|
| 1 | +name: AdminWebpage-Deploy-WF |
| 2 | + |
| 3 | +# Provisions the Admin Web App App Service via Terraform, then builds and |
| 4 | +# deploys the React SPA to it. Auth uses the same OIDC federated identity |
| 5 | +# Phil configured for the BotNet API workflow, so no new secrets are needed. |
| 6 | + |
| 7 | +on: |
| 8 | + workflow_dispatch: |
| 9 | + pull_request: |
| 10 | + branches: [main] |
| 11 | + paths: |
| 12 | + - "admin-webapp/**" |
| 13 | + - "Iac/admin-webapp/**" |
| 14 | + - ".github/workflows/AdminWebpage-Deploy-WF.yml" |
| 15 | + push: |
| 16 | + branches: [main] |
| 17 | + paths: |
| 18 | + - "admin-webapp/**" |
| 19 | + - "Iac/admin-webapp/**" |
| 20 | + - ".github/workflows/AdminWebpage-Deploy-WF.yml" |
| 21 | + |
| 22 | +permissions: |
| 23 | + id-token: write |
| 24 | + contents: read |
| 25 | + |
| 26 | +env: |
| 27 | + RESOURCE_GROUP: ewu-deliverybotsystem-rg |
| 28 | + APP_SERVICE_NAME: WA-DeliveryBot-Admin-dev |
| 29 | + TFSTATE_STORAGE_ACCOUNT: dbstfstate01 |
| 30 | + TFSTATE_CONTAINER: tfstate |
| 31 | + BOTNET_API_URL: https://ewu-deliverybotsystem-api.mangocoast-332176b0.westus2.azurecontainerapps.io |
| 32 | + SIMULATOR_API_URL: https://deliverybot-robot-simulator.mangocoast-332176b0.westus2.azurecontainerapps.io |
| 33 | + |
| 34 | +jobs: |
| 35 | + provision-and-deploy: |
| 36 | + runs-on: ubuntu-latest |
| 37 | + |
| 38 | + steps: |
| 39 | + - name: Checkout repository |
| 40 | + uses: actions/checkout@v4 |
| 41 | + |
| 42 | + # ── 1. Authenticate to Azure via OIDC ──────────────────────────────── |
| 43 | + - name: Azure Login (OIDC) |
| 44 | + uses: azure/login@v2 |
| 45 | + with: |
| 46 | + client-id: ${{ secrets.AZURE_CLIENT_ID }} |
| 47 | + tenant-id: ${{ secrets.AZURE_TENANT_ID }} |
| 48 | + subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }} |
| 49 | + |
| 50 | + # ── 2. Ensure the Terraform state container exists ──────────────────── |
| 51 | + # `az storage container create` is idempotent; safe to run every time. |
| 52 | + - name: Ensure TF state container exists |
| 53 | + run: | |
| 54 | + az storage container create \ |
| 55 | + --name "$TFSTATE_CONTAINER" \ |
| 56 | + --account-name "$TFSTATE_STORAGE_ACCOUNT" \ |
| 57 | + --auth-mode login \ |
| 58 | + --only-show-errors |
| 59 | +
|
| 60 | + # ── 3. Provision App Service via Terraform ──────────────────────────── |
| 61 | + - name: Setup Terraform |
| 62 | + uses: hashicorp/setup-terraform@v3 |
| 63 | + with: |
| 64 | + terraform_version: "1.9.5" |
| 65 | + |
| 66 | + - name: Terraform Init |
| 67 | + working-directory: ./Iac/admin-webapp |
| 68 | + env: |
| 69 | + ARM_USE_OIDC: "true" |
| 70 | + ARM_USE_AZUREAD: "true" |
| 71 | + ARM_CLIENT_ID: ${{ secrets.AZURE_CLIENT_ID }} |
| 72 | + ARM_TENANT_ID: ${{ secrets.AZURE_TENANT_ID }} |
| 73 | + ARM_SUBSCRIPTION_ID: ${{ secrets.AZURE_SUBSCRIPTION_ID }} |
| 74 | + run: terraform init -input=false |
| 75 | + |
| 76 | + - name: Terraform Apply |
| 77 | + working-directory: ./Iac/admin-webapp |
| 78 | + env: |
| 79 | + ARM_USE_OIDC: "true" |
| 80 | + ARM_USE_AZUREAD: "true" |
| 81 | + ARM_CLIENT_ID: ${{ secrets.AZURE_CLIENT_ID }} |
| 82 | + ARM_TENANT_ID: ${{ secrets.AZURE_TENANT_ID }} |
| 83 | + ARM_SUBSCRIPTION_ID: ${{ secrets.AZURE_SUBSCRIPTION_ID }} |
| 84 | + run: terraform apply -input=false -auto-approve |
| 85 | + |
| 86 | + # ── 4. Build the SPA with upstream URLs baked in ────────────────────── |
| 87 | + - name: Setup Node.js |
| 88 | + uses: actions/setup-node@v4 |
| 89 | + with: |
| 90 | + node-version: "22.x" |
| 91 | + cache: "npm" |
| 92 | + cache-dependency-path: admin-webapp/package-lock.json |
| 93 | + |
| 94 | + - name: Install dependencies |
| 95 | + working-directory: ./admin-webapp |
| 96 | + run: npm install |
| 97 | + |
| 98 | + - name: Run unit tests |
| 99 | + working-directory: ./admin-webapp |
| 100 | + run: npm test |
| 101 | + |
| 102 | + - name: Build React app |
| 103 | + working-directory: ./admin-webapp |
| 104 | + env: |
| 105 | + VITE_BOTNET_API_URL: ${{ env.BOTNET_API_URL }} |
| 106 | + VITE_SIMULATOR_API_URL: ${{ env.SIMULATOR_API_URL }} |
| 107 | + run: npm run build |
| 108 | + |
| 109 | + # ── 5. Deploy the build to the App Service ──────────────────────────── |
| 110 | + - name: Deploy to Azure App Service |
| 111 | + uses: azure/webapps-deploy@v3 |
| 112 | + with: |
| 113 | + app-name: ${{ env.APP_SERVICE_NAME }} |
| 114 | + package: ./admin-webapp/dist |
| 115 | + |
| 116 | + - name: Print deployment URL |
| 117 | + run: | |
| 118 | + FQDN=$(az webapp show \ |
| 119 | + --name "$APP_SERVICE_NAME" \ |
| 120 | + --resource-group "$RESOURCE_GROUP" \ |
| 121 | + --query defaultHostName -o tsv) |
| 122 | + echo "========================================" |
| 123 | + echo " Admin Web App deployed!" |
| 124 | + echo " URL: https://${FQDN}" |
| 125 | + echo "========================================" |
0 commit comments