From 874b5686424d979a07469a23c832d42974c3ce5e Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Sun, 30 Aug 2026 16:39:04 -0400 Subject: [PATCH] ci(deploy): pause dev and staging deployments Prevent application releases from racing Terraform adoption while retaining production deployment and validation. --- .github/workflows/deploy.yml | 52 +++++++----------------------------- infra/cdk/README.md | 8 +++--- 2 files changed, 15 insertions(+), 45 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 1a2abcc..caa1eee 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -4,7 +4,7 @@ on: pull_request: branches: [dev, staging, main] push: - branches: [dev, staging, main] + branches: [main] workflow_dispatch: permissions: @@ -70,57 +70,25 @@ jobs: if: > github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && - contains(fromJSON('["refs/heads/dev","refs/heads/staging","refs/heads/main"]'), github.ref)) + github.ref == 'refs/heads/main') needs: validate runs-on: ubuntu-latest permissions: contents: read id-token: write environment: - name: ${{ github.ref_name == 'main' && 'prod' || github.ref_name }} + name: prod concurrency: - group: deploy-${{ github.ref_name == 'main' && 'prod' || github.ref_name }} + group: deploy-prod cancel-in-progress: false + env: + EB_APPLICATION_NAME: shoc-backend + EB_ENVIRONMENT_NAME: shoc-backend-prod + SMOKE_URL: https://api.seahaven.com steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Resolve deploy target - id: target - run: | - set -euo pipefail - case "${GITHUB_REF_NAME}" in - dev) - application=shoc-backend - environment=shoc-backend-dev - smoke_url=https://api.dev.seahaven.com - ;; - staging) - application=shoc-backend - environment=shoc-backend-staging - smoke_url=https://api.staging.seahaven.com - ;; - main) - application=shoc-backend - environment=shoc-backend-prod - smoke_url=https://api.seahaven.com - ;; - *) - echo "Unsupported ref ${GITHUB_REF_NAME}" >&2 - exit 1 - ;; - esac - { - echo "application=${application}" - echo "environment=${environment}" - echo "smoke_url=${smoke_url}" - } >> "${GITHUB_OUTPUT}" - { - echo "EB_APPLICATION_NAME=${application}" - echo "EB_ENVIRONMENT_NAME=${environment}" - echo "SMOKE_URL=${smoke_url}" - } >> "${GITHUB_ENV}" - - name: Set up .NET uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 with: @@ -151,8 +119,8 @@ jobs: uses: aws-actions/aws-elasticbeanstalk-deploy@7883cdd454c162051bf6fc13389536b045149b4c # v1.0.8 with: aws-region: us-east-1 - application-name: ${{ steps.target.outputs.application }} - environment-name: ${{ steps.target.outputs.environment }} + application-name: ${{ env.EB_APPLICATION_NAME }} + environment-name: ${{ env.EB_ENVIRONMENT_NAME }} version-label: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }} deployment-package-path: .artifacts/elastic-beanstalk/site.zip s3-bucket-name: elasticbeanstalk-us-east-1-396287094661 diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 255499d..fec30c6 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -2,9 +2,11 @@ ## Dev deploy-role stack -The existing `shoc-backend-deploy-dev` stack owns exactly one thing in the `shoc-backend` AWS account -(`396287094661`, `us-east-1`): the **GitHub OIDC deploy role** used by the -`dev` deployment workflow in `.github/workflows/deploy.yml`. +The existing `shoc-backend-deploy-dev` stack owns exactly one thing in the +`shoc-backend` AWS account (`396287094661`, `us-east-1`): the retained GitHub +OIDC deploy role for dev. Automated and manual dev deployments are disabled +while Terraform adoption proceeds. The CDK stack remains until the role's +CloudFormation ownership transfer completes. ## Ownership boundary (deliberate)