name: Deploy # Continuous deployment to AWS (S3 + CloudFront) on push to `dev`. # # This is a thin caller of the org's reusable CD workflow. `cd-cdk.yaml` runs # `cdk deploy` (provisioning the infra in infra/cdk) and then the # post-deploy-script, which builds the SPA and syncs it to S3 + invalidates # CloudFront. Both run as the OIDC deploy role created by the stack. # # When staging/prod accounts exist, add jobs keyed to their branches and their # own AWS_DEPLOY_ROLE_ARN, reusing this same reusable workflow. on: push: branches: [dev] workflow_dispatch: {} # OIDC needs id-token: write — it is never in the default token set and cannot # be granted to the reusable workflow unless the caller has it. permissions: id-token: write contents: read concurrency: group: deploy-dev cancel-in-progress: false jobs: deploy: uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main with: node-version: "24" region: us-east-1 cdk-dir: infra/cdk stack-name: shoc-frontend-dev post-deploy-script: scripts/deploy-web.sh secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}