Skip to content

cdk CDK

cdk CDK #71

Workflow file for this run

name: apps/cdk CDK
concurrency:
group: ${{ github.workflow }}-cdk
on:
push:
paths:
- "apps/cdk/**"
- "apps/backend/**"
- "apps/ebsi-json-rpc/**"
branches:
- master
workflow_dispatch:
jobs:
cdk-deploy:
environment: Production
permissions:
id-token: write
contents: read
name: CDK Deploy
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Print environment variables
run: |
echo "AWS_REGION: ${{ vars.AWS_REGION }}"
echo "AWS_ROLE_TO_ASSUME: ${{ vars.AWS_ROLE_TO_ASSUME }}"
echo "ISSUER_DID: ${{ vars.ISSUER_DID }}"
echo "KC_DB_SCHEMA: ${{ vars.KC_DB_SCHEMA }}"
echo "KM_DB_SCHEMA: ${{ vars.KM_DB_SCHEMA }}"
- name: Setup pnpm
uses: pnpm/action-setup@v4
with:
version: "latest"
- name: Check out Git repository
uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
cache: pnpm
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v2
with:
role-to-assume: ${{ vars.AWS_ROLE_TO_ASSUME }}
aws-region: ${{ vars.AWS_REGION }}
- name: Install dependencies
run: pnpm install
- name: Run cdk deploy
env:
ISSUER_PRIVATE_KEY_ID: ${{ secrets.ISSUER_PRIVATE_KEY_ID }}
ISSUER_PRIVATE_KEY_JWK: ${{ secrets.ISSUER_PRIVATE_KEY_JWK }}
ISSUER_PUBLIC_KEY_JWK: ${{ secrets.ISSUER_PUBLIC_KEY_JWK }}
AWS_ACCOUNT: ${{ secrets.AWS_ACCOUNT }}
AWS_PUBLIC_HOSTED_ZONE_ID: ${{ secrets.AWS_PUBLIC_HOSTED_ZONE_ID }}
AWS_PUBLIC_HOSTED_ZONE_NAME: ${{ secrets.AWS_PUBLIC_HOSTED_ZONE_NAME }}
ISSUER_DID: ${{ vars.ISSUER_DID }}
KC_DB_SCHEMA: ${{ vars.KC_DB_SCHEMA }}
KM_DB_SCHEMA: ${{ vars.KM_DB_SCHEMA }}
run: cd apps/cdk && pnpm run cdk deploy --all --require-approval never