From 83ed6a1790a1615a32b3adc6ae0b4ef91c7f8616 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 30 Jul 2026 10:44:43 -0400 Subject: [PATCH] fix(eb): configure work-order webhook HMAC secret source (#41) --- .ebextensions/02_webhook_config.config | 10 ++++++++ .github/workflows/deploy.yml | 33 ++++++++++++++++++++++++++ 2 files changed, 43 insertions(+) create mode 100644 .ebextensions/02_webhook_config.config diff --git a/.ebextensions/02_webhook_config.config b/.ebextensions/02_webhook_config.config new file mode 100644 index 0000000..59f0df6 --- /dev/null +++ b/.ebextensions/02_webhook_config.config @@ -0,0 +1,10 @@ +# Enables the dev receiver and sets the non-secret pointer it reads to locate +# the producer HMAC keyset. The keyset itself is fetched at runtime through the +# instance role's cross-account grant. Do not set these properties directly +# with update-environment: directly set values take precedence over +# .ebextensions and would silently turn this file into dead text. +option_settings: + aws:elasticbeanstalk:application:environment: + WorkOrderWebhook__Enabled: "true" + WorkOrderWebhook__Region: us-east-1 + WorkOrderWebhook__SecretId: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 83cf517..60a995f 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -55,6 +55,18 @@ jobs: grep -Fxq "efbundle" .artifacts/elastic-beanstalk/zip-contents.txt grep -Fxq ".ebextensions/01_migrations.config" \ .artifacts/elastic-beanstalk/zip-contents.txt + grep -Fxq ".ebextensions/02_webhook_config.config" \ + .artifacts/elastic-beanstalk/zip-contents.txt + unzip -p .artifacts/elastic-beanstalk/site.zip \ + .ebextensions/02_webhook_config.config \ + > .artifacts/elastic-beanstalk/webhook-config.txt + grep -Fxq ' WorkOrderWebhook__Enabled: "true"' \ + .artifacts/elastic-beanstalk/webhook-config.txt + grep -Fxq ' WorkOrderWebhook__Region: us-east-1' \ + .artifacts/elastic-beanstalk/webhook-config.txt + grep -Fxq \ + ' WorkOrderWebhook__SecretId: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB' \ + .artifacts/elastic-beanstalk/webhook-config.txt deploy: name: Deploy shoc-backend to Elastic Beanstalk dev @@ -154,6 +166,27 @@ jobs: - name: Post-deploy smoke run: bash scripts/smoke-elastic-beanstalk.sh https://api.dev.seahaven.com + - name: Verify webhook secret source is operational + run: | + set -euo pipefail + response_file="$(mktemp)" + trap 'rm -f "$response_file"' EXIT + status="$(curl --silent --show-error \ + --output "$response_file" \ + --write-out '%{http_code}' \ + --request POST \ + --header 'Content-Type: application/json' \ + --header "X-SH-Timestamp: $(date +%s)" \ + --header 'X-SH-Key-Id: deployment-smoke-invalid-key' \ + --header "X-SH-Signature: v1=$(printf '0%.0s' {1..64})" \ + --data '{}' \ + https://api.dev.seahaven.com/api/webhooks/work-orders)" + if [ "$status" != "401" ]; then + echo "Expected enabled webhook with an operational secret source to reject the invalid probe with 401; received $status." >&2 + sed -n '1,20p' "$response_file" >&2 + exit 1 + fi + - name: Restore previous application version on failure (schema is not reverted) if: failure() run: |