Skip to content

infra: rebuild docs.nanohype.dev in the isolated account - #40

Merged
stxkxs merged 2 commits into
mainfrom
cutover-to-own-account
Aug 15, 2026
Merged

infra: rebuild docs.nanohype.dev in the isolated account#40
stxkxs merged 2 commits into
mainfrom
cutover-to-own-account

Conversation

@stxkxs

@stxkxs stxkxs commented Aug 15, 2026

Copy link
Copy Markdown
Member

See commit message for full details.

Summary

  • site-v1.3.0 so ACM can validate across accounts
  • Origin renamed to nanohype-docs-site-${TERRAGRUNT_ACCOUNT_ID}
  • CI still points at the old account on purpose

Pair with nanohype/nanohype.dev#cutover-to-own-account. Do not merge until after the window.

@stxkxs
stxkxs marked this pull request as ready for review August 15, 2026 00:40
stxkxs and others added 2 commits August 14, 2026 17:40
Same cutover as nanohype.dev, this half. Bumps site to site-v1.3.0 so the
first apply can suppress ACM validation records (site-v1.1.0 has no such
flag, and writing them into the still-undelegated parent would block for
45 minutes then fail). create_zone stays false — the parent nanohype.dev
zone already exists here (Z01486163EQUBJKF0RTR9).

The origin is nanohype-docs-site-${TERRAGRUNT_ACCOUNT_ID}, derived at apply
time so this public repo never carries the account id. 351619759866 still
holds nanohype-docs-site and will until after the window.

Distributions are not in this commit's apply: they need the
docs.nanohype.dev alias, which the old account still holds. Seeded the new
bucket (426 objects) out of band. CI (repo-level AWS_DEPLOY_ROLE_ARN and
the hardcoded BUCKET=nanohype-docs-site in deploy.yml) still points at the
old account and must not be repointed until after the switch.

Co-authored-by: stxkxsbot <275011021+stxkxsbot@users.noreply.github.com>
The live origin is now nanohype-docs-site-767397986924. deploy.yml
hardcoded the old global name; leaving it would have the next successful
ci run write to a bucket this account's deploy role cannot see, or (worse,
if someone still holds credentials on the old account) keep filling a
bucket nothing serves.

DOCS_DISTRIBUTION_ID and AWS_DEPLOY_ROLE_ARN were updated as repo
variables to match. There is no org-level copy to inherit, so the repo
variables stay — they now name the new account.

Co-authored-by: stxkxsbot <275011021+stxkxsbot@users.noreply.github.com>
@stxkxs
stxkxs force-pushed the cutover-to-own-account branch from 34a09ae to bbd74e5 Compare August 15, 2026 00:40
@stxkxs
stxkxs merged commit eacc75a into main Aug 15, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant