fix(eb): configure work-order webhook HMAC secret source (#41)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions

This commit is contained in:
Adam Moussa 2026-07-30 10:44:43 -04:00 • committed by GitHub
parent 85ce7c6384
commit 83ed6a1790
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 43 additions and 0 deletions

View file

@ -0,0 +1,10 @@
# Enables the dev receiver and sets the non-secret pointer it reads to locate
# the producer HMAC keyset. The keyset itself is fetched at runtime through the
# instance role's cross-account grant. Do not set these properties directly
# with update-environment: directly set values take precedence over
# .ebextensions and would silently turn this file into dead text.
option_settings:
aws:elasticbeanstalk:application:environment:
WorkOrderWebhook__Enabled: "true"
WorkOrderWebhook__Region: us-east-1
WorkOrderWebhook__SecretId: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB

View file

@ -55,6 +55,18 @@ jobs:
grep -Fxq "efbundle" .artifacts/elastic-beanstalk/zip-contents.txt grep -Fxq "efbundle" .artifacts/elastic-beanstalk/zip-contents.txt
grep -Fxq ".ebextensions/01_migrations.config" \ grep -Fxq ".ebextensions/01_migrations.config" \
.artifacts/elastic-beanstalk/zip-contents.txt .artifacts/elastic-beanstalk/zip-contents.txt
grep -Fxq ".ebextensions/02_webhook_config.config" \
.artifacts/elastic-beanstalk/zip-contents.txt
unzip -p .artifacts/elastic-beanstalk/site.zip \
.ebextensions/02_webhook_config.config \
> .artifacts/elastic-beanstalk/webhook-config.txt
grep -Fxq ' WorkOrderWebhook__Enabled: "true"' \
.artifacts/elastic-beanstalk/webhook-config.txt
grep -Fxq ' WorkOrderWebhook__Region: us-east-1' \
.artifacts/elastic-beanstalk/webhook-config.txt
grep -Fxq \
' WorkOrderWebhook__SecretId: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB' \
.artifacts/elastic-beanstalk/webhook-config.txt
deploy: deploy:
name: Deploy shoc-backend to Elastic Beanstalk dev name: Deploy shoc-backend to Elastic Beanstalk dev
@ -154,6 +166,27 @@ jobs:
- name: Post-deploy smoke - name: Post-deploy smoke
run: bash scripts/smoke-elastic-beanstalk.sh https://api.dev.seahaven.com run: bash scripts/smoke-elastic-beanstalk.sh https://api.dev.seahaven.com
- name: Verify webhook secret source is operational
run: |
set -euo pipefail
response_file="$(mktemp)"
trap 'rm -f "$response_file"' EXIT
status="$(curl --silent --show-error \
--output "$response_file" \
--write-out '%{http_code}' \
--request POST \
--header 'Content-Type: application/json' \
--header "X-SH-Timestamp: $(date +%s)" \
--header 'X-SH-Key-Id: deployment-smoke-invalid-key' \
--header "X-SH-Signature: v1=$(printf '0%.0s' {1..64})" \
--data '{}' \
https://api.dev.seahaven.com/api/webhooks/work-orders)"
if [ "$status" != "401" ]; then
echo "Expected enabled webhook with an operational secret source to reject the invalid probe with 401; received $status." >&2
sed -n '1,20p' "$response_file" >&2
exit 1
fi
- name: Restore previous application version on failure (schema is not reverted) - name: Restore previous application version on failure (schema is not reverted)
if: failure() if: failure()
run: | run: |