fix(cd): honor reusable workflow inputs when resolving deploy target

This commit is contained in:
Adam Moussa 2026-09-18 11:33:34 -04:00
parent 7eaa7fb3f9
commit 396b1c690b
No known key found for this signature in database
2 changed files with 27 additions and 20 deletions

View file

@ -58,24 +58,28 @@ jobs:
GITHUB_SHA_IN: ${{ github.sha }} GITHUB_SHA_IN: ${{ github.sha }}
run: | run: |
set -euo pipefail set -euo pipefail
case "${EVENT_NAME}" in # A called reusable workflow keeps the caller's github.event_name
workflow_call) # (push or workflow_dispatch), not workflow_call. Prefer the call
environment="${CALL_ENVIRONMENT}" # inputs whenever they are set.
ref="${CALL_REF}" if [ -n "${CALL_ENVIRONMENT}" ]; then
;; environment="${CALL_ENVIRONMENT}"
workflow_dispatch) ref="${CALL_REF:-${GITHUB_SHA_IN}}"
environment="${INPUT_ENVIRONMENT}" else
ref="${INPUT_REF:-${GITHUB_SHA_IN}}" case "${EVENT_NAME}" in
;; workflow_dispatch)
push) environment="${INPUT_ENVIRONMENT}"
environment=dev ref="${INPUT_REF:-${GITHUB_SHA_IN}}"
ref="${GITHUB_SHA_IN}" ;;
;; push)
*) environment=dev
echo "unsupported event ${EVENT_NAME}" >&2 ref="${GITHUB_SHA_IN}"
exit 1 ;;
;; *)
esac echo "unsupported event ${EVENT_NAME}" >&2
exit 1
;;
esac
fi
case "${environment}" in case "${environment}" in
dev|staging|prod) ;; dev|staging|prod) ;;
*) *)

View file

@ -183,8 +183,11 @@ the same way as an empty allowlist.
branch. branch.
Do not create the `prod` environment yet. Leave `PROD_APP_CD_ENABLED` Do not create the `prod` environment yet. Leave `PROD_APP_CD_ENABLED`
unset. Do not run Actions → Release with `environment=prod`; the first unset. Until the `prod` environment exists with reviewers, do not run
prod dispatch would auto-create an unprotected environment. Actions → Release with `environment=prod`, do not push a bare `vX.Y.Z`
tag, and do not `workflow_dispatch` deploy with `environment=prod`. Any
of those declares `environment: prod` and would auto-create an
unprotected environment.
## Pinned live identities ## Pinned live identities