fix(ci): confirm release prefix with s3api head-object (SH-300) (#182)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Validate and deploy / Validate production build (push) Waiting to run
Validate and deploy / Deploy shoc-frontend-new-dev through Terraform (push) Blocked by required conditions

grep -q closed the aws s3 ls pipe after a successful upload and failed the deploy.
This commit is contained in:
Adam Moussa 2026-09-11 14:26:19 -04:00 • committed by GitHub
parent 69c24c1c2c
commit 7716b4afc8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 18 additions and 1 deletions

View file

@ -155,7 +155,9 @@ jobs:
aws s3 cp dist/index.html "s3://${SITE_BUCKET}/${prefix}/index.html" \
--cache-control "no-cache,no-store,must-revalidate" \
--content-type "text/html"
aws s3 ls "s3://${SITE_BUCKET}/${prefix}/" | grep -q index.html
aws s3api head-object \
--bucket "${SITE_BUCKET}" \
--key "${prefix}/index.html"
index_sha="$(python3 -c 'import hashlib,pathlib; print(hashlib.sha256(pathlib.Path("dist/index.html").read_bytes()).hexdigest())')"
echo "INDEX_SHA256=${index_sha}" >> "${GITHUB_ENV}"
echo "Uploaded ${prefix}; index.html sha256=${index_sha}"

View file

@ -280,6 +280,20 @@ def test_deploy_workflow_uses_script_flags() -> list[str]:
return failures
def test_deploy_workflow_confirms_prefix_with_head_object() -> list[str]:
workflow = (
Path(__file__).resolve().parents[1] / ".github/workflows/deploy.yml"
).read_text(encoding="utf-8")
failures: list[str] = []
if "aws s3api head-object" not in workflow:
failures.append(
"deploy.yml must confirm the uploaded index.html with s3api head-object"
)
if "aws s3 ls" in workflow:
failures.append("deploy.yml must not list the prefix with aws s3 ls")
return failures
def main() -> int:
cases = [
("version-only", run_case("version-only.json"), 0),
@ -307,6 +321,7 @@ def main() -> int:
redirect_failures = test_download_standard_opener_redirect()
download_failures.extend(redirect_failures)
download_failures.extend(test_deploy_workflow_uses_script_flags())
download_failures.extend(test_deploy_workflow_confirms_prefix_with_head_object())
if failures or download_failures:
if failures:
print(