Skip to content

Commit

Permalink
ci: use OIDC
Browse files Browse the repository at this point in the history
  • Loading branch information
mogusbi committed Nov 28, 2024
1 parent 7ffa9d7 commit 0e61896
Show file tree
Hide file tree
Showing 2 changed files with 210 additions and 42 deletions.
108 changes: 90 additions & 18 deletions .github/workflows/deploy-to-develop.yml
Original file line number Diff line number Diff line change
Expand Up @@ -84,15 +84,17 @@ jobs:
AUTH0_SES_ACCESS_KEY_ID: ${{ secrets.AUTH0_SES_ACCESS_KEY_ID }}
AUTH0_SES_ACCESS_SECRET_KEY: ${{ secrets.AUTH0_SES_ACCESS_SECRET_KEY }}
AUTH0_SES_REGION: ${{ secrets.AUTH0_SES_REGION }}
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
PREFIX: id-develop
PROD_DOMAIN: ${{ secrets.PROD_DOMAIN }}
PUBLIC_URL: https://id-develop.${{ secrets.PROD_DOMAIN }}
REACT_APP_GA: ${{ secrets.GA_ID_DEV }}
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
Expand Down Expand Up @@ -136,6 +138,12 @@ jobs:
restore-keys: |
${{ runner.os }}-id-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy ID infrastructure
run: yarn workspace @id/infrastructure deploy --stage $STAGE

Expand All @@ -160,12 +168,14 @@ jobs:
needs: setup

env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
SENTRY_DSN: ${{ secrets.SENTRY_DSN_CORE_BACKEND }}
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
Expand Down Expand Up @@ -208,6 +218,12 @@ jobs:
restore-keys: |
${{ runner.os }}-core-anti-virus-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy
uses: nick-fields/retry@v3.0.0
with:
Expand All @@ -230,8 +246,6 @@ jobs:
- setup

env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
CY_API_KEY: ${{ secrets.CY_API_KEY }}
CY_API_GITHUB_PRIVATE_KEY: ${{ secrets.CY_API_GITHUB_PRIVATE_KEY }}
CY_API_GITHUB_APP_ID: ${{ secrets.CY_API_GITHUB_APP_ID }}
Expand All @@ -240,6 +254,10 @@ jobs:
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
Expand Down Expand Up @@ -279,6 +297,12 @@ jobs:
restore-keys: |
${{ runner.os }}-cypress-api-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy
run: yarn workspace @cypress/api deploy --stage $STAGE

Expand All @@ -293,12 +317,14 @@ jobs:
- accounts-data

env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
SENTRY_DSN: ${{ secrets.SENTRY_DSN_ACCOUNTS_BACKEND }}
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
Expand Down Expand Up @@ -341,6 +367,12 @@ jobs:
restore-keys: |
${{ runner.os }}-accounts-queue-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy
run: yarn workspace @accounts/queue deploy --stage $STAGE

Expand All @@ -355,12 +387,14 @@ jobs:
- anti-virus

env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
SENTRY_DSN: ${{ secrets.SENTRY_DSN_ACCOUNTS_BACKEND }}
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
Expand Down Expand Up @@ -403,6 +437,12 @@ jobs:
restore-keys: |
${{ runner.os }}-accounts-storage-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy
run: yarn workspace @accounts/storage deploy --stage $STAGE

Expand All @@ -417,12 +457,14 @@ jobs:
- accounts-storage

env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
SENTRY_DSN: ${{ secrets.SENTRY_DSN_ACCOUNTS_BACKEND }}
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
Expand Down Expand Up @@ -465,6 +507,12 @@ jobs:
restore-keys: |
${{ runner.os }}-accounts-data-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy
run: yarn workspace @accounts/data deploy --stage $STAGE

Expand All @@ -479,11 +527,13 @@ jobs:
- accounts-data

env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
Expand Down Expand Up @@ -526,6 +576,12 @@ jobs:
restore-keys: |
${{ runner.os }}-accounts-notifications-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy
run: yarn workspace @accounts/notifications deploy --stage $STAGE

Expand All @@ -542,12 +598,14 @@ jobs:
- accounts-storage

env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
SENTRY_DSN: ${{ secrets.SENTRY_DSN_ACCOUNTS_BACKEND }}
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4
Expand Down Expand Up @@ -590,6 +648,12 @@ jobs:
restore-keys: |
${{ runner.os }}-accounts-reports-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy
run: yarn workspace @accounts/reports deploy --stage $STAGE

Expand All @@ -609,13 +673,15 @@ jobs:

env:
AUTH0_DOMAIN: ${{ secrets.AUTH0_DOMAIN_DEV }}
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
SENTRY_DSN: ${{ secrets.SENTRY_DSN_ACCOUNTS_BACKEND }}
STAGE: develop
YARN_ENABLE_IMMUTABLE_INSTALLS: false

permissions:
id-token: write
contents: read

steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
Expand Down Expand Up @@ -666,5 +732,11 @@ jobs:
restore-keys: |
${{ runner.os }}-accounts-api-v4-
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: eu-west-1
role-to-assume: arn:aws:iam::633331859210:role/github-actions

- name: Deploy
run: yarn workspace @accounts/api deploy --stage $STAGE
Loading

0 comments on commit 0e61896

Please sign in to comment.