Skip to content

v1.1.0 — site-deploy reusable

Choose a tag to compare

@cpitzi cpitzi released this 17 Aug 18:32
· 7 commits to main since this release
71857e1

What's new

site-deploy.yml — the site deploy pipeline, extracted (#38, #47). The three site repos ran near-identical deploy.yml files: build the Astro site, docker build, push to ECR (sha + latest), roll the ECS service, wait for it to stabilize. That pipeline now lives here once, parameterized on what actually differs (ECR repo, cluster, service, region, role ARN, node version, and an optional pre_build_command for the sites that need a content sync or emit two skins).

Two things folded in while centralizing, because doing them once here is cheap and doing them three times was not:

  • Image scanning on the built image before it rolls.
  • Build-provenance attestation (actions/attest-build-provenance), controllable by input. Building inside a reusable workflow is what qualifies the result for SLSA Build L3 rather than L2 — the reason the attestation belongs here and not in each caller.

Callers must grant id-token: write, attestations: write and packages: read; the README documents the wiring.

Also included: this repo's own OpenSSF Scorecard workflow and badge (#43), and a grouped Dependabot config that separates routine (minor/patch) from major bumps.

Callers

uses: lentago/shared-workflows/.github/workflows/site-deploy.yml@v1.1.0

Bump uses: refs from @v1.0.0 to @v1.1.0. Dependabot opens these as PRs automatically now that the fleet-wide rollout has landed in every active repo.

Release process note

This tag was cut from a commit that first bumped the repo's internal self-references (the reusables call this repo's own composite action by its full external form, since ./ inside a reusable resolves against the caller). Tagging without that bump would have shipped a release whose workflows still ran v1.0.0's action — see RELEASING.md step 2.