From a93e5ad44e8afa53ff57c47c3c0d8679c444978d Mon Sep 17 00:00:00 2001 From: Saqib Date: Tue, 8 Sep 2026 13:23:07 +0530 Subject: [PATCH] ci: deploy from the keycloak-production environment auth.civicdatalab.in serves production auth for every CivicDataLab product, so the deploy should not run under an environment named staging. This could not be done in the promotion PR: GitHub cannot move secrets between environments, and the deploy's SSH credentials were scoped to keycloak-staging. EC2_HOST, EC2_USERNAME and EC2_PRIVATE_KEY have now been added to keycloak-production, verified present, so the workflow can point at it. keycloak-staging is deliberately left in place. A missing environment secret surfaces as an opaque ssh authentication failure rather than "secret not found", so being able to flip back in one line is worth keeping until a deploy has succeeded from the new environment. The container names, the kc_postgres_data volume and DEPLOY_PATH still say staging and still must not be renamed - those are on the running server, and changing them orphans the container or empties the database. --- .github/workflows/deploy-keycloak-staging.yml | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/.github/workflows/deploy-keycloak-staging.yml b/.github/workflows/deploy-keycloak-staging.yml index 1d86948..53cc3d3 100644 --- a/.github/workflows/deploy-keycloak-staging.yml +++ b/.github/workflows/deploy-keycloak-staging.yml @@ -149,11 +149,19 @@ jobs: name: Deploy to production needs: build runs-on: ubuntu-latest - # Kept as keycloak-staging on purpose: EC2_HOST, EC2_USERNAME and - # EC2_PRIVATE_KEY are scoped to this environment, and GitHub cannot rename an - # environment while preserving its secrets. Renaming would strip the deploy's - # SSH key. Rename only alongside re-adding those three secrets. - environment: keycloak-staging + # keycloak-production, not keycloak-staging: auth.civicdatalab.in serves + # production auth for every CivicDataLab product. + # + # GitHub cannot move secrets between environments, so this could only change + # once EC2_HOST, EC2_USERNAME and EC2_PRIVATE_KEY had been added to the new + # environment. They have been. keycloak-staging is deliberately left in place + # until a deploy has succeeded from here -- a missing secret surfaces as an + # opaque ssh auth failure, not as "secret not found", so the ability to flip + # back in one line is worth keeping for a release or two. + # + # This environment is also where a required reviewer would be configured if + # production deploys should need approval. + environment: keycloak-production timeout-minutes: 15 permissions: contents: read