Skip to content

feat(aws): add aws tooling and setup #16

feat(aws): add aws tooling and setup

feat(aws): add aws tooling and setup #16

Workflow file for this run

name: Deploy
on:
push:
branches:
- main
tags:
- "*"
paths:
- ".github/workflows/deploy.yml"
- "cmd/**"
- "deploy/**"
- "pkg/**"
pull_request:
branches: [main]
workflow_run:
workflows: [Releaser]
types: [completed]
branches: [main]
workflow_dispatch:
permissions:
id-token: write # This is required for requesting the JWT
contents: read # This is required for actions/checkout
jobs:
# always deploy to staging
staging:
uses: ./.github/workflows/terraform.yml
with:
env: staging
workspace: staging
apply: ${{ github.event_name != 'pull_request' }}
use-external-blob-bucket: ${{ env.STAGING_USE_EXTERNAL_BLOB_BUCKET }}

Check failure on line 34 in .github/workflows/deploy.yml

View workflow run for this annotation

GitHub Actions / Deploy

Invalid workflow file

The workflow is not valid. .github/workflows/deploy.yml (Line: 34, Col: 33): Unrecognized named-value: 'env'. Located at position 1 within expression: env.STAGING_USE_EXTERNAL_BLOB_BUCKET .github/workflows/deploy.yml (Line: 35, Col: 38): Unrecognized named-value: 'env'. Located at position 1 within expression: env.STAGING_EXTERNAL_BLOB_BUCKET_ENDPOINT
external-blob-bucket-endpoint: ${{ env.STAGING_EXTERNAL_BLOB_BUCKET_ENDPOINT }}
external-blob-bucket-region: ${{ env.STAGING_EXTERNAL_BLOB_BUCKET_REGION }}
external-blob-bucket-name: ${{ env.STAGING_EXTERNAL_BLOB_BUCKET_NAME }}
external-blob-bucket-domain: ${{ env.STAGING_EXTERNAL_BLOB_BUCKET_DOMAIN }}
secrets:
aws-account-id: ${{ secrets.STAGING_AWS_ACCOUNT_ID }}
aws-region: ${{ secrets.STAGING_AWS_REGION }}
allowed-account-ids: ${{ secrets.STAGING_ALLOWED_ACCOUNT_IDS }}
private-key: ${{ secrets.STAGING_PRIVATE_KEY }}
indexing-service-proof: ${{ secrets.STAGING_INDEXING_SERVICE_PROOF }}
external-blob-bucket-access-key-id: ${{ secrets.STAGING_EXTERNAL_BLOB_BUCKET_ACCESS_KEY_ID }}
external-blob-bucket-secret-access-key: ${{ secrets.STAGING_EXTERNAL_BLOB_BUCKET_SECRET_ACCESS_KEY }}
# deploy to prod on new releases
production:
if: ${{ github.event_name == 'workflow_run' && github.event.workflow_run.conclusion == 'success' }}
uses: ./.github/workflows/terraform.yml
with:
env: production
workspace: prod
apply: true
use-external-blob-bucket: ${{ env.PROD_USE_EXTERNAL_BLOB_BUCKET }}
external-blob-bucket-endpoint: ${{ env.PROD_EXTERNAL_BLOB_BUCKET_ENDPOINT }}
external-blob-bucket-region: ${{ env.PROD_EXTERNAL_BLOB_BUCKET_REGION }}
external-blob-bucket-name: ${{ env.PROD_EXTERNAL_BLOB_BUCKET_NAME }}
external-blob-bucket-domain: ${{ env.PROD_EXTERNAL_BLOB_BUCKET_DOMAIN }}
secrets:
aws-account-id: ${{ secrets.PROD_AWS_ACCOUNT_ID }}
aws-region: ${{ secrets.PROD_AWS_REGION }}
allowed-account-ids: ${{ secrets.PROD_ALLOWED_ACCOUNT_IDS }}
private-key: ${{ secrets.PROD_PRIVATE_KEY }}
indexing-service-proof: ${{ secrets.PROD_INDEXING_SERVICE_PROOF }}
external-blob-bucket-access-key-id: ${{ secrets.PROD_EXTERNAL_BLOB_BUCKET_ACCESS_KEY_ID }}
external-blob-bucket-secret-access-key: ${{ secrets.PROD_EXTERNAL_BLOB_BUCKET_SECRET_ACCESS_KEY }}