diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 4423e6ce..c276aa2c 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -155,7 +155,9 @@ jobs: aws s3 cp dist/index.html "s3://${SITE_BUCKET}/${prefix}/index.html" \ --cache-control "no-cache,no-store,must-revalidate" \ --content-type "text/html" - aws s3 ls "s3://${SITE_BUCKET}/${prefix}/" | grep -q index.html + aws s3api head-object \ + --bucket "${SITE_BUCKET}" \ + --key "${prefix}/index.html" index_sha="$(python3 -c 'import hashlib,pathlib; print(hashlib.sha256(pathlib.Path("dist/index.html").read_bytes()).hexdigest())')" echo "INDEX_SHA256=${index_sha}" >> "${GITHUB_ENV}" echo "Uploaded ${prefix}; index.html sha256=${index_sha}" diff --git a/scripts/test-terraform-release-plan-check.py b/scripts/test-terraform-release-plan-check.py index 70e436b7..4cfaac79 100755 --- a/scripts/test-terraform-release-plan-check.py +++ b/scripts/test-terraform-release-plan-check.py @@ -280,6 +280,20 @@ def test_deploy_workflow_uses_script_flags() -> list[str]: return failures +def test_deploy_workflow_confirms_prefix_with_head_object() -> list[str]: + workflow = ( + Path(__file__).resolve().parents[1] / ".github/workflows/deploy.yml" + ).read_text(encoding="utf-8") + failures: list[str] = [] + if "aws s3api head-object" not in workflow: + failures.append( + "deploy.yml must confirm the uploaded index.html with s3api head-object" + ) + if "aws s3 ls" in workflow: + failures.append("deploy.yml must not list the prefix with aws s3 ls") + return failures + + def main() -> int: cases = [ ("version-only", run_case("version-only.json"), 0), @@ -307,6 +321,7 @@ def main() -> int: redirect_failures = test_download_standard_opener_redirect() download_failures.extend(redirect_failures) download_failures.extend(test_deploy_workflow_uses_script_flags()) + download_failures.extend(test_deploy_workflow_confirms_prefix_with_head_object()) if failures or download_failures: if failures: print(