Repository navigation
feat: GitHub Actions deploy pipeline for the MVP host - #7
Merged
Merged
Conversation
…e MVP host The role trusts only repo:Kntro-Soft/reqsai-infra:environment:mvp. It may start AWS-StartSSHSession sessions on this instance (with the session document access check, so no default shell), use sessions whose ID starts with the deploy role session name, and describe instances.
Only archives present in app_images_archive_dir are uploaded. The role then requires both archive images on the host, so a config-only run or a single-app deploy reuses the image that is already loaded.
…em over SSM Builds reqsai-api and reqsai-web for linux/arm64 on free arm64 runners, ships them as artifacts and runs the app role through SSH tunnelled over SSM with an OIDC role, then requires UP from /actuator/health. Pushes to main that touch ansible/ or compose/ redeploy the configuration only.
This was referenced Oct 7, 2026
6 of 16 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Continuous deployment for the single-EC2 MVP (https://reqsai.tech) with GitHub Actions. It automates the registry-free flow from #6 (build
linux/arm64image archives, upload them with Ansible,docker load,docker compose up), and it costs nothing extra: free arm64 runners for public repos, one-day artifacts, and IAM/OIDC only. Port 22 stays closed to the internet: the runner reaches the host through SSH tunnelled over SSM.#6 is already merged, so this PR targets
maindirectly.What changes
Terraform (
envs/ec2-compose/github-deploy.tf, already applied)token.actions.githubusercontent.com.reqsai-mvp-github-deploy. Only a token withsub = repo:Kntro-Soft/reqsai-infra:environment:mvpandaud = sts.amazonaws.comcan assume it.ssm:StartSessionon this instance with theAWS-StartSSHSessiondocument only, plusssm:SessionDocumentAccessCheck, so the role cannot open the default shell document.ssm:TerminateSession,ssm:ResumeSessionandssmmessages:OpenDataChannelon sessions namedreqsai-mvp-deploy-*, the role session name the workflow sets.ec2:DescribeInstances.github_deploy_repository,github_deploy_environmentandgithub_oidc_provider_arn; new outputgithub_deploy_role_arn.Ansible
base:base_authorized_keyslist, applied by a task taggedauthorized_keys. It only adds keys.app(archive.yml): uploads only the archives present inapp_images_archive_dir, then requires bothreqsai-*:archiveimages on the host. This lets a run deploy one app, or only configuration, and keep the other image that is already loaded.Workflow
.github/workflows/deploy-mvp.ymlworkflow_dispatchwithapi_refandweb_ref, both defaulting tomain;repository_dispatchof typedeploy-mvp, with optional refs inclient_payloadthat also default tomain;pushtomainonansible/**,compose/**or the workflow. This deployskeep/keep, which re-applies configuration without rebuilding or changing app versions.concurrency: deploy-mvpwith no cancellation.refsvalidates the refs and builds the matrix.buildruns onubuntu-24.04-armand doesdocker buildx build --platform linux/arm64 --load, thendocker save | gzip -1, then uploads an artifact kept for one day. Images carry the OCI labelssourceandrevision.deployruns onubuntu-latestin themvpenvironment:.deb, pinned to version 1.2.835.0 with its SHA-256 checked;ansible-core2.21.5 and the collections;umask 077temp dir;ansible-playbook site.yml --tags appagainst the instance ID through an SSMProxyCommand;UPfromhttps://reqsai.tech/actuator/health;Docs: new section 14 "Despliegue continuo con GitHub Actions" in
docs/deploy-ec2-docker-compose.md. It covers the architecture, secrets and variables, how to run a deploy, rollback by deploying an older ref, the PAT for auto-deploy from the app repos, and troubleshooting.Configured outside the repo (done)
terraform applyinenvs/ec2-compose: 3 resources added (OIDC provider, role, inline policy). After the first run showed that session IDs are<role-session-name>-<random>, a second apply changed the inline policy in place (1 changed) to scope sessions toreqsai-mvp-deploy-*.reqsai-mvp-github-deploy(ed25519). It is authorized on the host with--tags authorized_keys, usingfrom="127.0.0.1,::1",no-agent-forwarding,no-port-forwarding,no-X11-forwarding. SSM connects to sshd from localhost, so the key only works through the SSM tunnel. The private key exists only as an environment secret.mvp. Deployment branches:mainonly. It was temporarily opened to this branch for validation, and that permission has been removed.ANSIBLE_VAULT_PASSWORD,ANSIBLE_VAULT_B64,ANSIBLE_EXTRA_VARS_B64,DEPLOY_SSH_PRIVATE_KEY.AWS_DEPLOY_ROLE_ARN,AWS_REGION,EC2_INSTANCE_ID,APP_URL.Validation (real runs against production)
The
mainbranches of reqsai-api and reqsai-web do not contain the MVP code yet, somainwas not deployed. A temporary commit, now dropped from this branch, added apushtrigger for this branch.api_ref=deploy/mvp-preview:a69aac3c, the integration of reqsai-api #89 and #90 that was already running, and the same tree asdevelopnow.web_ref=feature/mvp-ux-polish:410c4f5, a descendant of the commit that was running and identical todevelopnow.reqsai-api:archiveandreqsai-web:archiveimages whose labels show those SHAs, andapi/webrecreated at 13:32:51Z.dbandcaddywere untouched, and the config files were unchanged (ok).StartSessionsucceeded with no AccessDenied.keep/keep), https://github.com/Kntro-Soft/reqsai-infra/actions/runs/37629813006, success in 49s. It ran withchanged=0and no container was recreated. This is what the merge of this PR triggers.https://reqsai.tech/actuator/healthreturnsUP.After merging
keep/keep): no build, no version change, and health is checked.INFRA_DEPLOY_TOKENin reqsai-api and reqsai-web. See section 14.5 and the companion PRs (ci: deploy main through the reqsai-infra MVP pipeline reqsai-api#91, ci: deploy main through the reqsai-infra MVP pipeline reqsai-web#46).mainof both app repos holds the code that should run in production. Until then, a push to one app'smainwould deploy the other app's stalemain.