Skip to content

Use shared deployment suite for Forms ECS secrets - #4

Open
jmgasper wants to merge 3 commits into
developfrom
fix/ecs-appvar-injection
Open

jmgasper wants to merge 3 commits into
developfrom
fix/ecs-appvar-injection

Conversation

@jmgasper

@jmgasper jmgasper commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Forms deployments previously used a fixed CloudFormation secret list, so service/global appvars such as the Bus API authentication settings never reached the running task. This switches runtime deployment to the same pinned tc-deploy-scripts v1.4.20 flow used by bus-api-v6.

  • Load /config/forms-api-v6/deployvar with psvar-processor.sh, then invoke master_deploy.sh -d ECS -t latest -j "/config/${APPNAME}/appvar,/config/common/global-appvar" -i "$APPNAME" -p FARGATE for the selected environment.
  • Retain the existing Python helper only for the migration gate. It clones the live service task, pushes/runs the migration image with its database credential, and fails the job before runtime deployment if migration fails. The shared suite handles runtime image publishing, secret references, task registration, and service rollout.
  • Remove the custom appvar Python script, its tests, and the extra PyYAML/CI setup. Document deployment settings and the switch from CloudFormation app releases to shared ECS releases.

Validation: pnpm lint and pnpm build pass. A dry run of the actual shared scripts, using dev parameter names/settings with ECS registration mocked, verified all 20 SSM references, service precedence, CPU/memory, roles, port, health check, read-only filesystem, and log configuration. Migration success/failure checks verified that failed migrations stop the helper and that migration tasks receive only the database secret. CircleCI YAML, shell steps, Python syntax, and generated Node health-check syntax pass.

The dev deployvars are provisioned, and the current CORS/runtime environment settings are preserved as service appvars. The shared dev execution role can read both SSM paths. This revision does not deploy a new runtime; the existing healthy dev service remains on task revision 9. Production requires its corresponding deployvars/appvars before deployment. CloudFormation continues to own infrastructure; normal runtime releases now update ECS directly, matching the other v6 services.

@jmgasper jmgasper changed the title Inject Forms and global appvars into ECS on every release Use shared deployment suite for Forms ECS secrets Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant