Skip to content

Commit

Permalink
we're going to remove CFN CR stuff as seperate stacks
Browse files Browse the repository at this point in the history
  • Loading branch information
tmclaugh committed Oct 26, 2024
1 parent 0420502 commit 9e258a3
Show file tree
Hide file tree
Showing 3 changed files with 2 additions and 128 deletions.
71 changes: 2 additions & 69 deletions .github/workflows/main.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ jobs:
$_f;
done
- name: Upload SAM artifact (Management Account / GHA Deploy)
- name: Upload SAM artifact (Management Account)
id: upload-sam-gha-template
shell: bash
run: |
Expand All @@ -84,17 +84,6 @@ jobs:
--region us-east-1 \
--output-template-file packaged-gha-deploy-template.yaml
- name: Upload SAM artifact (Management Account / CFN CR)
id: upload-sam-cfncr-template
shell: bash
run: |
sam package \
--template stacksets/cfn-custom-resource-deploy/stackset.yaml \
--s3-bucket aws-sam-cli-sourcebucket-225989329251-us-east-1 \
--s3-prefix ${{ env.GITHUB_REPOSITORY_OWNER_PART_SLUG_URL }}/${{ env.GITHUB_REPOSITORY_NAME_PART_SLUG_URL }}/${{ env.GITHUB_REF_SLUG_URL }} \
--region us-east-1 \
--output-template-file packaged-cfncr-template.yaml
- name: Upload SAM artifact (Build Account)
id: upload-sam-stackset-build-template
shell: bash
Expand Down Expand Up @@ -233,7 +222,7 @@ jobs:
secrets_json: ${{ toJson(secrets) }}


deploy_management_gha_deploy:
deploy_management:
needs:
- build
- deploy_build_stacksets
Expand Down Expand Up @@ -287,59 +276,3 @@ jobs:
cfn_capabilities: CAPABILITY_NAMED_IAM,CAPABILITY_AUTO_EXPAND
env_json: ${{ toJson(env) }}
secrets_json: ${{ toJson(secrets) }}

deploy_management_cfn_cr:
needs:
- build
- deploy_build_stacksets
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read

steps:
- name: Set extra GitHub environment variables
id: github-env-vars
uses: rlespinasse/github-slug-action@v4

- name: Download artifact
id: download-artifact
uses: actions/download-artifact@v4
with:
name: ${{ env.GITHUB_REPOSITORY_SLUG }}-${{ env.GITHUB_REF_SLUG_URL }}-${{ github.run_number }}-${{ github.sha }}

- name: Setup Python
id: install-python
uses: actions/setup-python@v3
with:
python-version: 3.12
cache: pipenv

- name: Install pipenv
id: install-pipenv
shell: bash
run: python -m pip install --upgrade pipenv


- name: Install dependencies
id: install-python-deps
shell: bash
run: pipenv install --dev

- name: Assume AWS Credentials
uses: ServerlessOpsIO/gha-assume-aws-credentials@v1
with:
build_aws_account_id: ${{ secrets.AWS_CICD_ACCOUNT_ID }}
gha_build_role_name: ${{ secrets.AWS_CICD_BUILD_ROLE_NAME }}
deploy_aws_account_id: ${{ secrets.AWS_MANAGEMENT_ACCOUNT_ID }}
gha_deploy_role_name: ${{ secrets.AWS_CICD_DEPLOY_ROLE_NAME }}

- name: Deploy via AWS SAM (GHA Deploy)
uses: ServerlessOpsIO/gha-deploy-aws-sam@v1
with:
aws_account_id: ${{ secrets.AWS_MANAGEMENT_ACCOUNT_ID }}
stack_name: "${{ env.GITHUB_REPOSITORY_NAME_PART_SLUG_URL }}-${{ env.GITHUB_EVENT_REF_SLUG_URL }}-cfn-cr"
template_file: packaged-cfncr-template.yaml
cfn_capabilities: CAPABILITY_NAMED_IAM,CAPABILITY_AUTO_EXPAND
env_json: ${{ toJson(env) }}
secrets_json: ${{ toJson(secrets) }}
31 changes: 0 additions & 31 deletions stackset-build-template.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,6 @@ Metadata:
localTemplateFile: &gha_template_body ./stacksets/gha-build/stackset.yaml
SamStack:
localTemplateFile: &sam_template_body ./stacksets/gha-build/sam-deployment.yaml
CfnCrStack:
localTemplateFile: &cfn_cr_template_body ./stacksets/cfn-custom-resource-build/stackset.yaml

AWSTemplateFormatVersion: '2010-09-09'
Transform:
Expand Down Expand Up @@ -81,32 +79,3 @@ Resources:
MaxConcurrentCount: 5
PermissionModel: SERVICE_MANAGED
TemplateBody: *gha_template_body


DeployAccountCfnCustomResourcesSupport:
Type: AWS::CloudFormation::StackSet
Properties:
StackSetName: OrgBuildAccountCfnCustomResources
Description: Provides shared AWS CFN Custom Resources
Parameters:
- ParameterKey: AwsOrganizationId
ParameterValue: !Ref AwsOrganizationId
- ParameterKey: CustomResourceTopicName
ParameterValue: !Ref CustomResourceTopicName
StackInstancesGroup:
- DeploymentTargets:
OrganizationalUnitIds: !Ref CiCdOuIds
Regions: !Ref TargetRegions
AutoDeployment:
Enabled: true
RetainStacksOnAccountRemoval: false
ManagedExecution:
Active: true
OperationPreferences:
RegionConcurrencyType: PARALLEL
FailureToleranceCount: 1
MaxConcurrentCount: 5
Capabilities:
- CAPABILITY_NAMED_IAM
PermissionModel: SERVICE_MANAGED
TemplateBody: *cfn_cr_template_body
28 changes: 0 additions & 28 deletions stackset-deploy-template.yaml
Original file line number Diff line number Diff line change
@@ -1,8 +1,6 @@
Metadata:
GhaStack:
localTemplateFile: &gha_deploy_template_body ./stacksets/gha-deploy/stackset.yaml
CfnCrStack:
localTemplateFile: &cfn_cr_template_body ./stacksets/cfn-custom-resource-deploy/stackset.yaml

AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Expand Down Expand Up @@ -57,29 +55,3 @@ Resources:
MaxConcurrentCount: 5
PermissionModel: SERVICE_MANAGED
TemplateBody: *gha_deploy_template_body

DeployAccountCfnCustomResourcesSupport:
Type: AWS::CloudFormation::StackSet
Properties:
StackSetName: OrgDeployAccountCfnCustomResourcesSupport
Description: Provides service discovery for AWS CFN Custom Resources
Parameters:
- ParameterKey: CustomResourceSsmParamName
ParameterValue: !Ref CustomResourceSsmParamName
- ParameterKey: CustomResourceArn
ParameterValue: !Sub "arn:aws:sns:${AWS::Region}:${CicdAwsAccountId}:${CustomResourceTopicName}"
StackInstancesGroup:
- DeploymentTargets:
OrganizationalUnitIds: !Ref TargetOuIds
Regions: !Ref TargetRegions
AutoDeployment:
Enabled: true
RetainStacksOnAccountRemoval: false
ManagedExecution:
Active: true
OperationPreferences:
RegionConcurrencyType: PARALLEL
FailureToleranceCount: 1
MaxConcurrentCount: 5
PermissionModel: SERVICE_MANAGED
TemplateBody: *cfn_cr_template_body

0 comments on commit 9e258a3

Please sign in to comment.