Skip to content

feat: DS-59 Add marketing token build smoke #18

feat: DS-59 Add marketing token build smoke

feat: DS-59 Add marketing token build smoke #18

# Azure Static Web Apps PR preview for marketing (Free SKU).
name: Preview Marketing (SWA)
on:
pull_request:
types: [opened, synchronize, reopened, closed]
paths:
- 'apps/marketing/**'
- 'scripts/validate-staticwebapp-config.mjs'
- '.npmrc'
- 'pnpm-lock.yaml'
- '.github/workflows/preview-marketing.yml'
concurrency:
group: preview-marketing-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
build_and_preview:
if: github.event.action != 'closed'
runs-on: ubuntu-latest
name: Build + marketing SWA preview
permissions:
contents: read
id-token: write
pull-requests: write
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
with:
version: 9.15.0
- uses: actions/setup-node@v4
with:
node-version: 24
cache: pnpm
- name: Install
run: pnpm install --frozen-lockfile
- name: Build marketing
run: pnpm --filter @singleton-sd/marketing... run build
- name: Smoke marketing tokens
run: pnpm --filter @singleton-sd/marketing run test:smoke
- name: Validate SWA config (dist)
run: node scripts/validate-staticwebapp-config.mjs apps/marketing/dist/staticwebapp.config.json
- name: Check OIDC Variables
id: oidc
run: |
set -euo pipefail
if [ -z "${{ vars.AZURE_CLIENT_ID }}" ] || [ -z "${{ vars.AZURE_TENANT_ID }}" ] || [ -z "${{ vars.AZURE_SUBSCRIPTION_ID }}" ]; then
echo "configured=false" >> "$GITHUB_OUTPUT"
echo "OIDC Variables not set — skipping marketing SWA deploy."
else
echo "configured=true" >> "$GITHUB_OUTPUT"
fi
- name: Azure login (OIDC)
if: steps.oidc.outputs.configured == 'true'
uses: azure/login@v2
with:
client-id: ${{ vars.AZURE_CLIENT_ID }}
tenant-id: ${{ vars.AZURE_TENANT_ID }}
subscription-id: ${{ vars.AZURE_SUBSCRIPTION_ID }}
- name: Read marketing SWA deploy token from Key Vault
if: steps.oidc.outputs.configured == 'true'
run: |
set -euo pipefail
token=$(az keyvault secret show \
--vault-name ssd-global-kv-prod-ae \
--name swa-marketing-deployment-token \
--query value -o tsv)
echo "::add-mask::$token"
echo "SWA_DEPLOYMENT_TOKEN=$token" >> "$GITHUB_ENV"
- name: Resolve SWA default hostname
id: swa
if: steps.oidc.outputs.configured == 'true'
run: |
set -euo pipefail
host=$(az staticwebapp show -g rg-ssd-marketing -n ssd-mkt-prod-ae --query defaultHostname -o tsv)
echo "hostname=$host" >> "$GITHUB_OUTPUT"
# purple-field-05048bf00.7.azurestaticapps.net → purple-field-05048bf00
prefix=$(echo "$host" | cut -d. -f1)
echo "prefix=$prefix" >> "$GITHUB_OUTPUT"
- name: Deploy marketing SWA preview
id: deploy
if: steps.oidc.outputs.configured == 'true' && env.SWA_DEPLOYMENT_TOKEN != ''
uses: Azure/static-web-apps-deploy@v1
env:
SWA_DEPLOYMENT_TOKEN: ${{ env.SWA_DEPLOYMENT_TOKEN }}
with:
azure_static_web_apps_api_token: ${{ env.SWA_DEPLOYMENT_TOKEN }}
repo_token: ${{ secrets.GITHUB_TOKEN }}
action: upload
app_location: apps/marketing/dist
skip_app_build: true
- name: Comment preview URL
if: steps.oidc.outputs.configured == 'true' && steps.deploy.outcome == 'success'
uses: actions/github-script@v7
with:
script: |
const marker = '<!-- swa-preview-marketing -->';
const pr = context.issue.number;
const prefix = '${{ steps.swa.outputs.prefix }}';
const previewHost = `https://${prefix}-${pr}.eastasia.7.azurestaticapps.net`;
const body = [
marker,
'### Marketing preview (SWA Free)',
'',
'Static Web Apps created a **PR preview environment** for `apps/marketing`.',
'',
`- Preview URL: ${previewHost}`,
'- Production SWA: `ssd-mkt-prod-ae` (Free).',
'- Deploy token via **OIDC → Key Vault** (`ssd-global-kv-prod-ae` / `swa-marketing-deployment-token`).',
'',
'_Production: `https://singletonsd.com`._',
].join('\n');
const { data: comments } = await github.rest.issues.listComments({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
});
const existing = comments.find((c) => c.body?.includes(marker));
if (existing) {
await github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: existing.id,
body,
});
} else {
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
body,
});
}
- name: Skip notice (OIDC not configured)
if: steps.oidc.outputs.configured != 'true'
run: |
echo "Marketing SWA preview skipped — set GitHub Variables AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_SUBSCRIPTION_ID."
close_preview:
if: github.event.action == 'closed'
runs-on: ubuntu-latest
name: Close marketing SWA preview
permissions:
contents: read
id-token: write
steps:
- name: Check OIDC Variables
id: oidc
run: |
set -euo pipefail
if [ -z "${{ vars.AZURE_CLIENT_ID }}" ] || [ -z "${{ vars.AZURE_TENANT_ID }}" ] || [ -z "${{ vars.AZURE_SUBSCRIPTION_ID }}" ]; then
echo "configured=false" >> "$GITHUB_OUTPUT"
else
echo "configured=true" >> "$GITHUB_OUTPUT"
fi
- name: Azure login (OIDC)
if: steps.oidc.outputs.configured == 'true'
uses: azure/login@v2
with:
client-id: ${{ vars.AZURE_CLIENT_ID }}
tenant-id: ${{ vars.AZURE_TENANT_ID }}
subscription-id: ${{ vars.AZURE_SUBSCRIPTION_ID }}
- name: Read marketing SWA deploy token from Key Vault
if: steps.oidc.outputs.configured == 'true'
run: |
set -euo pipefail
token=$(az keyvault secret show \
--vault-name ssd-global-kv-prod-ae \
--name swa-marketing-deployment-token \
--query value -o tsv)
echo "::add-mask::$token"
echo "SWA_DEPLOYMENT_TOKEN=$token" >> "$GITHUB_ENV"
- name: Close Static Web App preview
if: steps.oidc.outputs.configured == 'true' && env.SWA_DEPLOYMENT_TOKEN != ''
uses: Azure/static-web-apps-deploy@v1
env:
SWA_DEPLOYMENT_TOKEN: ${{ env.SWA_DEPLOYMENT_TOKEN }}
with:
azure_static_web_apps_api_token: ${{ env.SWA_DEPLOYMENT_TOKEN }}
action: close