shoc-frontend-new/scripts/summarize-cloudfront-live-state.sh
Adam Moussa c96a259365
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
refactor(cd): ship SPA content from GitHub on main (#220)
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD

Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.

* ci: run Frontend checks and Terraform CI on PRs to main and dev

Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.

* refactor(terraform): keep live/dev and live/staging as HCP roots

Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.

* style: prettier terraform-validate.mjs

* fix(terraform): pin githubdeploy assume-role policy in import checker

Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 14:30:20 -04:00

25 lines
995 B
Bash
Executable file

#!/usr/bin/env bash
# Print origin paths, distribution status, and served index hash.
# Used by deploy-web.yaml's always() summary. Never fails the job.
set -u
DISTRIBUTION_ID="${DISTRIBUTION_ID:-}"
SITE_URL="${SITE_URL:-}"
echo "=== CloudFront live state ==="
if [[ -z "${DISTRIBUTION_ID}" ]]; then
echo "DISTRIBUTION_ID unset"
exit 0
fi
aws cloudfront get-distribution --id "${DISTRIBUTION_ID}" --output json | python3 -c '
import json, sys
payload = json.load(sys.stdin)
dist = payload.get("Distribution") or {}
config = dist.get("DistributionConfig") or {}
print("status:", dist.get("Status"))
for origin in ((config.get("Origins") or {}).get("Items") or []):
print("origin %s: origin_path=%r" % (origin.get("Id"), origin.get("OriginPath") or ""))
'
echo
if [[ -n "${SITE_URL}" ]]; then
echo -n "served index sha256: "
curl -fsS --max-time 30 "${SITE_URL%/}/" | python3 -c "import hashlib,sys; print(hashlib.sha256(sys.stdin.buffer.read()).hexdigest())" || echo "unreachable"
fi