mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-09-30 08:03:13 +00:00
* ci: add protected staging deployment lane * fix: constrain staging publisher permissions * fix: handle first-push governance baseline --------- Co-authored-by: Codex Review Integration <codex-review@local.invalid>
51 lines
2 KiB
JavaScript
51 lines
2 KiB
JavaScript
#!/usr/bin/env node
|
|
import { App, Tags } from "aws-cdk-lib";
|
|
import { FrontendStack } from "../lib/frontend-stack";
|
|
|
|
const app = new App();
|
|
|
|
// Defaults match the dev setup; override via `-c key=value` on the CLI.
|
|
const envName = app.node.tryGetContext("envName") ?? "dev";
|
|
const githubRepo = app.node.tryGetContext("githubRepo") ?? "Sea-Haven-Industries/shoc-frontend-new";
|
|
const deployBranch = app.node.tryGetContext("deployBranch") ?? "dev";
|
|
// When set (e.g. "staging"), the deploy role trusts the exact GitHub
|
|
// environment OIDC subject instead of a deploy-branch ref. Empty = dev-style
|
|
// branch-ref trust.
|
|
const githubEnvironment = app.node.tryGetContext("githubEnvironment") ?? "";
|
|
|
|
// Custom domain. Comma-separated, e.g. -c domainNames=dev.seahaven.com
|
|
// The ACM cert MUST be in us-east-1 in the SAME account this stack deploys to.
|
|
const domainNames = (app.node.tryGetContext("domainNames") ?? "")
|
|
.split(",")
|
|
.map((d: string) => d.trim())
|
|
.filter((d: string) => d.length > 0);
|
|
const certificateArn = app.node.tryGetContext("certificateArn") ?? "";
|
|
|
|
// Route 53 hosted zone (this account) for the custom-domain alias record.
|
|
const hostedZoneId = app.node.tryGetContext("hostedZoneId") ?? "";
|
|
const hostedZoneName = app.node.tryGetContext("hostedZoneName") ?? "";
|
|
|
|
// Staging and beyond protect their stacks from accidental deletion; dev
|
|
// stays teardown-friendly (its artifacts are reproducible). CDK applies this
|
|
// at deploy time — it is not part of the synthesized template.
|
|
const terminationProtection = envName !== "dev";
|
|
|
|
const stack = new FrontendStack(app, `shoc-frontend-${envName}`, {
|
|
envName,
|
|
githubRepo,
|
|
deployBranch,
|
|
githubEnvironment,
|
|
terminationProtection,
|
|
domainNames,
|
|
certificateArn,
|
|
hostedZoneId,
|
|
hostedZoneName,
|
|
env: {
|
|
account: process.env.CDK_DEFAULT_ACCOUNT,
|
|
region: process.env.CDK_DEFAULT_REGION ?? "us-east-1",
|
|
},
|
|
});
|
|
|
|
Tags.of(stack).add("Project", "shoc-frontend");
|
|
Tags.of(stack).add("Environment", envName);
|
|
Tags.of(stack).add("ManagedBy", "cdk");
|