From 092f3bab7ad34c02db6a1c63c62a5632b4a50760 Mon Sep 17 00:00:00 2001 From: amandazhu Date: Mon, 31 Aug 2026 11:08:03 +1000 Subject: [PATCH 1/2] feat: publish versioned image tag --- .github/workflows/release-please.yml | 45 ++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 095e6fcb..09a3c56a 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -12,6 +12,9 @@ permissions: jobs: release: runs-on: ubuntu-latest + outputs: + release_created: ${{ steps.release.outputs.release_created }} + tag_name: ${{ steps.release.outputs.tag_name }} steps: - name: Generate GitHub App token id: app-token @@ -21,6 +24,7 @@ jobs: private-key: ${{ secrets.SBP_RELEASE_PLEASE_APP_PRIVATE_KEY }} - uses: googleapis/release-please-action@v5 + id: release with: release-type: python package-name: sbp-backend @@ -39,3 +43,44 @@ jobs: {"type":"chore","section":"Chores","hidden":true}, {"type":"test","section":"Tests","hidden":true} ] + + # Publishes an immutable, version-tagged image for prod to promote, right at + # the point a release is actually cut (merging the release-please PR) — no + # extra manual step beyond what's already done, and no new IAM trust needed + # since this job still runs under the same push-to-staging OIDC identity as + # build-push-deploy.yml's staging job. + publish-release-image: + needs: release + if: needs.release.outputs.release_created == 'true' + runs-on: ubuntu-latest + permissions: + id-token: write + contents: read + env: + AWS_REGION: ap-southeast-2 + AWS_ACCOUNT_ID: '456789093900' + ECR_REPOSITORY: sbp-backend + steps: + - name: Checkout release tag + uses: actions/checkout@v4 + with: + ref: ${{ needs.release.outputs.tag_name }} + + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: arn:aws:iam::${{ env.AWS_ACCOUNT_ID }}:role/sbp-backend-staging-github-actions-deploy-role + aws-region: ${{ env.AWS_REGION }} + + - name: Log in to Amazon ECR + id: login-ecr + uses: aws-actions/amazon-ecr-login@v2 + + - name: Build and push release image + env: + ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }} + IMAGE_TAG: ${{ needs.release.outputs.tag_name }} + run: | + set -euo pipefail + docker build -t "$ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG" . + docker push "$ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG" From 03686bd81e72b6f755154ac51978ce6a228e4a1b Mon Sep 17 00:00:00 2001 From: amandazhu Date: Mon, 31 Aug 2026 15:32:01 +1000 Subject: [PATCH 2/2] fix: use latest action versions --- .github/workflows/release-please.yml | 26 ++++++++++++++++---------- 1 file changed, 16 insertions(+), 10 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 09a3c56a..e1d6113e 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -62,12 +62,14 @@ jobs: ECR_REPOSITORY: sbp-backend steps: - name: Checkout release tag - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: ref: ${{ needs.release.outputs.tag_name }} + - uses: docker/setup-buildx-action@v4 + - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@v4 + uses: aws-actions/configure-aws-credentials@v6 with: role-to-assume: arn:aws:iam::${{ env.AWS_ACCOUNT_ID }}:role/sbp-backend-staging-github-actions-deploy-role aws-region: ${{ env.AWS_REGION }} @@ -76,11 +78,15 @@ jobs: id: login-ecr uses: aws-actions/amazon-ecr-login@v2 - - name: Build and push release image - env: - ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }} - IMAGE_TAG: ${{ needs.release.outputs.tag_name }} - run: | - set -euo pipefail - docker build -t "$ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG" . - docker push "$ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG" + - name: Build & Push release image + uses: docker/build-push-action@v7 + with: + context: . + file: ./Dockerfile + platforms: linux/amd64 + push: true + tags: ${{ steps.login-ecr.outputs.registry }}/${{ env.ECR_REPOSITORY }}:${{ needs.release.outputs.tag_name }} + provenance: false + sbom: false + cache-from: type=gha + cache-to: type=gha,mode=max