mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-03 16:43:28 +00:00
ci(deploy): require manual environment dispatch
This commit is contained in:
parent
874b568642
commit
67f21b623a
2 changed files with 46 additions and 16 deletions
55
.github/workflows/deploy.yml
vendored
55
.github/workflows/deploy.yml
vendored
|
|
@ -3,8 +3,6 @@ name: Validate and deploy
|
||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
branches: [dev, staging, main]
|
branches: [dev, staging, main]
|
||||||
push:
|
|
||||||
branches: [main]
|
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
|
|
@ -68,27 +66,58 @@ jobs:
|
||||||
deploy:
|
deploy:
|
||||||
name: Deploy shoc-backend to Elastic Beanstalk
|
name: Deploy shoc-backend to Elastic Beanstalk
|
||||||
if: >
|
if: >
|
||||||
github.event_name == 'push' ||
|
github.event_name == 'workflow_dispatch' &&
|
||||||
(github.event_name == 'workflow_dispatch' &&
|
contains(fromJSON('["refs/heads/dev","refs/heads/staging","refs/heads/main"]'), github.ref)
|
||||||
github.ref == 'refs/heads/main')
|
|
||||||
needs: validate
|
needs: validate
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
id-token: write
|
id-token: write
|
||||||
environment:
|
environment:
|
||||||
name: prod
|
name: ${{ github.ref_name == 'main' && 'prod' || github.ref_name }}
|
||||||
concurrency:
|
concurrency:
|
||||||
group: deploy-prod
|
group: deploy-${{ github.ref_name == 'main' && 'prod' || github.ref_name }}
|
||||||
cancel-in-progress: false
|
cancel-in-progress: false
|
||||||
env:
|
|
||||||
EB_APPLICATION_NAME: shoc-backend
|
|
||||||
EB_ENVIRONMENT_NAME: shoc-backend-prod
|
|
||||||
SMOKE_URL: https://api.seahaven.com
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
|
|
||||||
|
- name: Resolve deploy target
|
||||||
|
id: target
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
dev)
|
||||||
|
application=shoc-backend
|
||||||
|
environment=shoc-backend-dev
|
||||||
|
smoke_url=https://api.dev.seahaven.com
|
||||||
|
;;
|
||||||
|
staging)
|
||||||
|
application=shoc-backend
|
||||||
|
environment=shoc-backend-staging
|
||||||
|
smoke_url=https://api.staging.seahaven.com
|
||||||
|
;;
|
||||||
|
main)
|
||||||
|
application=shoc-backend
|
||||||
|
environment=shoc-backend-prod
|
||||||
|
smoke_url=https://api.seahaven.com
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo "Unsupported ref ${GITHUB_REF_NAME}" >&2
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
{
|
||||||
|
echo "application=${application}"
|
||||||
|
echo "environment=${environment}"
|
||||||
|
echo "smoke_url=${smoke_url}"
|
||||||
|
} >> "${GITHUB_OUTPUT}"
|
||||||
|
{
|
||||||
|
echo "EB_APPLICATION_NAME=${application}"
|
||||||
|
echo "EB_ENVIRONMENT_NAME=${environment}"
|
||||||
|
echo "SMOKE_URL=${smoke_url}"
|
||||||
|
} >> "${GITHUB_ENV}"
|
||||||
|
|
||||||
- name: Set up .NET
|
- name: Set up .NET
|
||||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||||
with:
|
with:
|
||||||
|
|
@ -119,8 +148,8 @@ jobs:
|
||||||
uses: aws-actions/aws-elasticbeanstalk-deploy@7883cdd454c162051bf6fc13389536b045149b4c # v1.0.8
|
uses: aws-actions/aws-elasticbeanstalk-deploy@7883cdd454c162051bf6fc13389536b045149b4c # v1.0.8
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-1
|
aws-region: us-east-1
|
||||||
application-name: ${{ env.EB_APPLICATION_NAME }}
|
application-name: ${{ steps.target.outputs.application }}
|
||||||
environment-name: ${{ env.EB_ENVIRONMENT_NAME }}
|
environment-name: ${{ steps.target.outputs.environment }}
|
||||||
version-label: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
|
version-label: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
|
||||||
deployment-package-path: .artifacts/elastic-beanstalk/site.zip
|
deployment-package-path: .artifacts/elastic-beanstalk/site.zip
|
||||||
s3-bucket-name: elasticbeanstalk-us-east-1-396287094661
|
s3-bucket-name: elasticbeanstalk-us-east-1-396287094661
|
||||||
|
|
|
||||||
|
|
@ -4,9 +4,10 @@
|
||||||
|
|
||||||
The existing `shoc-backend-deploy-dev` stack owns exactly one thing in the
|
The existing `shoc-backend-deploy-dev` stack owns exactly one thing in the
|
||||||
`shoc-backend` AWS account (`396287094661`, `us-east-1`): the retained GitHub
|
`shoc-backend` AWS account (`396287094661`, `us-east-1`): the retained GitHub
|
||||||
OIDC deploy role for dev. Automated and manual dev deployments are disabled
|
OIDC deploy role for dev. Automatic deployments are disabled while Terraform
|
||||||
while Terraform adoption proceeds. The CDK stack remains until the role's
|
adoption proceeds; dev, staging, and prod releases require an explicit
|
||||||
CloudFormation ownership transfer completes.
|
`workflow_dispatch` from the matching branch. The CDK stack remains until the
|
||||||
|
role's CloudFormation ownership transfer completes.
|
||||||
|
|
||||||
## Ownership boundary (deliberate)
|
## Ownership boundary (deliberate)
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue