From bf4483f239ba84b48ed22eb3297bd6a9ee572ec8 Mon Sep 17 00:00:00 2001 From: Derek Roberts Date: Tue, 6 Oct 2026 19:44:35 -0700 Subject: [PATCH 1/2] chore(ci): remove prod deployment and switch test deploy to inherit secrets --- .github/ISSUE_TEMPLATE/documentation.md | 2 +- .github/ISSUE_TEMPLATE/feature.md | 2 +- .github/workflows/merge.yml | 37 +------------------------ 3 files changed, 3 insertions(+), 38 deletions(-) diff --git a/.github/ISSUE_TEMPLATE/documentation.md b/.github/ISSUE_TEMPLATE/documentation.md index 5186b698..16460297 100644 --- a/.github/ISSUE_TEMPLATE/documentation.md +++ b/.github/ISSUE_TEMPLATE/documentation.md @@ -22,5 +22,5 @@ assignees: '' - [ ] Does what I have made have appropriate test coverage? - [ ] Documentation and/or scientific documentation exists and can be found - [ ] Peer Reviewed by 2 people on the team -- [ ] Manual testing of all PRs in Dev and Prod +- [ ] Manual testing of all PRs in Dev and Test - [ ] Merged diff --git a/.github/ISSUE_TEMPLATE/feature.md b/.github/ISSUE_TEMPLATE/feature.md index c779fac8..7f60dd90 100644 --- a/.github/ISSUE_TEMPLATE/feature.md +++ b/.github/ISSUE_TEMPLATE/feature.md @@ -22,5 +22,5 @@ assignees: '' - [ ] Does what I have made have appropriate test coverage? - [ ] Documentation and/or scientific documentation exists and can be found - [ ] Peer Reviewed by 2 people on the team -- [ ] Manual testing of all PRs in Dev and Prod +- [ ] Manual testing of all PRs in Dev and Test - [ ] Merged diff --git a/.github/workflows/merge.yml b/.github/workflows/merge.yml index 38291d56..934d81d0 100644 --- a/.github/workflows/merge.yml +++ b/.github/workflows/merge.yml @@ -54,10 +54,7 @@ jobs: contents: read # Required for repository access needs: [vars] uses: ./.github/workflows/.deploy.yml - secrets: - db_password: ${{ secrets.db_password }} - oc_namespace: ${{ secrets.OC_NAMESPACE }} - oc_token: ${{ secrets.OC_TOKEN }} + secrets: inherit with: environment: test target: test @@ -92,35 +89,3 @@ jobs: - name: Run integration tests run: BASE_URL=${{ matrix.baseUrl }} API_NAME=${{ matrix.name }} node src/main.js - deploy-prod: - name: Deploy (prod) - permissions: - contents: read # Required for repository access - needs: [integration-tests, vars] - uses: ./.github/workflows/.deploy.yml - secrets: - db_password: ${{ secrets.db_password }} - oc_namespace: ${{ secrets.OC_NAMESPACE }} - oc_token: ${{ secrets.OC_TOKEN }} - with: - environment: prod - target: prod - tag: ${{ github.sha }} - - promote: - name: Promote Images - needs: [deploy-prod, vars] - runs-on: ubuntu-26.04 - permissions: - packages: write - strategy: - matrix: - package: [backend-java, backend-py, migrations-py] - timeout-minutes: 1 - steps: - - uses: shrink/actions-docker-registry-tag@e6aaef25c595b6e0edd18bf4c7dbfea3abd43299 # v5 - with: - registry: ghcr.io - repository: ${{ github.repository }}/${{ matrix.package }} - target: ${{ github.sha }} - tags: prod From 3f97d0629bfbfb9d838f727bbda5d28bbd23ece0 Mon Sep 17 00:00:00 2001 From: Derek Roberts Date: Tue, 6 Oct 2026 19:53:10 -0700 Subject: [PATCH 2/2] chore(ci): use explicit secrets mapping for deploy-test --- .github/workflows/merge.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/merge.yml b/.github/workflows/merge.yml index 934d81d0..459cc9a1 100644 --- a/.github/workflows/merge.yml +++ b/.github/workflows/merge.yml @@ -54,7 +54,10 @@ jobs: contents: read # Required for repository access needs: [vars] uses: ./.github/workflows/.deploy.yml - secrets: inherit + secrets: + db_password: ${{ secrets.db_password }} + oc_namespace: ${{ secrets.OC_NAMESPACE }} + oc_token: ${{ secrets.OC_TOKEN }} with: environment: test target: test