Repository navigation
feat: DS-59 Add marketing token build smoke #18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Azure Static Web Apps PR preview for marketing (Free SKU). | |
| name: Preview Marketing (SWA) | |
| on: | |
| pull_request: | |
| types: [opened, synchronize, reopened, closed] | |
| paths: | |
| - 'apps/marketing/**' | |
| - 'scripts/validate-staticwebapp-config.mjs' | |
| - '.npmrc' | |
| - 'pnpm-lock.yaml' | |
| - '.github/workflows/preview-marketing.yml' | |
| concurrency: | |
| group: preview-marketing-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| build_and_preview: | |
| if: github.event.action != 'closed' | |
| runs-on: ubuntu-latest | |
| name: Build + marketing SWA preview | |
| permissions: | |
| contents: read | |
| id-token: write | |
| pull-requests: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 9.15.0 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 24 | |
| cache: pnpm | |
| - name: Install | |
| run: pnpm install --frozen-lockfile | |
| - name: Build marketing | |
| run: pnpm --filter @singleton-sd/marketing... run build | |
| - name: Smoke marketing tokens | |
| run: pnpm --filter @singleton-sd/marketing run test:smoke | |
| - name: Validate SWA config (dist) | |
| run: node scripts/validate-staticwebapp-config.mjs apps/marketing/dist/staticwebapp.config.json | |
| - name: Check OIDC Variables | |
| id: oidc | |
| run: | | |
| set -euo pipefail | |
| if [ -z "${{ vars.AZURE_CLIENT_ID }}" ] || [ -z "${{ vars.AZURE_TENANT_ID }}" ] || [ -z "${{ vars.AZURE_SUBSCRIPTION_ID }}" ]; then | |
| echo "configured=false" >> "$GITHUB_OUTPUT" | |
| echo "OIDC Variables not set — skipping marketing SWA deploy." | |
| else | |
| echo "configured=true" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Azure login (OIDC) | |
| if: steps.oidc.outputs.configured == 'true' | |
| uses: azure/login@v2 | |
| with: | |
| client-id: ${{ vars.AZURE_CLIENT_ID }} | |
| tenant-id: ${{ vars.AZURE_TENANT_ID }} | |
| subscription-id: ${{ vars.AZURE_SUBSCRIPTION_ID }} | |
| - name: Read marketing SWA deploy token from Key Vault | |
| if: steps.oidc.outputs.configured == 'true' | |
| run: | | |
| set -euo pipefail | |
| token=$(az keyvault secret show \ | |
| --vault-name ssd-global-kv-prod-ae \ | |
| --name swa-marketing-deployment-token \ | |
| --query value -o tsv) | |
| echo "::add-mask::$token" | |
| echo "SWA_DEPLOYMENT_TOKEN=$token" >> "$GITHUB_ENV" | |
| - name: Resolve SWA default hostname | |
| id: swa | |
| if: steps.oidc.outputs.configured == 'true' | |
| run: | | |
| set -euo pipefail | |
| host=$(az staticwebapp show -g rg-ssd-marketing -n ssd-mkt-prod-ae --query defaultHostname -o tsv) | |
| echo "hostname=$host" >> "$GITHUB_OUTPUT" | |
| # purple-field-05048bf00.7.azurestaticapps.net → purple-field-05048bf00 | |
| prefix=$(echo "$host" | cut -d. -f1) | |
| echo "prefix=$prefix" >> "$GITHUB_OUTPUT" | |
| - name: Deploy marketing SWA preview | |
| id: deploy | |
| if: steps.oidc.outputs.configured == 'true' && env.SWA_DEPLOYMENT_TOKEN != '' | |
| uses: Azure/static-web-apps-deploy@v1 | |
| env: | |
| SWA_DEPLOYMENT_TOKEN: ${{ env.SWA_DEPLOYMENT_TOKEN }} | |
| with: | |
| azure_static_web_apps_api_token: ${{ env.SWA_DEPLOYMENT_TOKEN }} | |
| repo_token: ${{ secrets.GITHUB_TOKEN }} | |
| action: upload | |
| app_location: apps/marketing/dist | |
