GitHub Actions CD: deploy via workflow_dispatch #4

Closed
opened 2026-07-02 17:44:22 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-02 17:44:22 +00:00 (Migrated from github.com)

Context

Part of JMR-dev/LibreMail#11 — "Deployment from GitHub Actions."

Scope

  • GitHub Actions workflow triggered via workflow_dispatch that runs pulumi up against the production stack.
  • Wire up required secrets (Cloudflare API token, GCP credentials) as GitHub Actions secrets — document what's needed, don't commit values.
  • Restrict who can trigger it (manual production deploy) — e.g. require it be run from main and limit to maintainers.

Acceptance criteria

  • A maintainer can manually trigger the deploy workflow (Actions tab or gh workflow run) and it runs pulumi up; the deploy fails loudly (and is visible) if pulumi up errors.

Dependencies

Depends on #2 (Pulumi IaC to run). Not merge-gated — it's triggered manually rather than automatically on merge, though a maintainer should typically only run it after CI (#3) has passed on the commit being deployed.

## Context Part of [JMR-dev/LibreMail#11](https://github.com/JMR-dev/LibreMail/issues/11) — "Deployment from GitHub Actions." ## Scope - [ ] GitHub Actions workflow triggered via `workflow_dispatch` that runs `pulumi up` against the production stack. - [ ] Wire up required secrets (Cloudflare API token, GCP credentials) as GitHub Actions secrets — document what's needed, don't commit values. - [ ] Restrict who can trigger it (manual production deploy) — e.g. require it be run from `main` and limit to maintainers. ## Acceptance criteria - A maintainer can manually trigger the deploy workflow (Actions tab or `gh workflow run`) and it runs `pulumi up`; the deploy fails loudly (and is visible) if `pulumi up` errors. ## Dependencies Depends on #2 (Pulumi IaC to run). Not merge-gated — it's triggered manually rather than automatically on merge, though a maintainer should typically only run it after CI (#3) has passed on the commit being deployed.
Sign in to join this conversation.