ci(deploy): require manual environment dispatch

This commit is contained in:
Adam Moussa 2026-08-30 17:33:35 -04:00
parent 874b568642
commit 67f21b623a
2 changed files with 46 additions and 16 deletions

View file

@ -3,8 +3,6 @@ name: Validate and deploy
on:
pull_request:
branches: [dev, staging, main]
push:
branches: [main]
workflow_dispatch:
permissions:
@ -68,27 +66,58 @@ jobs:
deploy:
name: Deploy shoc-backend to Elastic Beanstalk
if: >
github.event_name == 'push' ||
(github.event_name == 'workflow_dispatch' &&
github.ref == 'refs/heads/main')
github.event_name == 'workflow_dispatch' &&
contains(fromJSON('["refs/heads/dev","refs/heads/staging","refs/heads/main"]'), github.ref)
needs: validate
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
environment:
name: prod
name: ${{ github.ref_name == 'main' && 'prod' || github.ref_name }}
concurrency:
group: deploy-prod
group: deploy-${{ github.ref_name == 'main' && 'prod' || github.ref_name }}
cancel-in-progress: false
env:
EB_APPLICATION_NAME: shoc-backend
EB_ENVIRONMENT_NAME: shoc-backend-prod
SMOKE_URL: https://api.seahaven.com
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Resolve deploy target
id: target
run: |
set -euo pipefail
case "${GITHUB_REF_NAME}" in
dev)
application=shoc-backend
environment=shoc-backend-dev
smoke_url=https://api.dev.seahaven.com
;;
staging)
application=shoc-backend
environment=shoc-backend-staging
smoke_url=https://api.staging.seahaven.com
;;
main)
application=shoc-backend
environment=shoc-backend-prod
smoke_url=https://api.seahaven.com
;;
*)
echo "Unsupported ref ${GITHUB_REF_NAME}" >&2
exit 1
;;
esac
{
echo "application=${application}"
echo "environment=${environment}"
echo "smoke_url=${smoke_url}"
} >> "${GITHUB_OUTPUT}"
{
echo "EB_APPLICATION_NAME=${application}"
echo "EB_ENVIRONMENT_NAME=${environment}"
echo "SMOKE_URL=${smoke_url}"
} >> "${GITHUB_ENV}"
- name: Set up .NET
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
@ -119,8 +148,8 @@ jobs:
uses: aws-actions/aws-elasticbeanstalk-deploy@7883cdd454c162051bf6fc13389536b045149b4c # v1.0.8
with:
aws-region: us-east-1
application-name: ${{ env.EB_APPLICATION_NAME }}
environment-name: ${{ env.EB_ENVIRONMENT_NAME }}
application-name: ${{ steps.target.outputs.application }}
environment-name: ${{ steps.target.outputs.environment }}
version-label: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
deployment-package-path: .artifacts/elastic-beanstalk/site.zip
s3-bucket-name: elasticbeanstalk-us-east-1-396287094661

View file

@ -4,9 +4,10 @@
The existing `shoc-backend-deploy-dev` stack owns exactly one thing in the
`shoc-backend` AWS account (`396287094661`, `us-east-1`): the retained GitHub
OIDC deploy role for dev. Automated and manual dev deployments are disabled
while Terraform adoption proceeds. The CDK stack remains until the role's
CloudFormation ownership transfer completes.
OIDC deploy role for dev. Automatic deployments are disabled while Terraform
adoption proceeds; dev, staging, and prod releases require an explicit
`workflow_dispatch` from the matching branch. The CDK stack remains until the
role's CloudFormation ownership transfer completes.
## Ownership boundary (deliberate)