-
Notifications
You must be signed in to change notification settings - Fork 1
70 lines (56 loc) · 1.91 KB
/
Copy pathdeploy.yml
File metadata and controls
70 lines (56 loc) · 1.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
name: Deploy With CDK
on:
workflow_dispatch:
push:
branches:
- main
permissions:
contents: read
id-token: write
concurrency:
group: deploy
cancel-in-progress: false
jobs:
run-cdk-deploy:
runs-on: ubuntu-latest
timeout-minutes: 30
defaults:
run:
shell: devenv shell bash -- -e {0}
steps:
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Install Nix
uses: cachix/install-nix-action@8aa03977d8d733052d78f4e008a241fd1dbf36b3 # v31.10.6
- name: Set up devenv cache
uses: cachix/cachix-action@3ba601ff5bbb07c7220846facfa2cd81eeee15a1 # v16
with:
name: devenv
- name: Install devenv
shell: bash
run: nix profile add nixpkgs#devenv
# The Rust toolchain comes from the Nix rust-overlay, so cargo/rustc are
# only on PATH inside `devenv shell`. Expose their bin dir to subsequent
# action steps so rust-cache can probe the toolchain for its cache key.
- name: Expose Rust toolchain to GitHub PATH
run: dirname "$(command -v cargo)" >> "$GITHUB_PATH"
- name: Cache Rust build
uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2.9.1
with:
workspaces: lambda
cache-on-failure: true
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@e7f100cf4c008499ea8adda475de1042d6975c7b # v6.2.0
with:
role-to-assume: ${{ secrets.ASSUME_ROLE }}
aws-region: us-west-2
role-duration-seconds: 900
- name: Add arm target
run: rustup target add aarch64-unknown-linux-gnu
- name: Install deps
run: cd cdk && pnpm install
- name: CDK deploy
env:
DOMAIN_NAME: ${{ secrets.DOMAIN_NAME }}
EMAIL: ${{ secrets.EMAIL }}
run: cd cdk && pnpm run deploy