Repository navigation
Conversation
The ECR repository and ECS service the old workflow targeted no longer exist. A push to main now dispatches deploy-mvp.yml in Kntro-Soft/reqsai-infra with api_ref set to the pushed commit, using the INFRA_DEPLOY_TOKEN secret; without the secret the job only logs a notice.
Contributor
Author
|
Follow-up commit: the deploy trigger now passes |
6 of 16 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Replaces the obsolete
deploy.yml. It built an image, pushed it to ECR and updated an ECS Fargate service, but that AWS stack (ECR repository, ECS cluster and service, the GitHub OIDC provider and thegithub-actions-apirole) no longer exists, so the workflow would fail on the next push tomain.Production now runs on a single EC2 instance (https://reqsai.tech), and its deploy pipeline lives in
Kntro-Soft/reqsai-infra(.github/workflows/deploy-mvp.yml, see Kntro-Soft/reqsai-infra#7). This workflow only triggers it:main(or a manual run frommain), it runsgh workflow run deploy-mvp.yml --repo Kntro-Soft/reqsai-infra --ref main -f api_ref=<pushed SHA>. The infra workflow builds thelinux/arm64image from that exact commit on a free arm64 runner, uploads it to the instance over SSH tunnelled through SSM, recreates the container and checks/actuator/health.web_refkeeps its default,main.INFRA_DEPLOY_TOKEN. If the secret is missing, the job logs a notice and succeeds, somainnever goes red because of the deploy.mainare skipped. To deploy a branch, run the infra workflow withapi_ref=<branch>.Bounded context / area: ci
Related issue / US: —
Type of Change
feat— new featurefix— bug fixrefactor— code change without behavior changetest— tests onlydocs— documentation onlybuild/ci— build, dependencies, or CI/CDchore— maintenanceChecklist
develop(notmain)feature/*,bugfix/*, orhotfix/*: the branch isci/deploy-via-infra, matching thecitype of the change../gradlew buildpasses locally (compile + tests +verifyModularity): not applicable, no Java changes.actionlint, and the infra pipeline it calls was validated with a real deploy (see the infra PR)..pemkeys are committedCHANGELOG.mdupdated under[Unreleased]common/ortenant/): not applicable.How to Test
INFRA_DEPLOY_TOKEN: after merge, any push tomainshows a greenDeployrun with the notice "Deploy not triggered".maincreates aDeploy MVPrun in https://github.com/Kntro-Soft/reqsai-infra/actions/workflows/deploy-mvp.yml withapi_refset to the pushed SHA. The run summary shows the ref and the commit of each image.Notes / Screenshots (optional)
Creating
INFRA_DEPLOY_TOKEN(one-time, an org member with admin on reqsai-infra)GITHUB_TOKENcannot start workflows in another repository, so the dispatch needs its own token:Kntro-Soft. Expiration: the shortest you are willing to rotate (for example 90 days).Kntro-Soft/reqsai-infra.ghprompts for the value without echoing it:The token can only start or cancel workflows in reqsai-infra. The AWS role, the SSH key and the vault stay in the infra repo's
mvpenvironment, which only itsmainbranch can use.Order
Create the token only once
mainof both reqsai-api and reqsai-web holds the code that should run in production. A push tomainhere deploys reqsai-web'smaintoo, so a stalemainon the other repo would roll it back. The infra workflow must also be on reqsai-inframain(merge Kntro-Soft/reqsai-infra#7 first).