shoc-backend/.github/workflows/release.yaml
Adam Moussa 8f4fa36647
refactor(cd): ship Elastic Beanstalk versions from GitHub on main
Keep application and Terraform changes in separate PRs so a merge cannot race an HCP apply against an app deploy.
2026-09-17 15:54:31 -04:00

90 lines
2.7 KiB
YAML

name: Release
# Cut a SemVer tag from main HEAD, then call deploy. GITHUB_TOKEN is enough;
# it cannot start other workflows via the tag push, so this file calls deploy.
on:
workflow_dispatch:
inputs:
environment:
description: Target environment
required: true
type: choice
options: [staging, prod]
bump:
description: SemVer bump from the last prod core tag
required: true
type: choice
options: [patch, minor, major]
message:
description: Annotated tag message and GitHub Release body
required: true
type: string
permissions:
contents: write
checks: read
jobs:
cut:
name: Cut tag
runs-on: ubuntu-latest
timeout-minutes: 40
outputs:
tag: ${{ steps.tag.outputs.tag }}
sha: ${{ steps.tag.outputs.sha }}
environment: ${{ github.event.inputs.environment }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: true
- name: Require main
run: |
set -euo pipefail
if [ "${GITHUB_REF}" != "refs/heads/main" ]; then
echo "Release must run from main (Use workflow from: main). Got ${GITHUB_REF}." >&2
exit 1
fi
- name: Require CI
env:
GITHUB_TOKEN: ${{ github.token }}
run: |
python3 scripts/require_commit_checks.py \
--repo "${{ github.repository }}" \
--sha "$(git rev-parse HEAD)" \
--timeout-seconds 1200
- name: Compute and push tag
id: tag
env:
ENVIRONMENT: ${{ github.event.inputs.environment }}
BUMP: ${{ github.event.inputs.bump }}
MESSAGE: ${{ github.event.inputs.message }}
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
git fetch --tags origin
sha="$(git rev-parse HEAD)"
tag="$(git tag | python3 scripts/next_release_tag.py --environment "${ENVIRONMENT}" --bump "${BUMP}")"
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git tag -a "${tag}" -m "${MESSAGE}" "${sha}"
git push origin "refs/tags/${tag}"
gh release create "${tag}" --target "${sha}" --notes "${MESSAGE}" --title "${tag}"
{
echo "tag=${tag}"
echo "sha=${sha}"
} >> "${GITHUB_OUTPUT}"
echo "Created ${tag} at ${sha}"
deploy:
name: Deploy release
needs: cut
uses: ./.github/workflows/deploy.yaml
with:
environment: ${{ needs.cut.outputs.environment }}
ref: ${{ needs.cut.outputs.tag }}
secrets: inherit