generated from Real-Dev-Squad/website-template
-
Notifications
You must be signed in to change notification settings - Fork 6
111 lines (101 loc) · 3.74 KB
/
pipeline.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
name: Pipeline
on:
push:
branches:
- 'main'
- 'develop'
env:
SAM_TEMPLATE: template.yaml
jobs:
prepare:
name: Prepare
runs-on: ubuntu-20.04
steps:
- uses: actions/checkout@v3
- name: Inject slug/short variables
uses: rlespinasse/[email protected]
- name: Prepare Outputs
id: prepare-step
run: |
echo "::set-output name=branch_name::${GITHUB_REF_SLUG}";
outputs:
branch_name: ${{ steps.prepare-step.outputs.branch_name }}
build-and-package:
needs: [prepare]
runs-on: ubuntu-latest
environment: ${{ needs.prepare.outputs.branch_name }}
steps:
- uses: actions/checkout@v3
- uses: actions/setup-python@v2
- uses: aws-actions/setup-sam@v1
- name: Build resources
run: sam build --template ${SAM_TEMPLATE}
- name: Assume the pipeline user role
env:
PIPELINE_USER_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
PIPELINE_USER_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
PIPELINE_EXECUTION_ROLE: ${{ secrets.PIPELINE_EXECUTION_ROLE }}
REGION: ${{ secrets.REGION }}
uses: aws-actions/configure-aws-credentials@v1
with:
aws-access-key-id: ${{ env.PIPELINE_USER_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ env.PIPELINE_USER_SECRET_ACCESS_KEY }}
aws-region: ${{ env.REGION }}
role-to-assume: ${{ env.PIPELINE_EXECUTION_ROLE }}
role-session-name: packaging
role-duration-seconds: 3600
role-skip-session-tagging: true
- name: Upload artifacts to artifact buckets
env:
ARTIFACTS_BUCKET: ${{ secrets.ARTIFACTS_BUCKET }}
REGION: ${{ secrets.REGION }}
run: |
sam package \
--s3-bucket ${ARTIFACTS_BUCKET} \
--region ${REGION} \
--output-template-file packaged.yaml
- uses: actions/upload-artifact@v2
with:
name: packaged.yaml
path: packaged.yaml
deploy:
needs: [prepare, build-and-package]
runs-on: ubuntu-latest
environment: ${{ needs.prepare.outputs.branch_name }}
steps:
- uses: actions/checkout@v3
- uses: actions/setup-python@v2
- uses: aws-actions/setup-sam@v1
- uses: actions/download-artifact@v2
with:
name: packaged.yaml
- name: Assume the pipeline user role
env:
PIPELINE_USER_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
PIPELINE_USER_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
PIPELINE_EXECUTION_ROLE: ${{ secrets.PIPELINE_EXECUTION_ROLE }}
REGION: ${{ secrets.REGION }}
uses: aws-actions/configure-aws-credentials@v1
with:
aws-access-key-id: ${{ env.PIPELINE_USER_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ env.PIPELINE_USER_SECRET_ACCESS_KEY }}
aws-region: ${{ env.REGION }}
role-to-assume: ${{ env.PIPELINE_EXECUTION_ROLE }}
role-session-name: deployment
role-duration-seconds: 3600
role-skip-session-tagging: true
- name: Deploy to account
env:
ARTIFACTS_BUCKET: ${{ secrets.ARTIFACTS_BUCKET }}
CLOUDFORMATION_EXECUTION_ROLE: ${{ secrets.CLOUDFORMATION_EXECUTION_ROLE }}
PIPELINE_STACK_NAME: ${{ secrets.STACK_NAME }}
REGION: ${{ secrets.REGION }}
run: |
sam deploy --stack-name ${PIPELINE_STACK_NAME} \
--no-confirm-changeset \
--template packaged.yaml \
--capabilities CAPABILITY_IAM \
--region ${REGION} \
--s3-bucket ${ARTIFACTS_BUCKET} \
--no-fail-on-empty-changeset \
--role-arn ${CLOUDFORMATION_EXECUTION_ROLE}