Repository navigation
updated GHA workflows - #4
Conversation
Reviewer's GuideThis PR modernizes and hardens the GitHub Actions workflows for CloudFormation deployment and automatic branch deletion by updating deprecated syntax, aligning action versions, adding Python dependency management, and cleaning up minor naming and parameter issues. Sequence diagram for updated GitHub Actions CloudFormation deploymentsequenceDiagram
actor Dev
participant GitHub as GitHub_Repo
participant WF as GHA_Workflow_cft_deploy
participant JobEnv as Job_ENV
participant JobDep as Job_DeployCloudFormation
participant AWSIAM as AWS_IAM_Role
participant AWSS3 as AWS_S3_Bucket
participant AWSCF as AWS_CloudFormation
Dev->>GitHub: Push commit to deployment branch
GitHub->>WF: Trigger cft-deploy workflow on push
WF->>JobEnv: Start job ENV
JobEnv->>JobEnv: Get UTC date output via GITHUB_OUTPUT
JobEnv->>JobEnv: Determine environment_name based on branch
JobEnv-->>WF: Output environment_name
WF->>JobDep: Start job DeployCloudFormation with environment outputs
JobDep->>JobDep: Checkout code using actions/checkout v6
JobDep->>JobDep: Run cfn-lint GitHub Action and lint template.yml
JobDep->>JobDep: Setup Python 3.13 and install pip dependencies
JobDep->>JobDep: Set BRANCH env and file permissions
JobDep->>AWSIAM: Resolve deployment role per environment
AWSIAM-->>JobDep: Deployment role ARN
JobDep->>AWSIAM: Assume role via AWS credentials action
AWSIAM-->>JobDep: Temporary AWS credentials
JobDep->>JobDep: Setup AWS SAM CLI
JobDep->>JobDep: Run sam build using container
JobDep->>AWSS3: sam package uploads build artifacts and template
AWSS3-->>JobDep: Packaged template URL
JobDep->>AWSS3: Sync lambda directory and upload template.yml
JobDep->>AWSCF: Deploy stack with packaged template and parameters
AWSCF-->>JobDep: Stack update or create result
JobDep-->>WF: Job success
WF-->>GitHub: Report workflow status
GitHub-->>Dev: Show deployment result in checks
Flow diagram for updated CloudFormation deployment job stepsflowchart TD
A[Push to target branch] --> B[Job ENV Get Date]
B --> C[Job ENV Determine environment_name]
C --> D[Job DeployCloudFormation starts]
D --> E[Checkout repository with actions/checkout@v6]
E --> F[Run cfn-lint GitHub Action]
F --> G[Print cfn-lint version and lint template.yml]
G --> H[Setup Python 3.13 with actions/setup-python@v6]
H --> I[Install pip dependencies from requirements.txt]
I --> J[Set BRANCH environment variable]
J --> K[Set read permissions on tags dev qa prod json]
K --> L[Set DEPLOYMENT_ENV role arn and S3 bucket based on branch]
L --> M[Configure AWS credentials via assumed role]
M --> N[Setup AWS SAM]
N --> O[Run sam build using container]
O --> P[Run sam package to upload build artifacts and template.yml]
P --> Q[Upload lambda code and template.yml directly to S3]
Q --> R[Deploy or update CloudFormation stack with parameter overrides]
R --> S[Workflow completes]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 3 issues, and left some high level feedback:
- The workflow now references
actions/checkout@v6andactions/setup-python@v6, which do not exist yet; consider pinning to the latest stable major versions (e.g.@v4/@v5) and ideally to specific commit SHAs for reliability. - You’ve switched the runtime to Python 3.13, which is still very new and may not be fully supported by SAM or some dependencies; consider staying on 3.12 unless you have a specific need and have verified compatibility.
- The previous
aws s3 syncofconfig/andglue/directories was removed from the deployment workflow; if those assets are still needed by your stacks, you may want to retain or replace that sync step to avoid changing deployment behavior unintentionally.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- The workflow now references `actions/checkout@v6` and `actions/setup-python@v6`, which do not exist yet; consider pinning to the latest stable major versions (e.g. `@v4`/`@v5`) and ideally to specific commit SHAs for reliability.
