-
Notifications
You must be signed in to change notification settings - Fork 33
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: write publishing timestamps to SSM (#1773)
* feat: write publishing timestamps to SSM Add a feature to allow publishing the latest published version and its timestamp to SSM, so that we can start tracking how long it takes to replicate, and alarm at a different severity if a canary fails and we recently released. * Add test * Update test scripts * MOve commands * Add test * chore: self mutation Signed-off-by: github-actions <[email protected]> * Ensure that the scripts don't drift * Messaging --------- Signed-off-by: github-actions <[email protected]> Co-authored-by: github-actions <[email protected]>
- Loading branch information
Showing
25 changed files
with
449 additions
and
82 deletions.
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -82,4 +82,72 @@ describe('with standard pipeline', () => { | |
}]), | ||
}); | ||
}); | ||
|
||
test.each(['npm', 'nuget', 'maven', 'pypi'] as const)('publishing SSM timestamps adds IAM permissions: %p', (type) => { | ||
switch (type) { | ||
case 'npm': | ||
pipeline.publishToNpm({ | ||
npmTokenSecret: { secretArn: 'arn:secret' }, | ||
ssmPrefix: '/published/jsii-sample/npm', | ||
}); | ||
break; | ||
|
||
case 'nuget': | ||
pipeline.publishToNuGet({ | ||
nugetApiKeySecret: { secretArn: 'arn:secret' }, | ||
ssmPrefix: '/published/jsii-sample/nuget', | ||
}); | ||
break; | ||
|
||
case 'maven': | ||
const signingKey = new delivlib.OpenPGPKeyPair(stack, 'CodeSign', { | ||
email: '[email protected]', | ||
encryptionKey: new kms.Key(stack, 'CodeSign-CMK'), | ||
expiry: '4y', | ||
identity: 'aws-cdk-dev', | ||
keySizeBits: 4_096, | ||
pubKeyParameterName: `/${stack.node.path}/CodeSign.pub`, | ||
secretName: stack.node.path + '/CodeSign', | ||
version: 0, | ||
removalPolicy: delivlib.OpenPGPKeyPairRemovalPolicy.DESTROY_IMMEDIATELY, | ||
}); | ||
|
||
pipeline.publishToMaven({ | ||
mavenLoginSecret: { secretArn: 'arn:secret' }, | ||
mavenEndpoint: 'https://aws.oss.sonatype.org:443/', | ||
stagingProfileId: '68a05363083174', | ||
ssmPrefix: '/published/jsii-sample/maven', | ||
signingKey, | ||
}); | ||
break; | ||
|
||
case 'pypi': | ||
pipeline.publishToPyPI({ | ||
loginSecret: { secretArn: 'arn:secret' }, | ||
ssmPrefix: '/published/jsii-sample/pypi', | ||
}); | ||
break; | ||
} | ||
|
||
const template = Template.fromStack(stack); | ||
template.hasResourceProperties('AWS::IAM::Policy', { | ||
PolicyDocument: { | ||
Statement: Match.arrayWith([{ | ||
Effect: 'Allow', | ||
Action: ['ssm:PutParameter', 'ssm:GetParameter'], | ||
Resource: { | ||
'Fn::Join': ['', [ | ||
'arn:', | ||
{ Ref: 'AWS::Partition' }, | ||
':ssm:', | ||
{ Ref: 'AWS::Region' }, | ||
':', | ||
{ Ref: 'AWS::AccountId' }, | ||
`:parameter/published/jsii-sample/${type}/*`, | ||
]], | ||
}, | ||
}]), | ||
}, | ||
}); | ||
}); | ||
}); |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -53,12 +53,16 @@ export class TestStack extends Stack { | |
scriptDirectory: path.join(testDir, 'linux'), | ||
}); | ||
|
||
// add a test that runs on Windows | ||
pipeline.addTest('HelloWindows', { | ||
platform: delivlib.ShellPlatform.Windows, | ||
entrypoint: 'test.ps1', | ||
scriptDirectory: path.join(testDir, 'windows'), | ||
}); | ||
// This test takes a lot of time (~10 minutes), which is annoying during testing | ||
const WINDOWS = false; | ||
if (WINDOWS) { | ||
// add a test that runs on Windows | ||
pipeline.addTest('HelloWindows', { | ||
platform: delivlib.ShellPlatform.Windows, | ||
entrypoint: 'test.ps1', | ||
scriptDirectory: path.join(testDir, 'windows'), | ||
}); | ||
} | ||
|
||
const externalId = 'require-me-please'; | ||
|
||
|
@@ -111,9 +115,13 @@ export class TestStack extends Stack { | |
// PUBLISH | ||
// | ||
|
||
const dryRun = false; | ||
|
||
pipeline.publishToNpm({ | ||
npmTokenSecret: { secretArn: 'arn:aws:secretsmanager:us-east-1:712950704752:secret:delivlib/npm-MhaWgx' }, | ||
access: delivlib.NpmAccess.RESTRICTED, | ||
ssmPrefix: '/published/jsii-sample/npm', | ||
dryRun, | ||
}); | ||
|
||
// this creates a self-signed certificate | ||
|
@@ -133,6 +141,8 @@ export class TestStack extends Stack { | |
pipeline.publishToNuGet({ | ||
nugetApiKeySecret: { secretArn: 'arn:aws:secretsmanager:us-east-1:712950704752:secret:delivlib/nuget-jDbgrN' }, | ||
codeSign, | ||
ssmPrefix: '/published/jsii-sample/nuget', | ||
dryRun, | ||
}); | ||
|
||
const signingKey = new delivlib.OpenPGPKeyPair(this, 'CodeSign', { | ||
|
@@ -152,20 +162,27 @@ export class TestStack extends Stack { | |
mavenEndpoint: 'https://aws.oss.sonatype.org:443/', | ||
signingKey, | ||
stagingProfileId: '68a05363083174', | ||
ssmPrefix: '/published/jsii-sample/maven', | ||
dryRun, | ||
}); | ||
|
||
pipeline.publishToGitHub({ | ||
githubRepo, | ||
signingKey, | ||
additionalInputArtifacts: shellableArtifacts, | ||
ssmPrefix: '/published/jsii-sample/github', | ||
dryRun, | ||
}); | ||
|
||
pipeline.publishToGitHubPages({ | ||
githubRepo, | ||
dryRun, | ||
}); | ||
|
||
pipeline.publishToPyPI({ | ||
loginSecret: { secretArn: 'arn:aws:secretsmanager:us-east-1:712950704752:secret:delivlib/pypi-tp8M57' }, | ||
ssmPrefix: '/published/jsii-sample/pypi', | ||
dryRun, | ||
}); | ||
|
||
// publish go bindings to awslabs/aws-delivlib-sample under the "golang" | ||
|
@@ -175,6 +192,8 @@ export class TestStack extends Stack { | |
gitBranch: 'golang', | ||
gitUserEmail: '[email protected]', | ||
gitUserName: 'Delivlib Tests', | ||
ssmPrefix: '/published/jsii-sample/golang', | ||
dryRun, | ||
}); | ||
|
||
// | ||
|
Oops, something went wrong.