Skip to content

ci: deploy main through the reqsai-infra MVP pipeline - #91

Closed
jhosepmyr wants to merge 2 commits into
developfrom
ci/deploy-via-infra
Closed

jhosepmyr wants to merge 2 commits into
developfrom
ci/deploy-via-infra

Conversation

@jhosepmyr

Copy link
Copy Markdown
Contributor

Description

Replaces the obsolete deploy.yml. It built an image, pushed it to ECR and updated an ECS Fargate service, but that AWS stack (ECR repository, ECS cluster and service, the GitHub OIDC provider and the github-actions-api role) no longer exists, so the workflow would fail on the next push to main.

Production now runs on a single EC2 instance (https://reqsai.tech), and its deploy pipeline lives in Kntro-Soft/reqsai-infra (.github/workflows/deploy-mvp.yml, see Kntro-Soft/reqsai-infra#7). This workflow only triggers it:

  • On push to main (or a manual run from main), it runs gh workflow run deploy-mvp.yml --repo Kntro-Soft/reqsai-infra --ref main -f api_ref=<pushed SHA>. The infra workflow builds the linux/arm64 image from that exact commit on a free arm64 runner, uploads it to the instance over SSH tunnelled through SSM, recreates the container and checks /actuator/health. web_ref keeps its default, main.
  • It authenticates with a new repository secret, INFRA_DEPLOY_TOKEN. If the secret is missing, the job logs a notice and succeeds, so main never goes red because of the deploy.
  • Manual runs from any branch other than main are skipped. To deploy a branch, run the infra workflow with api_ref=<branch>.

Bounded context / area: ci

Related issue / US: —


Type of Change

  • feat — new feature
  • fix — bug fix
  • refactor — code change without behavior change
  • test — tests only
  • docs — documentation only
  • build / ci — build, dependencies, or CI/CD
  • chore — maintenance

Checklist

  • The PR targets develop (not main)
  • Branch name follows feature/*, bugfix/*, or hotfix/*: the branch is ci/deploy-via-infra, matching the ci type of the change.
  • Commits follow Conventional Commits
  • ./gradlew build passes locally (compile + tests + verifyModularity): not applicable, no Java changes.
  • New cross-module access respects module boundaries (no reaching into another module's internals): not applicable, no Java changes.
  • Added/updated tests for the change (Testcontainers for DB-dependent code): not applicable. The workflow passes actionlint, and the infra pipeline it calls was validated with a real deploy (see the infra PR).
  • No secrets, credentials, or .pem keys are committed
  • CHANGELOG.md updated under [Unreleased]
  • Database changes are expressed as Flyway migrations (common/ or tenant/): not applicable.

How to Test

  1. Without INFRA_DEPLOY_TOKEN: after merge, any push to main shows a green Deploy run with the notice "Deploy not triggered".
  2. With the token: a push to main creates a Deploy MVP run in https://github.com/Kntro-Soft/reqsai-infra/actions/workflows/deploy-mvp.yml with api_ref set to the pushed SHA. The run summary shows the ref and the commit of each image.

Notes / Screenshots (optional)

Creating INFRA_DEPLOY_TOKEN (one-time, an org member with admin on reqsai-infra)

GITHUB_TOKEN cannot start workflows in another repository, so the dispatch needs its own token:

  1. If the organization blocks fine-grained tokens or requires approval: Kntro-Soft → Settings → Personal access tokens → Settings, allow fine-grained tokens (an owner approves the request if approval is on).
  2. Settings → Developer settings → Personal access tokens → Fine-grained tokens → Generate new token.
  3. Resource owner: Kntro-Soft. Expiration: the shortest you are willing to rotate (for example 90 days).
  4. Repository access: Only select repositories → Kntro-Soft/reqsai-infra.
  5. Repository permissions: Actions: Read and write (GitHub adds Metadata: Read-only). Nothing else.
  6. Store it in both app repos; gh prompts for the value without echoing it:
    gh secret set INFRA_DEPLOY_TOKEN -R Kntro-Soft/reqsai-api
    gh secret set INFRA_DEPLOY_TOKEN -R Kntro-Soft/reqsai-web

The token can only start or cancel workflows in reqsai-infra. The AWS role, the SSH key and the vault stay in the infra repo's mvp environment, which only its main branch can use.

Order

Create the token only once main of both reqsai-api and reqsai-web holds the code that should run in production. A push to main here deploys reqsai-web's main too, so a stale main on the other repo would roll it back. The infra workflow must also be on reqsai-infra main (merge Kntro-Soft/reqsai-infra#7 first).

The ECR repository and ECS service the old workflow targeted no longer
exist. A push to main now dispatches deploy-mvp.yml in
Kntro-Soft/reqsai-infra with api_ref set to the pushed commit, using the
INFRA_DEPLOY_TOKEN secret; without the secret the job only logs a notice.
@jhosepmyr

Copy link
Copy Markdown
Contributor Author

Follow-up commit: the deploy trigger now passes web_ref=keep, so a push to this repo's main redeploys only the API and leaves the running web image untouched (before, it defaulted the web to main). INFRA_DEPLOY_TOKEN is now configured as a repo secret.

@jhosepmyr jhosepmyr closed this Oct 7, 2026
@jhosepmyr
jhosepmyr deleted the ci/deploy-via-infra branch October 7, 2026 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant