ci: update sam pipeline #35
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
on: | |
push: | |
branches: | |
- main | |
- dev | |
paths: | |
- 'src/**' | |
- 'tests/**' | |
- '.github/workflows/**' | |
- 'template.yml' | |
- 'samconfig.toml' | |
- 'requirements.txt' | |
jobs: | |
test: | |
runs-on: ubuntu-latest | |
steps: | |
- uses: actions/checkout@v4 | |
- name: Set up Python 3.9 | |
uses: actions/setup-python@v5 | |
with: | |
python-version: "3.9" | |
cache: 'pip' | |
- name: Execute unit tests and coverage report | |
run: | | |
python -m pip install --upgrade pip | |
if [ -f requirements.txt ]; then pip install -r requirements.txt; fi | |
- name: Run unit tests | |
run: python -m coverage run -m unittest -v tests/*.py | |
- name: Run coverage report | |
run: python -m coverage report -m | |
build-and-deploy: | |
runs-on: ubuntu-latest | |
needs: test | |
steps: | |
- uses: actions/checkout@v4 | |
- uses: actions/setup-python@v5 | |
with: | |
python-version: '3.9' | |
cache: 'pip' | |
- uses: aws-actions/setup-sam@v2 | |
with: | |
use-installer: true | |
- uses: aws-actions/configure-aws-credentials@v1 | |
with: | |
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | |
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
aws-region: ${{ secrets.AWS_REGION }} | |
- name: Set environment for branch | |
run: | | |
if [[ $GITHUB_REF_NAME == 'main' ]]; then | |
echo "ENV_STAGE=prod" >> "$GITHUB_ENV" | |
else | |
echo "ENV_STAGE=dev" >> "$GITHUB_ENV" | |
fi | |
# sam build | |
- name: Run SAM Build | |
run: sam build --use-container | |
# sam deploy | |
- name: Run SAM Deploy | |
run: | | |
sam deploy --s3-bucket ${{ secrets.AWS_ARTIFACTS_BUCKET_NAME }} \ | |
--stack-name stori-transactions-email-sender-${{ env.ENV_STAGE }} \ | |
--parameter-overrides \ | |
BucketName=${{ secrets.AWS_BUCKET_NAME_FILES_PREFIX }}-${{ env.ENV_STAGE }} \ | |
SecretName=${{ secrets.AWS_SECRET_NAME }} \ | |
Stage=${{ env.ENV_STAGE }} \ | |
--no-confirm-changeset --no-fail-on-empty-changeset |