name: Deploy # Continuous deployment to AWS (S3 + CloudFront) on push to `dev`. # # This is a thin caller of the org's reusable CD workflow. `cd-cdk.yaml` runs # `cdk deploy` (provisioning the infra in infra/cdk) and then the # post-deploy-script, which builds the SPA and syncs it to S3 + invalidates # CloudFront. Both run as the OIDC deploy role created by the stack. # # When staging/prod accounts exist, add jobs keyed to their branches and their # own AWS_DEPLOY_ROLE_ARN, reusing this same reusable workflow. on: push: branches: [dev] workflow_dispatch: {} # OIDC needs id-token: write — it is never in the default token set and cannot # be granted to the reusable workflow unless the caller has it. permissions: id-token: write contents: read concurrency: group: deploy-dev cancel-in-progress: false jobs: deploy: uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8 with: node-version: "24" region: us-east-1 cdk-dir: infra/cdk stack-name: shoc-frontend-dev post-deploy-script: scripts/deploy-web.sh secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} upload-sourcemaps: name: Upload private source maps needs: deploy if: github.ref == 'refs/heads/dev' runs-on: ubuntu-latest env: VITE_APP_COMMIT_SHA: ${{ github.sha }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" cache: npm - name: Build exact deployed release run: npm ci && npm run build - name: Upload source maps to Sentry run: bash scripts/upload-sourcemaps.sh env: SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}