Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/auto-delete-merged-branch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,8 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v6
Comment on lines 15 to +16

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

issue (bug_risk): The auto-delete workflow also references a non-existent actions/checkout@v6.

This version of actions/checkout doesn’t exist and will cause the workflow to fail. Please switch to a valid version (e.g., actions/checkout@v4).


- name: Run if Pull Request is merged/closed
run: |
if [ "${{github.event.pull_request.merged}}" == "true" ]; then
Expand Down
66 changes: 32 additions & 34 deletions .github/workflows/cft-deploy.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,4 @@
name: Deploy Cloudformation

# on:
# push:
# branches: [master, main, qa, stage-qa, dev, develop]
name: Deploy CloudFormation

on:
push:
Expand All @@ -27,24 +23,25 @@ jobs:
steps:
- name: Get Date
id: getDate
run: echo "::set-output name=date::$(/bin/date -u "+%Y%m%d%H")"
run: echo "date=$(date -u +%Y%m%d%H)" >> $GITHUB_OUTPUT
shell: bash
- name: environment

- name: Environment
id: getEnvironment
env:
BRANCH: ${{github.ref_name}}
PRD_BRANCH: main
QA_BRANCH: qa
run: |
case "$BRANCH" in
"$PRD_BRANCH") echo "::set-output name=environment_name::prd" ;;
"$QA_BRANCH") echo "::set-output name=environment_name::qa" ;;
*) echo "::set-output name=environment_name::dev" ;;
"$PRD_BRANCH") echo "environment_name=prd" >> $GITHUB_OUTPUT ;;
"$QA_BRANCH") echo "environment_name=qa" >> $GITHUB_OUTPUT ;;
*) echo "environment_name=dev" >> $GITHUB_OUTPUT ;;
esac
shell: bash

DeployCloudformation:
name: Deploy Cloudformation
DeployCloudFormation:
name: Deploy CloudFormation
needs: [ENV]
environment: ${{needs.ENV.outputs.Env}}
runs-on: ubuntu-latest
Expand All @@ -53,26 +50,35 @@ jobs:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v2
uses: actions/checkout@v6
Comment on lines 52 to +53

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

issue (bug_risk): Using actions/checkout@v6 is likely invalid and will break the workflow.

actions/checkout only has published versions up to v4. Using @v6 will fail at runtime with Action not found. Please update this to a valid version (e.g. @v4).


- name: cfn-lint-action
uses: ScottBrenner/cfn-lint-action@v2.2.9
- name: Print the Cloud Formation Linter Version & run Linter.
uses: ScottBrenner/cfn-lint-action@v2

- name: Print the CloudFormation Linter Version & Run Linter
run: |
cfn-lint --version
cfn-lint -t ./template.yml -i W3002


- name: Setup Python
uses: actions/setup-python@v6
with:
python-version: 3.13
cache: 'pip' # caching pip dependencies

- name: Installing pip dependencies
run: pip install -r ${GITHUB_WORKSPACE}/.github/workflows/requirements.txt

- name: Set env BRANCH
run: echo "BRANCH=$(echo $GITHUB_REF | cut -d'/' -f 3)" >> $GITHUB_ENV

- name: Set permissions for tags.*.json
run: |
chmod +r ./tags.dev.json
chmod +r ./tags.qa.json
chmod +r ./tags.prod.json

- name: Set env DEPLOYMENT_ENV and DEPLOYMENT_ROLE_ARN and S3_BUCKET
- name: Set DEPLOYMENT_ENV and DEPLOYMENT_ROLE_ARN and S3_BUCKET
env:
DEV_DEPLOYMENT_ROLE: ${{ vars.DEPLOYMENT_ROLE_DEV }}
QA_DEPLOYMENT_ROLE: ${{ vars.DEPLOYMENT_ROLE_QA }}
Expand Down Expand Up @@ -110,26 +116,18 @@ jobs:
role-to-assume: ${{env.DEPLOYMENT_ROLE_ARN}}
aws-region: ${{vars.AWS_REGION}}

- name: Setup Python
uses: actions/setup-python@v3
continue-on-error: true
with:
python-version: 3.12
cache: 'pip'

- name: Setup AWS SAM
uses: aws-actions/setup-sam@v2

- name: Run AWS SAM Build
run: sam build --use-container --template-file template.yml

- name: sam package
run: sam package --template-file .aws-sam/build/template.yaml --s3-bucket ${{env.S3_BUCKET}} --output-template-file template.yml --kms-key-id alias/aws/s3

- name: Upload CloudFormation Template to S3
Comment on lines -126 to -129

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

question (bug_risk): Config and glue asset uploads to S3 were removed; confirm if those artifacts are no longer required.

If any existing stacks or downstream jobs still read config/ or glue/ from this S3 bucket, they’ll fail once those paths stop being uploaded. If these assets are truly deprecated, no change needed; otherwise consider restoring or replacing the previous sync behavior.

- name: Run AWS SAM Package
run: |
aws s3 sync config/ s3://${{env.S3_BUCKET}}/${{github.event.repository.name}}/config/
aws s3 sync glue/ s3://${{env.S3_BUCKET}}/${{github.event.repository.name}}/glue/
sam package --template-file .aws-sam/build/template.yaml --s3-bucket ${{env.S3_BUCKET}} --output-template-file template.yml --kms-key-id alias/aws/s3

- name: Upload CloudFormation Template to S3
run: |
aws s3 sync lambda/ s3://${{env.S3_BUCKET}}/${{github.event.repository.name}}/lambda/
aws s3 cp ./template.yml s3://${{env.S3_BUCKET}}/${{github.event.repository.name}}/template.yml

Expand All @@ -139,6 +137,6 @@ jobs:
name: pipeline-${{github.event.repository.name}}-deployment
template: https://s3.amazonaws.com/${{env.S3_BUCKET}}/${{github.event.repository.name}}/template.yml
parameter-overrides: file://${{github.workspace}}/params.${{env.DEPLOYMENT_ENV}}.json
capabilities: CAPABILITY_IAM,CAPABILITY_AUTO_EXPAND, CAPABILITY_NAMED_IAM
capabilities: CAPABILITY_IAM, CAPABILITY_AUTO_EXPAND, CAPABILITY_NAMED_IAM
no-fail-on-empty-changeset: "1"
tags: ${{env.DEPLOYMENT_TAGS}}
2 changes: 2 additions & 0 deletions .github/workflows/requirements.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
requests
boto3
Loading