GITHUB_SHA_IN: ${{ github.sha }} GITHUB_SHA_IN: ${{ github.sha }}
run: | run: |
set -euo pipefail set -euo pipefail
case "${EVENT_NAME}" in # A called reusable workflow keeps the caller's github.event_name
workflow_call) # (push or workflow_dispatch), not workflow_call. Prefer the call
# inputs whenever they are set.
if [ -n "${CALL_ENVIRONMENT}" ]; then
environment="${CALL_ENVIRONMENT}" environment="${CALL_ENVIRONMENT}"
ref="${CALL_REF}" ref="${CALL_REF:-${GITHUB_SHA_IN}}"
;; else
case "${EVENT_NAME}" in
workflow_dispatch) workflow_dispatch)
environment="${INPUT_ENVIRONMENT}" environment="${INPUT_ENVIRONMENT}"
ref="${INPUT_REF:-${GITHUB_SHA_IN}}" ref="${INPUT_REF:-${GITHUB_SHA_IN}}"
@ -76,6 +79,7 @@ jobs:
exit 1 exit 1
;; ;;
esac esac
fi
case "${environment}" in case "${environment}" in
dev|staging|prod) ;; dev|staging|prod) ;;
*) *)

View file

@ -183,8 +183,11 @@ the same way as an empty allowlist.
branch. branch.
Do not create the `prod` environment yet. Leave `PROD_APP_CD_ENABLED` Do not create the `prod` environment yet. Leave `PROD_APP_CD_ENABLED`
unset. Do not run Actions → Release with `environment=prod`; the first unset. Until the `prod` environment exists with reviewers, do not run
prod dispatch would auto-create an unprotected environment. Actions → Release with `environment=prod`, do not push a bare `vX.Y.Z`
tag, and do not `workflow_dispatch` deploy with `environment=prod`. Any
of those declares `environment: prod` and would auto-create an
unprotected environment.
## Pinned live identities ## Pinned live identities