This repository was archived by the owner on Aug 10, 2026. It is now read-only.
Repository navigation
Added resource tagging into terraform #9
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy Architecture Diagram | |
| # Pipeline stages: | |
| # lint ──┬──→ build ──┐ | |
| # └──→ scan ──┴──→ deploy | |
| # | |
| # build and scan run in parallel after lint; deploy gates on both. | |
| on: | |
| push: | |
| branches: | |
| - main | |
| paths: | |
| - '.github/workflows/deploy-architecture-diagram.yml' | |
| - 'projects/04-architecture-diagram/**' | |
| pull_request: | |
| paths: | |
| - '.github/workflows/deploy-architecture-diagram.yml' | |
| - 'projects/04-architecture-diagram/**' | |
| workflow_dispatch: | |
| inputs: | |
| student_name: | |
| description: 'Deployment name prefix (e.g. john-smith). Overrides repo variable.' | |
| required: false | |
| default: '' | |
| aws_region: | |
| description: 'AWS region to deploy into' | |
| required: false | |
| default: 'us-east-1' | |
| aws_access_key_id: | |
| description: 'AWS Access Key ID — leave blank to use repo secret AWS_ACCESS_KEY_ID' | |
| required: false | |
| default: '' | |
| aws_secret_access_key: | |
| description: 'AWS Secret Access Key — leave blank to use repo secret AWS_SECRET_ACCESS_KEY' | |
| required: false | |
| default: '' | |
| env: | |
| PROJECT_DIR: projects/04-architecture-diagram | |
| AWS_REGION: ${{ inputs.aws_region || vars.ARCFLOW_AWS_REGION || 'us-east-1' }} | |
| STUDENT_NAME: ${{ inputs.student_name || vars.ARCFLOW_STUDENT_NAME }} | |
| # ── Stage 1: Lint ───────────────────────────────────────────────────────────── | |
| jobs: | |
| lint: | |
| name: Lint | |
| runs-on: ubuntu-latest | |
| continue-on-error: true | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 25 | |
| - uses: hashicorp/setup-terraform@v3 | |
| with: | |
| terraform_wrapper: false | |
| - name: Install frontend dependencies | |
| working-directory: ${{ env.PROJECT_DIR }}/frontend | |
| run: npm install | |
| - name: ESLint — frontend | |
| working-directory: ${{ env.PROJECT_DIR }}/frontend | |
| run: npm run lint | |
| - name: Terraform format check | |
| run: terraform fmt -check -recursive ${{ env.PROJECT_DIR }}/terraform | |
| - name: Terraform validate | |
| working-directory: ${{ env.PROJECT_DIR }}/terraform | |
| run: | | |
| terraform init -backend=false | |
| terraform validate | |
| # ── Stage 2a: Build ─────────────────────────────────────────────────────────── | |
| build: | |
| name: Build | |
| runs-on: ubuntu-latest | |
| needs: lint | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 25 | |
| - name: Install frontend dependencies | |
| working-directory: ${{ env.PROJECT_DIR }}/frontend | |
| run: npm install | |
| - name: Build frontend (static export) | |
| working-directory: ${{ env.PROJECT_DIR }}/frontend | |
| run: npm run build | |
| - name: TypeScript type check | |
| working-directory: ${{ env.PROJECT_DIR }}/frontend | |
| run: npx tsc --noEmit | |
| # ── Stage 2b: Security Scan ─────────────────────────────────────────────────── | |
| scan: | |
| name: Security Scan | |
| runs-on: ubuntu-latest | |
| needs: lint | |
| permissions: | |
| contents: read | |
| security-events: write | |
| actions: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 25 | |
| - name: npm audit — frontend | |
| working-directory: ${{ env.PROJECT_DIR }}/frontend | |
| run: | | |
| npm install | |
| npm audit --audit-level=high || true | |
| npm audit --audit-level=critical | |
| - name: Checkov — Terraform IaC scan | |
| uses: bridgecrewio/checkov-action@v12 | |
| with: | |
| directory: ${{ env.PROJECT_DIR }}/terraform | |
| framework: terraform | |
| output_format: sarif | |
| output_file_path: checkov.sarif | |
| soft_fail: true | |
| - name: Upload Checkov results to Security tab | |
| if: always() | |
| uses: github/codeql-action/upload-sarif@v3 | |
| with: | |
| sarif_file: checkov.sarif | |
| category: checkov-arcflow | |
| - name: Initialize CodeQL | |
| uses: github/codeql-action/init@v3 | |
| with: | |
| languages: javascript-typescript | |
| queries: security-extended | |
| - name: Build for CodeQL | |
| working-directory: ${{ env.PROJECT_DIR }}/frontend | |
| run: npm run build | |
| - name: Run CodeQL analysis | |
| uses: github/codeql-action/analyze@v3 | |
| with: | |
| category: codeql-arcflow | |
| # ── Stage 3: Deploy ─────────────────────────────────────────────────────────── | |
| deploy: | |
| name: Deploy to AWS | |
| runs-on: ubuntu-latest | |
| needs: [build, scan] | |
| if: github.event_name == 'workflow_dispatch' || github.ref == 'refs/heads/main' | |
| permissions: | |
| contents: read | |
| id-token: write | |
| outputs: | |
| frontend_url: ${{ steps.capture_outputs.outputs.frontend_url }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 25 | |
| - uses: hashicorp/setup-terraform@v3 | |
| with: | |
| terraform_wrapper: false | |
| - name: Configure AWS credentials | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| aws-region: ${{ env.AWS_REGION }} | |
| aws-access-key-id: ${{ inputs.aws_access_key_id || secrets.AWS_ACCESS_KEY_ID }} | |
| aws-secret-access-key: ${{ inputs.aws_secret_access_key || secrets.AWS_SECRET_ACCESS_KEY }} | |
| - name: Validate deployment settings | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| if [ -z "${STUDENT_NAME}" ]; then | |
| echo "::error::Provide student_name as a workflow input or set repo variable ARCFLOW_STUDENT_NAME." | |
| exit 1 | |
| fi | |
| aws sts get-caller-identity | |
| - name: Deploy application | |
| working-directory: ${{ env.PROJECT_DIR }} | |
| env: | |
| CI: true | |
| run: bash scripts/deploy.sh --name "$STUDENT_NAME" --region "$AWS_REGION" | |
| - name: Capture Terraform outputs | |
| id: capture_outputs | |
| working-directory: ${{ env.PROJECT_DIR }}/terraform | |
| run: echo "frontend_url=$(terraform output -raw frontend_url)" >> "$GITHUB_OUTPUT" | |
| - name: Publish deployment summary | |
| working-directory: ${{ env.PROJECT_DIR }}/terraform | |
| shell: bash | |
| run: | | |
| { | |
| echo "## Architecture Diagram — Deployed :rocket:" | |
| echo "" | |
| echo "| | |" | |
| echo "|---|---|" | |
| echo "| **Region** | ${AWS_REGION} |" | |
| echo "| **Name** | ${STUDENT_NAME} |" | |
| echo "| **Frontend** | $(terraform output -raw frontend_url) |" | |
| echo "| **Bucket** | $(terraform output -raw frontend_bucket) |" | |
| } >> "$GITHUB_STEP_SUMMARY" |