| skip_app_build: true | |
| - name: Comment preview URL | |
| if: steps.oidc.outputs.configured == 'true' && steps.deploy.outcome == 'success' | |
| uses: actions/github-script@v7 | |
| with: | |
| script: | | |
| const marker = '<!-- swa-preview-marketing -->'; | |
| const pr = context.issue.number; | |
| const prefix = '${{ steps.swa.outputs.prefix }}'; | |
| const previewHost = `https://${prefix}-${pr}.eastasia.7.azurestaticapps.net`; | |
| const body = [ | |
| marker, | |
| '### Marketing preview (SWA Free)', | |
| '', | |
| 'Static Web Apps created a **PR preview environment** for `apps/marketing`.', | |
| '', | |
| `- Preview URL: ${previewHost}`, | |
| '- Production SWA: `ssd-mkt-prod-ae` (Free).', | |
| '- Deploy token via **OIDC → Key Vault** (`ssd-global-kv-prod-ae` / `swa-marketing-deployment-token`).', | |
| '', | |
| '_Production: `https://singletonsd.com`._', | |
| ].join('\n'); | |
| const { data: comments } = await github.rest.issues.listComments({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| issue_number: context.issue.number, | |
| }); | |
| const existing = comments.find((c) => c.body?.includes(marker)); | |
| if (existing) { | |
| await github.rest.issues.updateComment({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| comment_id: existing.id, | |
| body, | |
| }); | |
| } else { | |
| await github.rest.issues.createComment({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| issue_number: context.issue.number, | |
| body, | |
| }); | |
| } | |
| - name: Skip notice (OIDC not configured) | |
| if: steps.oidc.outputs.configured != 'true' | |
| run: | | |
| echo "Marketing SWA preview skipped — set GitHub Variables AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_SUBSCRIPTION_ID." | |
| close_preview: | |
| if: github.event.action == 'closed' | |
| runs-on: ubuntu-latest | |
| name: Close marketing SWA preview | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - name: Check OIDC Variables | |
| id: oidc | |
| run: | | |
| set -euo pipefail | |
| if [ -z "${{ vars.AZURE_CLIENT_ID }}" ] || [ -z "${{ vars.AZURE_TENANT_ID }}" ] || [ -z "${{ vars.AZURE_SUBSCRIPTION_ID }}" ]; then | |
| echo "configured=false" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "configured=true" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Azure login (OIDC) | |
| if: steps.oidc.outputs.configured == 'true' | |
| uses: azure/login@v2 | |
| with: | |
| client-id: ${{ vars.AZURE_CLIENT_ID }} | |
| tenant-id: ${{ vars.AZURE_TENANT_ID }} | |
| subscription-id: ${{ vars.AZURE_SUBSCRIPTION_ID }} | |
| - name: Read marketing SWA deploy token from Key Vault | |
| if: steps.oidc.outputs.configured == 'true' | |
| run: | | |
| set -euo pipefail | |
| token=$(az keyvault secret show \ | |
| --vault-name ssd-global-kv-prod-ae \ | |
| --name swa-marketing-deployment-token \ | |
| --query value -o tsv) | |
| echo "::add-mask::$token" | |
| echo "SWA_DEPLOYMENT_TOKEN=$token" >> "$GITHUB_ENV" | |
| - name: Close Static Web App preview | |
| if: steps.oidc.outputs.configured == 'true' && env.SWA_DEPLOYMENT_TOKEN != '' | |
| uses: Azure/static-web-apps-deploy@v1 | |
| env: | |
| SWA_DEPLOYMENT_TOKEN: ${{ env.SWA_DEPLOYMENT_TOKEN }} | |
| with: | |
| azure_static_web_apps_api_token: ${{ env.SWA_DEPLOYMENT_TOKEN }} | |
| action: close |