Skip to content
This repository was archived by the owner on Aug 10, 2026. It is now read-only.

Deploy Architecture Diagram #2

Deploy Architecture Diagram

Deploy Architecture Diagram #2

name: Deploy Architecture Diagram
# Pipeline stages:
# lint ──┬──→ build ──┐
# └──→ scan ──┴──→ deploy
#
# build and scan run in parallel after lint; deploy gates on both.
on:
push:
branches:
- main
paths:
- '.github/workflows/deploy-architecture-diagram.yml'
- 'projects/04-architecture-diagram/**'
pull_request:
paths:
- '.github/workflows/deploy-architecture-diagram.yml'
- 'projects/04-architecture-diagram/**'
workflow_dispatch:
inputs:
student_name:
description: 'Deployment name prefix (e.g. john-smith). Overrides repo variable.'
required: false
default: ''
aws_region:
description: 'AWS region to deploy into'
required: false
default: 'us-east-1'
aws_access_key_id:
description: 'AWS Access Key ID — leave blank to use repo secret AWS_ACCESS_KEY_ID'
required: false
default: ''
aws_secret_access_key:
description: 'AWS Secret Access Key — leave blank to use repo secret AWS_SECRET_ACCESS_KEY'
required: false
default: ''
env:
PROJECT_DIR: projects/04-architecture-diagram
AWS_REGION: ${{ inputs.aws_region || vars.ARCFLOW_AWS_REGION || 'us-east-1' }}
STUDENT_NAME: ${{ inputs.student_name || vars.ARCFLOW_STUDENT_NAME }}
# ── Stage 1: Lint ─────────────────────────────────────────────────────────────
jobs:
lint:
name: Lint
runs-on: ubuntu-latest
continue-on-error: true
permissions:
contents: read
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 25
- uses: hashicorp/setup-terraform@v3
with:
terraform_wrapper: false
- name: Install frontend dependencies
working-directory: ${{ env.PROJECT_DIR }}/frontend
run: npm install
- name: ESLint — frontend
working-directory: ${{ env.PROJECT_DIR }}/frontend
run: npm run lint
- name: Terraform format check
run: terraform fmt -check -recursive ${{ env.PROJECT_DIR }}/terraform
- name: Terraform validate
working-directory: ${{ env.PROJECT_DIR }}/terraform
run: |
terraform init -backend=false
terraform validate
# ── Stage 2a: Build ───────────────────────────────────────────────────────────
build:
name: Build
runs-on: ubuntu-latest
needs: lint
permissions:
contents: read
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 25
- name: Install frontend dependencies
working-directory: ${{ env.PROJECT_DIR }}/frontend
run: npm install
- name: Build frontend (static export)
working-directory: ${{ env.PROJECT_DIR }}/frontend
run: npm run build
- name: TypeScript type check
working-directory: ${{ env.PROJECT_DIR }}/frontend
run: npx tsc --noEmit
# ── Stage 2b: Security Scan ───────────────────────────────────────────────────
scan:
name: Security Scan
runs-on: ubuntu-latest
needs: lint
permissions:
contents: read
security-events: write
actions: read
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 25
- name: npm audit — frontend
working-directory: ${{ env.PROJECT_DIR }}/frontend
run: |
npm install
npm audit --audit-level=high || true
npm audit --audit-level=critical
- name: Checkov — Terraform IaC scan
uses: bridgecrewio/checkov-action@v12
with:
directory: ${{ env.PROJECT_DIR }}/terraform
framework: terraform
output_format: sarif
output_file_path: checkov.sarif
soft_fail: true
- name: Upload Checkov results to Security tab
if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: checkov.sarif
category: checkov-arcflow
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: javascript-typescript
queries: security-extended
- name: Build for CodeQL
working-directory: ${{ env.PROJECT_DIR }}/frontend
run: npm run build
- name: Run CodeQL analysis
uses: github/codeql-action/analyze@v3
with:
category: codeql-arcflow
# ── Stage 3: Deploy ───────────────────────────────────────────────────────────
deploy:
name: Deploy to AWS
runs-on: ubuntu-latest
needs: [build, scan]
if: github.event_name == 'workflow_dispatch' || github.ref == 'refs/heads/main'
permissions:
contents: read
id-token: write
outputs:
frontend_url: ${{ steps.capture_outputs.outputs.frontend_url }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 25
- uses: hashicorp/setup-terraform@v3
with:
terraform_wrapper: false
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-region: ${{ env.AWS_REGION }}
aws-access-key-id: ${{ inputs.aws_access_key_id || secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ inputs.aws_secret_access_key || secrets.AWS_SECRET_ACCESS_KEY }}
- name: Validate deployment settings
shell: bash
run: |
set -euo pipefail
if [ -z "${STUDENT_NAME}" ]; then
echo "::error::Provide student_name as a workflow input or set repo variable ARCFLOW_STUDENT_NAME."
exit 1
fi
aws sts get-caller-identity
- name: Deploy application
working-directory: ${{ env.PROJECT_DIR }}
env:
CI: true
run: bash scripts/deploy.sh --name "$STUDENT_NAME" --region "$AWS_REGION"
- name: Capture Terraform outputs
id: capture_outputs
working-directory: ${{ env.PROJECT_DIR }}/terraform
run: echo "frontend_url=$(terraform output -raw frontend_url)" >> "$GITHUB_OUTPUT"
- name: Publish deployment summary
working-directory: ${{ env.PROJECT_DIR }}/terraform
shell: bash
run: |
{
echo "## Architecture Diagram — Deployed :rocket:"
echo ""
echo "| | |"
echo "|---|---|"
echo "| **Region** | ${AWS_REGION} |"
echo "| **Name** | ${STUDENT_NAME} |"
echo "| **Frontend** | $(terraform output -raw frontend_url) |"
echo "| **Bucket** | $(terraform output -raw frontend_bucket) |"
} >> "$GITHUB_STEP_SUMMARY"