GitHub Actions
Recipe
mkdocs buildを実行し、静的コンテンツをS3へ同期
-
フォルダ構成
./ ├── README.md ├── requirements.txt └── pj/ # mkdocs プロジェクトフォルダ ├── docs/ │ ├── hoge/ │ │ └── hoge.md │ │ : │ │ : │ ├── index.md │ └── mkdocs.yml -
.github/workflows/aws-s3-sync.yml# Sample workflow to access AWS resources when workflow is tied to branch # The workflow Creates static website using aws s3 name: AWS S3 Sync workflow on: push: branches: - main - "releases/**" env: BUCKET_NAME: "${{ secrets.S3_BUCKET_NAME }}" AWS_REGION: "${{ secrets.AWS_REGION }}" IAM_ROLE_ARN: "arn:aws:iam::${{ secrets.AWS_ACCOUNT_ID }}:role/${{ secrets.ROLE_NAME }}" # permission can be added at job level or workflow level permissions: id-token: write # This is required for requesting the JWT contents: read # This is required for actions/checkout jobs: S3PackageUpload: runs-on: ubuntu-latest steps: # checkout - name: Git clone the repository uses: actions/checkout@v3 - name: Install Python uses: actions/setup-python@v4 with: python-version: "3.9" - name: Setup mkdocs if: ${{ success() }} run: | python -m pip install -r requirements.txt - name: Configure AWS Credentials uses: aws-actions/configure-aws-credentials@v1-node16 with: role-to-assume: ${{ env.IAM_ROLE_ARN }} role-session-name: s3_session aws-region: ${{ env.AWS_REGION }} role-duration-seconds: 1200 - name: Mkdocs build working-directory: ./pj run: | mkdocs build # Sync a file to AWS s3 - name: S3 Sync files to S3 working-directory: ./pj/site run: | aws s3 sync ./ s3://${{ env.BUCKET_NAME }} --delete -
./requirements.txt... mkdocs とかをインストール.pip freezeで出力しておく. - secrets
S3_BUCKET_NAME... s3 syncを実施するS3バケット.AWS_REGION... リージョンを指定.AWS_ACCOUNT_ID... アカウントID.ROLE_NAME... AssuemeRoleするためのロール.- reference
- Configuring OpenID Connect in Amazon Web Services