Repository navigation
ci: deploy main through the reqsai-infra MVP pipeline - #46
Merged
Merged
Conversation
…nd CloudFront The S3 bucket and CloudFront distribution the old workflow targeted no longer exist. A push to main now dispatches deploy-mvp.yml in Kntro-Soft/reqsai-infra with web_ref set to the pushed commit, using the INFRA_DEPLOY_TOKEN secret; without the secret the job only logs a notice.
Contributor
Author
|
Follow-up commit: the deploy trigger now passes |
This was referenced Oct 7, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Replaces the obsolete
deploy.yml. It built the app, synced it to an S3 bucket and invalidated a CloudFront distribution, but that AWS stack (bucket, distribution, GitHub OIDC provider andgithub-actions-webrole) no longer exists, so the workflow would fail on the next push tomain.Production now runs on a single EC2 instance (https://reqsai.tech), where the frontend is the nginx image from this repo's
Dockerfile. The deploy pipeline lives inKntro-Soft/reqsai-infra(.github/workflows/deploy-mvp.yml, see Kntro-Soft/reqsai-infra#7). This workflow only triggers it:main(or a manual run frommain), it runsgh workflow run deploy-mvp.yml --repo Kntro-Soft/reqsai-infra --ref main -f web_ref=<pushed SHA>. The infra workflow builds thelinux/arm64image from that exact commit on a free arm64 runner, uploads it to the instance over SSH tunnelled through SSM, recreates the container and checks the public health endpoint.api_refkeeps its default,main.INFRA_DEPLOY_TOKEN. If the secret is missing, the job logs a notice and succeeds, somainnever goes red because of the deploy.mainare skipped. To deploy a branch, run the infra workflow withweb_ref=<branch>.Cache headers:
nginx.confinside the image already servesindex.htmlwithno-cacheand hashed assets asimmutable, as the S3 upload did. One gap carried over from the image (not introduced here):i18n/*.jsongets no explicitCache-Controlfrom nginx, while the S3 upload setno-cache,must-revalidate, so browsers may keep old translations for a while after a deploy. Worth a small follow-up innginx.conf.Feature module / area: ci
Related issue / US: —
Type of Change
feat— new feature or UI componentfix— bug fixrefactor— code change without behavior changetest— tests onlydocs— documentation onlybuild/ci— build, dependencies, or CI/CDchore— maintenanceChecklist
develop(notmain)feature/*,bugfix/*, orhotfix/*: the branch isci/deploy-via-infra, matching thecitype of the change.bun run lintpasses locally (ESLint + angular-eslint): not applicable, no TypeScript changes.bun run testpasses locally (Vitest): not applicable.bun run buildpasses locally (no type errors, no budget exceeded): not applicable here; the infra pipeline built this repo's image fromfeature/mvp-ux-polishin its validation run.ChangeDetectionStrategy.OnPushand Angular signals: not applicable.localStorage/sessionStorageaccess for JWT tokens (use the auth store): not applicable.bypassSecurityTrust*calls without explicit review: not applicable..envcontent committedCHANGELOG.mdupdated under[Unreleased]How to Test
INFRA_DEPLOY_TOKEN: after merge, any push tomainshows a greenDeployrun with the notice "Deploy not triggered".maincreates aDeploy MVPrun in https://github.com/Kntro-Soft/reqsai-infra/actions/workflows/deploy-mvp.yml withweb_refset to the pushed SHA. The run summary shows the ref and the commit of each image.Screenshots / recordings (if UI changes)
None, no UI changes.
Notes (optional)
Creating
INFRA_DEPLOY_TOKEN(one-time, an org member with admin on reqsai-infra)GITHUB_TOKENcannot start workflows in another repository, so the dispatch needs its own token:Kntro-Soft. Expiration: the shortest you are willing to rotate (for example 90 days).Kntro-Soft/reqsai-infra.ghprompts for the value without echoing it:The token can only start or cancel workflows in reqsai-infra. The AWS role, the SSH key and the vault stay in the infra repo's
mvpenvironment, which only itsmainbranch can use.Order
Create the token only once
mainof both reqsai-api and reqsai-web holds the code that should run in production. A push tomainhere deploys reqsai-api'smaintoo, so a stalemainon the other repo would roll it back. The infra workflow must also be on reqsai-inframain(merge Kntro-Soft/reqsai-infra#7 first).