mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 06:03:12 +00:00
fix(eb): configure work-order webhook HMAC secret source (#41)
This commit is contained in:
parent
85ce7c6384
commit
83ed6a1790
2 changed files with 43 additions and 0 deletions
10
.ebextensions/02_webhook_config.config
Normal file
10
.ebextensions/02_webhook_config.config
Normal file
|
|
@ -0,0 +1,10 @@
|
||||||
|
# Enables the dev receiver and sets the non-secret pointer it reads to locate
|
||||||
|
# the producer HMAC keyset. The keyset itself is fetched at runtime through the
|
||||||
|
# instance role's cross-account grant. Do not set these properties directly
|
||||||
|
# with update-environment: directly set values take precedence over
|
||||||
|
# .ebextensions and would silently turn this file into dead text.
|
||||||
|
option_settings:
|
||||||
|
aws:elasticbeanstalk:application:environment:
|
||||||
|
WorkOrderWebhook__Enabled: "true"
|
||||||
|
WorkOrderWebhook__Region: us-east-1
|
||||||
|
WorkOrderWebhook__SecretId: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB
|
||||||
33
.github/workflows/deploy.yml
vendored
33
.github/workflows/deploy.yml
vendored
|
|
@ -55,6 +55,18 @@ jobs:
|
||||||
grep -Fxq "efbundle" .artifacts/elastic-beanstalk/zip-contents.txt
|
grep -Fxq "efbundle" .artifacts/elastic-beanstalk/zip-contents.txt
|
||||||
grep -Fxq ".ebextensions/01_migrations.config" \
|
grep -Fxq ".ebextensions/01_migrations.config" \
|
||||||
.artifacts/elastic-beanstalk/zip-contents.txt
|
.artifacts/elastic-beanstalk/zip-contents.txt
|
||||||
|
grep -Fxq ".ebextensions/02_webhook_config.config" \
|
||||||
|
.artifacts/elastic-beanstalk/zip-contents.txt
|
||||||
|
unzip -p .artifacts/elastic-beanstalk/site.zip \
|
||||||
|
.ebextensions/02_webhook_config.config \
|
||||||
|
> .artifacts/elastic-beanstalk/webhook-config.txt
|
||||||
|
grep -Fxq ' WorkOrderWebhook__Enabled: "true"' \
|
||||||
|
.artifacts/elastic-beanstalk/webhook-config.txt
|
||||||
|
grep -Fxq ' WorkOrderWebhook__Region: us-east-1' \
|
||||||
|
.artifacts/elastic-beanstalk/webhook-config.txt
|
||||||
|
grep -Fxq \
|
||||||
|
' WorkOrderWebhook__SecretId: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB' \
|
||||||
|
.artifacts/elastic-beanstalk/webhook-config.txt
|
||||||
|
|
||||||
deploy:
|
deploy:
|
||||||
name: Deploy shoc-backend to Elastic Beanstalk dev
|
name: Deploy shoc-backend to Elastic Beanstalk dev
|
||||||
|
|
@ -154,6 +166,27 @@ jobs:
|
||||||
- name: Post-deploy smoke
|
- name: Post-deploy smoke
|
||||||
run: bash scripts/smoke-elastic-beanstalk.sh https://api.dev.seahaven.com
|
run: bash scripts/smoke-elastic-beanstalk.sh https://api.dev.seahaven.com
|
||||||
|
|
||||||
|
- name: Verify webhook secret source is operational
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
response_file="$(mktemp)"
|
||||||
|
trap 'rm -f "$response_file"' EXIT
|
||||||
|
status="$(curl --silent --show-error \
|
||||||
|
--output "$response_file" \
|
||||||
|
--write-out '%{http_code}' \
|
||||||
|
--request POST \
|
||||||
|
--header 'Content-Type: application/json' \
|
||||||
|
--header "X-SH-Timestamp: $(date +%s)" \
|
||||||
|
--header 'X-SH-Key-Id: deployment-smoke-invalid-key' \
|
||||||
|
--header "X-SH-Signature: v1=$(printf '0%.0s' {1..64})" \
|
||||||
|
--data '{}' \
|
||||||
|
https://api.dev.seahaven.com/api/webhooks/work-orders)"
|
||||||
|
if [ "$status" != "401" ]; then
|
||||||
|
echo "Expected enabled webhook with an operational secret source to reject the invalid probe with 401; received $status." >&2
|
||||||
|
sed -n '1,20p' "$response_file" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Restore previous application version on failure (schema is not reverted)
|
- name: Restore previous application version on failure (schema is not reverted)
|
||||||
if: failure()
|
if: failure()
|
||||||
run: |
|
run: |
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue