|
8 | 8 |
|
9 | 9 | jobs: |
10 | 10 | build: |
| 11 | + name: Build |
11 | 12 | runs-on: ubuntu-latest |
12 | 13 | permissions: |
13 | 14 | id-token: write |
14 | 15 | contents: read |
15 | 16 |
|
16 | 17 | steps: |
17 | 18 | - name: Setup job workspace |
18 | | - uses: ServerlessOpsIO/gha-setup-workspace@v1 |
| 19 | + uses: ServerlessOpsIO/gha-setup-workspace@v2 |
19 | 20 |
|
20 | 21 | - name: Assume AWS Credentials |
21 | 22 | uses: ServerlessOpsIO/gha-assume-aws-credentials@v1 |
22 | 23 | with: |
23 | 24 | build_aws_account_id: ${{ secrets.AWS_CICD_ACCOUNT_ID }} |
24 | 25 |
|
25 | 26 | - name: Install AWS SAM |
26 | | - uses: aws-actions/setup-sam@v2 |
27 | | - |
| 27 | + uses: aws-actions/setup-sam@v3 |
28 | 28 |
|
29 | 29 | - name: Validate template |
30 | 30 | run: sam validate --lint |
31 | 31 |
|
32 | | - - name: Validate template (userpool stackset) |
33 | | - run: sam validate --lint --template ./stacksets/userpool/stackset.yaml |
| 32 | + - name: Validate template (stackset) |
| 33 | + run: sam validate --lint --template stacksets.yaml |
34 | 34 |
|
35 | | - - name: Validate template (products stackset) |
36 | | - run: sam validate --lint --template ./products/stackset.yaml |
| 35 | + - name: Validate template (products template) |
| 36 | + run: sam validate --lint --template ./products/products.yaml |
37 | 37 |
|
38 | 38 | - name: Validate template (client product) |
39 | | - run: sam validate --lint --template ./products/client/product.yaml |
| 39 | + run: sam validate --lint --template ./products/client/template.yaml |
40 | 40 |
|
41 | 41 | - name: Validate template (server product) |
42 | | - run: sam validate --lint --template ./products/server/product.yaml |
| 42 | + run: sam validate --lint --template ./products/server/template.yaml |
43 | 43 |
|
44 | 44 | - name: Synethsize StackSet templates |
45 | 45 | run: | |
46 | | - for _f in $(find . -type f -name 'template.yaml'); do |
| 46 | + for _f in $(find . -type f -name 'stacksets.yaml'); do |
47 | 47 | _dir="$(dirname $_f)/" \ |
48 | 48 | yq \ |
49 | 49 | -i \ |
50 | 50 | '(.. | select(has("localTemplateFile")) | .localTemplateFile) |= load_str(strenv(_dir) + .)' \ |
51 | 51 | $_f; |
52 | 52 | done |
53 | 53 |
|
| 54 | + - name: Package Stackset template |
| 55 | + id: package-stackset |
| 56 | + uses: ServerlessOpsIO/gha-package-aws-sam@v1 |
| 57 | + with: |
| 58 | + template_file: stacksets.yaml |
| 59 | + packaged_template_file: packaged-stacksets.yaml |
| 60 | + |
54 | 61 | - name: Store Artifacts |
55 | | - uses: ServerlessOpsIO/gha-store-artifacts@v1 |
| 62 | + uses: ServerlessOpsIO/gha-store-artifacts@v2 |
56 | 63 | with: |
57 | 64 | use_aws_sam: true |
58 | 65 |
|
59 | | - deploy: |
| 66 | + deploy_authnz: |
| 67 | + name: Deploy Authnz Service |
| 68 | + needs: |
| 69 | + - build |
| 70 | + environment: production |
| 71 | + runs-on: ubuntu-latest |
| 72 | + permissions: |
| 73 | + id-token: write |
| 74 | + contents: read |
| 75 | + |
| 76 | + steps: |
| 77 | + - name: Setup job workspace |
| 78 | + uses: ServerlessOpsIO/gha-setup-workspace@v2 |
| 79 | + with: |
| 80 | + checkout_artifact: true |
| 81 | + |
| 82 | + - name: Assume AWS Credentials |
| 83 | + uses: ServerlessOpsIO/gha-assume-aws-credentials@v1 |
| 84 | + with: |
| 85 | + build_aws_account_id: ${{ secrets.AWS_CICD_ACCOUNT_ID }} |
| 86 | + deploy_aws_account_id: ${{ secrets.DEPLOYMENT_ACCOUNT_ID }} |
| 87 | + |
| 88 | + - name: Deploy via AWS SAM |
| 89 | + uses: ServerlessOpsIO/gha-deploy-aws-sam@v1 |
| 90 | + with: |
| 91 | + aws_account_id: ${{ secrets.DEPLOYMENT_ACCOUNT_ID }} |
| 92 | + env_json: ${{ toJson(env) }} |
| 93 | + vars_json: ${{ toJson(vars) }} |
| 94 | + secrets_json: ${{ toJson(secrets) }} |
| 95 | + |
| 96 | + deploy_stacksets: |
| 97 | + name: Deploy Authnz Products |
60 | 98 | needs: |
61 | 99 | - build |
62 | 100 | environment: production |
|
67 | 105 |
|
68 | 106 | steps: |
69 | 107 | - name: Setup job workspace |
70 | | - uses: ServerlessOpsIO/gha-setup-workspace@v1 |
| 108 | + uses: ServerlessOpsIO/gha-setup-workspace@v2 |
71 | 109 | with: |
72 | 110 | checkout_artifact: true |
73 | 111 |
|
|
88 | 126 | uses: ServerlessOpsIO/gha-deploy-aws-sam@v1 |
89 | 127 | with: |
90 | 128 | aws_account_id: ${{ secrets.AWS_MANAGEMENT_ACCOUNT_ID }} |
| 129 | + template_file: packaged-stacksets.yaml |
| 130 | + cfn_parameters_file: cfn-parameters-stacksets.json |
91 | 131 | env_json: ${{ toJson(env) }} |
| 132 | + vars_json: ${{ toJson(vars) }} |
92 | 133 | secrets_json: ${{ toJson(secrets) }} |
0 commit comments