Skip to content

try moving perms

try moving perms #42

Workflow file for this run

name: CD
on:
push:
branches:
- main
permissions:
id-token: write
contents: read
jobs:
validate:
uses: ./.github/workflows/verify.yml
permissions:
contents: read
id-token: write
deploy:
needs:
- validate
permissions:
contents: read
id-token: write
runs-on: ubuntu-22.04
environment: production
steps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v2
with:
node-version: "18"
cache: "npm"
- uses: aws-actions/configure-aws-credentials@v2
with:
aws-region: us-west-2
role-session-name: GitHubActions
role-to-assume: ${{ secrets.AWS_READ_WRITE_ROLE_ARN }}
- run: npm ci
- run: npm run deploy -- cloudflareZones emailAccounts --auto-approve