ci(deploy): pause dev and staging deployments

Prevent application releases from racing Terraform adoption while retaining production deployment and validation.
This commit is contained in:
Adam Moussa 2026-08-30 16:39:04 -04:00
parent f8bf102f35
commit 874b568642
2 changed files with 15 additions and 45 deletions

View file

@ -4,7 +4,7 @@ on:
pull_request:
branches: [dev, staging, main]
push:
branches: [dev, staging, main]
branches: [main]
workflow_dispatch:
permissions:
@ -70,57 +70,25 @@ jobs:
if: >
github.event_name == 'push' ||
(github.event_name == 'workflow_dispatch' &&
contains(fromJSON('["refs/heads/dev","refs/heads/staging","refs/heads/main"]'), github.ref))
github.ref == 'refs/heads/main')
needs: validate
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
environment:
name: ${{ github.ref_name == 'main' && 'prod' || github.ref_name }}
name: prod
concurrency:
group: deploy-${{ github.ref_name == 'main' && 'prod' || github.ref_name }}
group: deploy-prod
cancel-in-progress: false
env:
EB_APPLICATION_NAME: shoc-backend
EB_ENVIRONMENT_NAME: shoc-backend-prod
SMOKE_URL: https://api.seahaven.com
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Resolve deploy target
id: target
run: |
set -euo pipefail
case "${GITHUB_REF_NAME}" in
dev)
application=shoc-backend
environment=shoc-backend-dev
smoke_url=https://api.dev.seahaven.com
;;
staging)
application=shoc-backend
environment=shoc-backend-staging
smoke_url=https://api.staging.seahaven.com
;;
main)
application=shoc-backend
environment=shoc-backend-prod
smoke_url=https://api.seahaven.com
;;
*)
echo "Unsupported ref ${GITHUB_REF_NAME}" >&2
exit 1
;;
esac
{
echo "application=${application}"
echo "environment=${environment}"
echo "smoke_url=${smoke_url}"
} >> "${GITHUB_OUTPUT}"
{
echo "EB_APPLICATION_NAME=${application}"
echo "EB_ENVIRONMENT_NAME=${environment}"
echo "SMOKE_URL=${smoke_url}"
} >> "${GITHUB_ENV}"
- name: Set up .NET
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
@ -151,8 +119,8 @@ jobs:
uses: aws-actions/aws-elasticbeanstalk-deploy@7883cdd454c162051bf6fc13389536b045149b4c # v1.0.8
with:
aws-region: us-east-1
application-name: ${{ steps.target.outputs.application }}
environment-name: ${{ steps.target.outputs.environment }}
application-name: ${{ env.EB_APPLICATION_NAME }}
environment-name: ${{ env.EB_ENVIRONMENT_NAME }}
version-label: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
deployment-package-path: .artifacts/elastic-beanstalk/site.zip
s3-bucket-name: elasticbeanstalk-us-east-1-396287094661

View file

@ -2,9 +2,11 @@
## Dev deploy-role stack
The existing `shoc-backend-deploy-dev` stack owns exactly one thing in the `shoc-backend` AWS account
(`396287094661`, `us-east-1`): the **GitHub OIDC deploy role** used by the
`dev` deployment workflow in `.github/workflows/deploy.yml`.
The existing `shoc-backend-deploy-dev` stack owns exactly one thing in the
`shoc-backend` AWS account (`396287094661`, `us-east-1`): the retained GitHub
OIDC deploy role for dev. Automated and manual dev deployments are disabled
while Terraform adoption proceeds. The CDK stack remains until the role's
CloudFormation ownership transfer completes.
## Ownership boundary (deliberate)