diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index caa1eee..33b4b2c 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -3,8 +3,6 @@ name: Validate and deploy on: pull_request: branches: [dev, staging, main] - push: - branches: [main] workflow_dispatch: permissions: @@ -68,27 +66,58 @@ jobs: deploy: name: Deploy shoc-backend to Elastic Beanstalk if: > - github.event_name == 'push' || - (github.event_name == 'workflow_dispatch' && - github.ref == 'refs/heads/main') + github.event_name == 'workflow_dispatch' && + contains(fromJSON('["refs/heads/dev","refs/heads/staging","refs/heads/main"]'), github.ref) needs: validate runs-on: ubuntu-latest permissions: contents: read id-token: write environment: - name: prod + name: ${{ github.ref_name == 'main' && 'prod' || github.ref_name }} concurrency: - group: deploy-prod + group: deploy-${{ github.ref_name == 'main' && 'prod' || github.ref_name }} cancel-in-progress: false - env: - EB_APPLICATION_NAME: shoc-backend - EB_ENVIRONMENT_NAME: shoc-backend-prod - SMOKE_URL: https://api.seahaven.com steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Resolve deploy target + id: target + run: | + set -euo pipefail + case "${GITHUB_REF_NAME}" in + dev) + application=shoc-backend + environment=shoc-backend-dev + smoke_url=https://api.dev.seahaven.com + ;; + staging) + application=shoc-backend + environment=shoc-backend-staging + smoke_url=https://api.staging.seahaven.com + ;; + main) + application=shoc-backend + environment=shoc-backend-prod + smoke_url=https://api.seahaven.com + ;; + *) + echo "Unsupported ref ${GITHUB_REF_NAME}" >&2 + exit 1 + ;; + esac + { + echo "application=${application}" + echo "environment=${environment}" + echo "smoke_url=${smoke_url}" + } >> "${GITHUB_OUTPUT}" + { + echo "EB_APPLICATION_NAME=${application}" + echo "EB_ENVIRONMENT_NAME=${environment}" + echo "SMOKE_URL=${smoke_url}" + } >> "${GITHUB_ENV}" + - name: Set up .NET uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 with: @@ -119,8 +148,8 @@ jobs: uses: aws-actions/aws-elasticbeanstalk-deploy@7883cdd454c162051bf6fc13389536b045149b4c # v1.0.8 with: aws-region: us-east-1 - application-name: ${{ env.EB_APPLICATION_NAME }} - environment-name: ${{ env.EB_ENVIRONMENT_NAME }} + application-name: ${{ steps.target.outputs.application }} + environment-name: ${{ steps.target.outputs.environment }} version-label: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }} deployment-package-path: .artifacts/elastic-beanstalk/site.zip s3-bucket-name: elasticbeanstalk-us-east-1-396287094661 diff --git a/infra/cdk/README.md b/infra/cdk/README.md index fec30c6..8c77048 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -4,9 +4,10 @@ The existing `shoc-backend-deploy-dev` stack owns exactly one thing in the `shoc-backend` AWS account (`396287094661`, `us-east-1`): the retained GitHub -OIDC deploy role for dev. Automated and manual dev deployments are disabled -while Terraform adoption proceeds. The CDK stack remains until the role's -CloudFormation ownership transfer completes. +OIDC deploy role for dev. Automatic deployments are disabled while Terraform +adoption proceeds; dev, staging, and prod releases require an explicit +`workflow_dispatch` from the matching branch. The CDK stack remains until the +role's CloudFormation ownership transfer completes. ## Ownership boundary (deliberate)