- You’ve switched the runtime to Python 3.13, which is still very new and may not be fully supported by SAM or some dependencies; consider staying on 3.12 unless you have a specific need and have verified compatibility.
- The previous `aws s3 sync` of `config/` and `glue/` directories was removed from the deployment workflow; if those assets are still needed by your stacks, you may want to retain or replace that sync step to avoid changing deployment behavior unintentionally.
## Individual Comments
### Comment 1
<location> `.github/workflows/cft-deploy.yml:52-53` </location>
<code_context>
contents: read
steps:
- name: Checkout
- uses: actions/checkout@v2
-
+ uses: actions/checkout@v6
+
- name: cfn-lint-action
</code_context>
<issue_to_address>
**issue (bug_risk):** Using `actions/checkout@v6` is likely invalid and will break the workflow.
`actions/checkout` only has published versions up to `v4`. Using `@v6` will fail at runtime with `Action not found`. Please update this to a valid version (e.g. `@v4`).
</issue_to_address>
### Comment 2
<location> `.github/workflows/auto-delete-merged-branch.yml:15-16` </location>
<code_context>
runs-on: ubuntu-latest
steps:
- name: Checkout code
- uses: actions/checkout@v4
-
+ uses: actions/checkout@v6
+
- name: Run if Pull Request is merged/closed
</code_context>
<issue_to_address>
**issue (bug_risk):** The auto-delete workflow also references a non-existent `actions/checkout@v6`.
This version of `actions/checkout` doesn’t exist and will cause the workflow to fail. Please switch to a valid version (e.g., `actions/checkout@v4`).
</issue_to_address>
### Comment 3
<location> `.github/workflows/cft-deploy.yml:126-129` </location>
<code_context>
- name: Run AWS SAM Build
run: sam build --use-container --template-file template.yml
-
- - name: sam package
- run: sam package --template-file .aws-sam/build/template.yaml --s3-bucket ${{env.S3_BUCKET}} --output-template-file template.yml --kms-key-id alias/aws/s3
- - name: Upload CloudFormation Template to S3
+ - name: Run AWS SAM Package
run: |
</code_context>
<issue_to_address>
**question (bug_risk):** Config and glue asset uploads to S3 were removed; confirm if those artifacts are no longer required.
If any existing stacks or downstream jobs still read `config/` or `glue/` from this S3 bucket, they’ll fail once those paths stop being uploaded. If these assets are truly deprecated, no change needed; otherwise consider restoring or replacing the previous sync behavior.
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
| - name: Checkout | ||
| uses: actions/checkout@v2 | ||
| uses: actions/checkout@v6 |
There was a problem hiding this comment.
issue (bug_risk): Using actions/checkout@v6 is likely invalid and will break the workflow.
actions/checkout only has published versions up to v4. Using @v6 will fail at runtime with Action not found. Please update this to a valid version (e.g. @v4).
| - name: Checkout code | ||
| uses: actions/checkout@v4 | ||
| uses: actions/checkout@v6 |
There was a problem hiding this comment.
issue (bug_risk): The auto-delete workflow also references a non-existent actions/checkout@v6.
This version of actions/checkout doesn’t exist and will cause the workflow to fail. Please switch to a valid version (e.g., actions/checkout@v4).
| - name: sam package | ||
| run: sam package --template-file .aws-sam/build/template.yaml --s3-bucket ${{env.S3_BUCKET}} --output-template-file template.yml --kms-key-id alias/aws/s3 | ||
|
|
||
| - name: Upload CloudFormation Template to S3 |
There was a problem hiding this comment.
question (bug_risk): Config and glue asset uploads to S3 were removed; confirm if those artifacts are no longer required.
If any existing stacks or downstream jobs still read config/ or glue/ from this S3 bucket, they’ll fail once those paths stop being uploaded. If these assets are truly deprecated, no change needed; otherwise consider restoring or replacing the previous sync behavior.
Summary by Sourcery
Update GitHub Actions workflows for CloudFormation deployment and post-merge branch cleanup to use modern patterns and dependencies.
Build:
CI: