mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-07 16:19:07 +00:00
Compare commits
1 commit
f145a2e5af
...
2e121a7cd3
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2e121a7cd3 |
2 changed files with 24 additions and 50 deletions
40
.github/workflows/deploy.yaml
vendored
40
.github/workflows/deploy.yaml
vendored
|
|
@ -58,28 +58,24 @@ jobs:
|
|||
GITHUB_SHA_IN: ${{ github.sha }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
# A called reusable workflow keeps the caller's github.event_name
|
||||
# (push or workflow_dispatch), not workflow_call. Prefer the call
|
||||
# inputs whenever they are set.
|
||||
if [ -n "${CALL_ENVIRONMENT}" ]; then
|
||||
environment="${CALL_ENVIRONMENT}"
|
||||
ref="${CALL_REF:-${GITHUB_SHA_IN}}"
|
||||
else
|
||||
case "${EVENT_NAME}" in
|
||||
workflow_dispatch)
|
||||
environment="${INPUT_ENVIRONMENT}"
|
||||
ref="${INPUT_REF:-${GITHUB_SHA_IN}}"
|
||||
;;
|
||||
push)
|
||||
environment=dev
|
||||
ref="${GITHUB_SHA_IN}"
|
||||
;;
|
||||
*)
|
||||
echo "unsupported event ${EVENT_NAME}" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
fi
|
||||
case "${EVENT_NAME}" in
|
||||
workflow_call)
|
||||
environment="${CALL_ENVIRONMENT}"
|
||||
ref="${CALL_REF}"
|
||||
;;
|
||||
workflow_dispatch)
|
||||
environment="${INPUT_ENVIRONMENT}"
|
||||
ref="${INPUT_REF:-${GITHUB_SHA_IN}}"
|
||||
;;
|
||||
push)
|
||||
environment=dev
|
||||
ref="${GITHUB_SHA_IN}"
|
||||
;;
|
||||
*)
|
||||
echo "unsupported event ${EVENT_NAME}" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
case "${environment}" in
|
||||
dev|staging|prod) ;;
|
||||
*)
|
||||
|
|
|
|||
|
|
@ -137,11 +137,11 @@ restores the previous Elastic Beanstalk version label. Database migrations
|
|||
already applied by the failed bundle are not reverted. Deploy parameters are read from `/shoc-backend/<env>/deploy/*` SSM
|
||||
parameters this module writes.
|
||||
|
||||
Merge to `main` deploys **dev** unless the push is terraform-only. Staging is
|
||||
cut from **Actions → Release** (`environment`, `bump`, `message`). That
|
||||
workflow waits for CI, tags `vX.Y.Z-staging` from main HEAD with
|
||||
`GITHUB_TOKEN`, then calls deploy. Do not cut prod yet; leave
|
||||
`PROD_APP_CD_ENABLED` unset and do not create the `prod` GitHub Environment.
|
||||
Merge to `main` deploys **dev** unless the push is terraform-only. Staging and
|
||||
prod are cut from **Actions → Release** (`environment`, `bump`, `message`).
|
||||
That workflow waits for CI, tags `vX.Y.Z-staging` or `vX.Y.Z` from main HEAD
|
||||
with `GITHUB_TOKEN`, then calls deploy. Prod waits on GitHub Environment
|
||||
reviewers; AWS steps stay skipped until `PROD_APP_CD_ENABLED` is true.
|
||||
Staging remains `adoption_complete=false` with a pinned API CNAME until its
|
||||
import apply is proven.
|
||||
|
||||
|
|
@ -160,35 +160,13 @@ on that leftover path only.
|
|||
### Credentials
|
||||
|
||||
Store `DEPLOY_ROLE_ARN` as a GitHub Environment **variable** (`dev`,
|
||||
`staging`). OIDC trust is
|
||||
`staging`, later `prod`). OIDC trust is
|
||||
`repo:Sea-Haven-Industries/shoc-backend:environment:<env>` plus
|
||||
`job_workflow_ref` for `.github/workflows/deploy.yaml` at `refs/heads/main`
|
||||
and `refs/tags/v*`. Adding another deploy workflow is a cross-family IAM
|
||||
change. After cutover, drop `TF_API_TOKEN` from GitHub Environments. The new
|
||||
CD path does not use it.
|
||||
|
||||
GitHub Environment deployment branch and tag policies are repository
|
||||
settings, not this diff. Update them before the first merge to `main` and
|
||||
the first staging cut. The policy matches `GITHUB_REF` of the workflow run.
|
||||
Branch patterns never match tag refs; adding `v*` as a branch pattern fails
|
||||
the same way as an empty allowlist.
|
||||
|
||||
1. `dev` — allow branch `main`. Keep `dev` allowed while leftover
|
||||
`.github/workflows/deploy.yml` still deploys from that branch.
|
||||
2. `staging` — add a **tag-type** policy matching `v*.*.*-staging` for
|
||||
`deploy-tag.yaml`. Allow branch `main` because Actions → Release is
|
||||
`workflow_dispatch` on `main` and then calls `deploy.yaml`
|
||||
(`GITHUB_TOKEN` tag pushes do not start `deploy-tag.yaml`). Keep
|
||||
`staging` allowed while leftover `deploy.yml` still deploys from that
|
||||
branch.
|
||||
|
||||
Do not create the `prod` environment yet. Leave `PROD_APP_CD_ENABLED`
|
||||
unset. Until the `prod` environment exists with reviewers, do not run
|
||||
Actions → Release with `environment=prod`, do not push a bare `vX.Y.Z`
|
||||
tag, and do not `workflow_dispatch` deploy with `environment=prod`. Any
|
||||
of those declares `environment: prod` and would auto-create an
|
||||
unprotected environment.
|
||||
|
||||
## Pinned live identities
|
||||
|
||||
- Dev: workspace `shoc-backend-dev`; EB environment `shoc-backend-dev`
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue