Skip to content

Commit ce2f817

Browse files
committed
Update main workflow to work with new deploy style
1 parent db9b0f6 commit ce2f817

5 files changed

Lines changed: 85 additions & 57 deletions

File tree

‎.github/workflows/branch.yml‎

Lines changed: 28 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -8,64 +8,57 @@ on:
88

99
jobs:
1010
build:
11+
name: Build
1112
runs-on: ubuntu-latest
1213
permissions:
1314
id-token: write
1415
contents: read
1516

1617
steps:
1718
- name: Setup job workspace
18-
uses: ServerlessOpsIO/gha-setup-workspace@v1
19+
uses: ServerlessOpsIO/gha-setup-workspace@v2
1920

2021
- name: Assume AWS Credentials
2122
uses: ServerlessOpsIO/gha-assume-aws-credentials@v1
2223
with:
2324
build_aws_account_id: ${{ secrets.AWS_CICD_ACCOUNT_ID }}
2425

2526
- name: Install AWS SAM
26-
uses: aws-actions/setup-sam@v2
27-
27+
uses: aws-actions/setup-sam@v3
2828

2929
- name: Validate template
3030
run: sam validate --lint
3131

32-
- name: Build artifact
33-
run: sam build --parallel --template template.yaml
32+
- name: Validate template (stackset)
33+
run: sam validate --lint --template stacksets.yaml
3434

35-
# Disableing until a full workflow for feature branches is figured out.
36-
- name: Store Artifacts
37-
if: false
38-
uses: ServerlessOpsIO/gha-store-artifacts@v1
39-
with:
40-
use_aws_sam: true
35+
- name: Validate template (products template)
36+
run: sam validate --lint --template ./products/products.yaml
4137

42-
deploy:
43-
# Disableing until a full workflow for feature branches is figured out.
44-
if: false
45-
needs:
46-
- build
38+
- name: Validate template (client product)
39+
run: sam validate --lint --template ./products/client/template.yaml
4740

48-
environment: feature
49-
runs-on: ubuntu-latest
50-
permissions:
51-
id-token: write
52-
contents: read
41+
- name: Validate template (server product)
42+
run: sam validate --lint --template ./products/server/template.yaml
5343

54-
steps:
55-
- name: Setup job workspace
56-
uses: ServerlessOpsIO/gha-setup-workspace@v1
57-
with:
58-
checkout_artifact: true
44+
- name: Synethsize StackSet templates
45+
run: |
46+
for _f in $(find . -type f -name 'stacksets.yaml'); do
47+
_dir="$(dirname $_f)/" \
48+
yq \
49+
-i \
50+
'(.. | select(has("localTemplateFile")) | .localTemplateFile) |= load_str(strenv(_dir) + .)' \
51+
$_f;
52+
done
5953
60-
- name: Assume AWS Credentials
61-
uses: ServerlessOpsIO/gha-assume-aws-credentials@v1
54+
- name: Package Stackset template
55+
id: package-stackset
56+
uses: ServerlessOpsIO/gha-package-aws-sam@v1
6257
with:
63-
build_aws_account_id: ${{ secrets.AWS_CICD_ACCOUNT_ID }}
64-
deploy_aws_account_id: ${{ secrets.AWS_MANAGEMENT_ACCOUNT_ID }}
58+
template_file: stacksets.yaml
59+
packaged_template_file: packaged-stacksets.yaml
6560

66-
- name: Deploy via AWS SAM
67-
uses: ServerlessOpsIO/gha-deploy-aws-sam@v1
61+
- name: Store Artifacts
62+
uses: ServerlessOpsIO/gha-store-artifacts@v2
6863
with:
69-
aws_account_id: ${{ secrets.AWS_MANAGEMENT_ACCOUNT_ID }}
70-
env_json: ${{ toJson(env) }}
71-
secrets_json: ${{ toJson(secrets) }}
64+
use_aws_sam: true

‎.github/workflows/main.yml‎

Lines changed: 54 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -8,55 +8,93 @@ on:
88

99
jobs:
1010
build:
11+
name: Build
1112
runs-on: ubuntu-latest
1213
permissions:
1314
id-token: write
1415
contents: read
1516

1617
steps:
1718
- name: Setup job workspace
18-
uses: ServerlessOpsIO/gha-setup-workspace@v1
19+
uses: ServerlessOpsIO/gha-setup-workspace@v2
1920

2021
- name: Assume AWS Credentials
2122
uses: ServerlessOpsIO/gha-assume-aws-credentials@v1
2223
with:
2324
build_aws_account_id: ${{ secrets.AWS_CICD_ACCOUNT_ID }}
2425

2526
- name: Install AWS SAM
26-
uses: aws-actions/setup-sam@v2
27-
27+
uses: aws-actions/setup-sam@v3
2828

2929
- name: Validate template
3030
run: sam validate --lint
3131

32-
- name: Validate template (userpool stackset)
33-
run: sam validate --lint --template ./stacksets/userpool/stackset.yaml
32+
- name: Validate template (stackset)
33+
run: sam validate --lint --template stacksets.yaml
3434

35-
- name: Validate template (products stackset)
36-
run: sam validate --lint --template ./products/stackset.yaml
35+
- name: Validate template (products template)
36+
run: sam validate --lint --template ./products/products.yaml
3737

3838
- name: Validate template (client product)
39-
run: sam validate --lint --template ./products/client/product.yaml
39+
run: sam validate --lint --template ./products/client/template.yaml
4040

4141
- name: Validate template (server product)
42-
run: sam validate --lint --template ./products/server/product.yaml
42+
run: sam validate --lint --template ./products/server/template.yaml
4343

4444
- name: Synethsize StackSet templates
4545
run: |
46-
for _f in $(find . -type f -name 'template.yaml'); do
46+
for _f in $(find . -type f -name 'stacksets.yaml'); do
4747
_dir="$(dirname $_f)/" \
4848
yq \
4949
-i \
5050
'(.. | select(has("localTemplateFile")) | .localTemplateFile) |= load_str(strenv(_dir) + .)' \
5151
$_f;
5252
done
5353
54+
- name: Package Stackset template
55+
id: package-stackset
56+
uses: ServerlessOpsIO/gha-package-aws-sam@v1
57+
with:
58+
template_file: stacksets.yaml
59+
packaged_template_file: packaged-stacksets.yaml
60+
5461
- name: Store Artifacts
55-
uses: ServerlessOpsIO/gha-store-artifacts@v1
62+
uses: ServerlessOpsIO/gha-store-artifacts@v2
5663
with:
5764
use_aws_sam: true
5865

59-
deploy:
66+
deploy_authnz:
67+
name: Deploy Authnz Service
68+
needs:
69+
- build
70+
environment: production
71+
runs-on: ubuntu-latest
72+
permissions:
73+
id-token: write
74+
contents: read
75+
76+
steps:
77+
- name: Setup job workspace
78+
uses: ServerlessOpsIO/gha-setup-workspace@v2
79+
with:
80+
checkout_artifact: true
81+
82+
- name: Assume AWS Credentials
83+
uses: ServerlessOpsIO/gha-assume-aws-credentials@v1
84+
with:
85+
build_aws_account_id: ${{ secrets.AWS_CICD_ACCOUNT_ID }}
86+
deploy_aws_account_id: ${{ secrets.DEPLOYMENT_ACCOUNT_ID }}
87+
88+
- name: Deploy via AWS SAM
89+
uses: ServerlessOpsIO/gha-deploy-aws-sam@v1
90+
with:
91+
aws_account_id: ${{ secrets.DEPLOYMENT_ACCOUNT_ID }}
92+
env_json: ${{ toJson(env) }}
93+
vars_json: ${{ toJson(vars) }}
94+
secrets_json: ${{ toJson(secrets) }}
95+
96+
deploy_stacksets:
97+
name: Deploy Authnz Products
6098
needs:
6199
- build
62100
environment: production
@@ -67,7 +105,7 @@ jobs:
67105

68106
steps:
69107
- name: Setup job workspace
70-
uses: ServerlessOpsIO/gha-setup-workspace@v1
108+
uses: ServerlessOpsIO/gha-setup-workspace@v2
71109
with:
72110
checkout_artifact: true
73111

@@ -88,5 +126,8 @@ jobs:
88126
uses: ServerlessOpsIO/gha-deploy-aws-sam@v1
89127
with:
90128
aws_account_id: ${{ secrets.AWS_MANAGEMENT_ACCOUNT_ID }}
129+
template_file: packaged-stacksets.yaml
130+
cfn_parameters_file: cfn-parameters-stacksets.json
91131
env_json: ${{ toJson(env) }}
132+
vars_json: ${{ toJson(vars) }}
92133
secrets_json: ${{ toJson(secrets) }}

‎cfn-parameters-stacksets.json‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,6 @@
44
"Component": $env.GITHUB_REPOSITORY_NAME_PART_SLUG_CS,
55
"TargetOuIds": $secrets.DEPLOYMENT_TARGET_OU,
66
"TargetRegions": "us-east-1",
7-
"TargetAccountIds": $secrets.DEPLOYMENT_TARGET_ACCOUNT_ID,
87
"GitHubSha": $env.GITHUB_SHA,
98
"CfnTemplateBucket": $secrets.CFN_TEMPLATE_BUCKET
109
}

‎products/products.yaml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
AWSTemplateFormatVersion: '2010-09-09'
2-
Description: Create a Cognito Resource Server
2+
Description: ServerlessOps API Authnz Service Catalog Products
33

44
Parameters:
55
GitHubSha:
@@ -44,7 +44,7 @@ Resources:
4444
- Name: latest
4545
Description: latest release
4646
Info:
47-
LoadTemplateFromURL: !Sub 'https://${CfnTemplateBucket}.s3.amazonaws.com/serverlessops-api-authnz/${GitHubSha}/server/product.yaml'
47+
LoadTemplateFromURL: !Sub 'https://${CfnTemplateBucket}.s3.amazonaws.com/serverlessops-api-authnz/${GitHubSha}/server/template.yaml'
4848

4949
CognitoResourceServerProductAssociation:
5050
Type: AWS::ServiceCatalog::PortfolioProductAssociation
@@ -62,7 +62,7 @@ Resources:
6262
- Name: latest
6363
Description: latest release
6464
Info:
65-
LoadTemplateFromURL: !Sub 'https://${CfnTemplateBucket}.s3.amazonaws.com/serverlessops-api-authnz/${GitHubSha}/client/product.yaml'
65+
LoadTemplateFromURL: !Sub 'https://${CfnTemplateBucket}.s3.amazonaws.com/serverlessops-api-authnz/${GitHubSha}/client/template.yaml'
6666

6767
CognitoUserPoolClientProductAssociation:
6868
Type: AWS::ServiceCatalog::PortfolioProductAssociation

‎stacksets.yaml‎

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,6 @@ Parameters:
1212
TargetOuIds:
1313
Type: CommaDelimitedList
1414
Description: "Organizational Units to deploy to"
15-
TargetAccountIds:
16-
Type: CommaDelimitedList
17-
Description: "Accounts to deploy to"
1815
GitHubSha:
1916
Type: String
2017
Description: GitHub SHA
@@ -35,9 +32,7 @@ Resources:
3532
ParameterValue: !Ref CfnTemplateBucket
3633
StackInstancesGroup:
3734
- DeploymentTargets:
38-
AccountFilterType: INTERSECTION
3935
OrganizationalUnitIds: !Ref TargetOuIds
40-
Accounts: !Ref TargetAccountIds
4136
Regions: !Ref TargetRegions
4237
AutoDeployment:
4338
Enabled: true

0 commit comments

Comments
 (0)