Skip to content

Merge pull request #75 from jsr6720/new-post #52

Merge pull request #75 from jsr6720/new-post

Merge pull request #75 from jsr6720/new-post #52

# copied from
# https://aws.amazon.com/blogs/security/use-iam-roles-to-connect-github-actions-to-actions-in-aws/
# Improved by Claude
name: AWS Deploy Jekyll website to jsrowe.com s3 bucket
on:
# Runs on pushes targeting the default branch
push:
branches: ["main"]
# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:
# Sets permissions of the GITHUB_TOKEN to allow deployment to GitHub Pages
permissions:
contents: read
pages: write
id-token: write
# Allow only one concurrent deployment, skipping runs queued between the run in-progress and latest queued.
# However, do NOT cancel in-progress runs as we want to allow these production deployments to complete.
concurrency:
group: "pages"
cancel-in-progress: false
jobs:
# Build job
build:
runs-on: ubuntu-latest
steps:
- name: Configure AWS credentials
uses: aws-actions/[email protected]
with:
role-to-assume: ${{ secrets.AWS_GHA_ROLE_TO_ASSUME }}
role-session-name: GitHub_to_AWS_via_FederatedOIDC
aws-region: ${{ vars.AWS_REGION }}
- name: Checkout
uses: actions/checkout@v4
- name: Setup Ruby
uses: ruby/setup-ruby@v1
with:
ruby-version: '3.1.3' # Specify your Ruby version
bundler-cache: true
cache-version: 0
- name: Setup Pages
id: pages
uses: actions/configure-pages@v5
- name: Build with Jekyll
# Outputs to the './_site' directory by default
run: bundle exec jekyll build --baseurl "${{ steps.pages.outputs.base_path }}"
env:
JEKYLL_ENV: production
- name: Check for broken links (warnings only)
continue-on-error: true
run: |
gem install html-proofer
echo "::warning::Running HTML-Proofer checks - errors will be reported but won't fail the build"
htmlproofer ./_site --allow-hash-href --checks "Links,Images,Scripts" || echo "::warning::HTML-Proofer found issues, see log above for details"
- name: Upload artifact
# Automatically uploads an artifact from the './_site' directory by default
uses: actions/upload-pages-artifact@v3
- name: Deploy to S3
run: |
aws s3 sync _site/ s3://${{ secrets.S3_BUCKET }} --delete --region ${{ vars.AWS_REGION }}
aws cloudfront create-invalidation --distribution-id ${{ secrets.CLOUDFRONT_DISTRIBUTION_ID }} --paths "/*"