From e2337124715edecb5c587debbdd8012515b8d041 Mon Sep 17 00:00:00 2001 From: Philip Trauner Date: Thu, 10 Sep 2026 12:03:12 +0200 Subject: [PATCH] ops: retire aws --- .github/workflows/deploy.yaml | 81 --------- project/server/docker/entrypoint.sh | 2 - project/server/docker/node-options.ts | 24 --- project/server/vendor/aws/ecs-ci-policy.json | 41 ----- .../vendor/aws/ecs-task-definition.json | 158 ------------------ ...ecs-task-execution-role-secret-policy.json | 12 -- .../vendor/aws/ecs-task-execution-role.json | 13 -- .../vendor/aws/ecs-task-role-exec-policy.json | 25 --- .../vendor/aws/s3-snapshot-defer-policy.json | 15 -- 9 files changed, 371 deletions(-) delete mode 100644 .github/workflows/deploy.yaml delete mode 100644 project/server/docker/node-options.ts delete mode 100644 project/server/vendor/aws/ecs-ci-policy.json delete mode 100644 project/server/vendor/aws/ecs-task-definition.json delete mode 100644 project/server/vendor/aws/ecs-task-execution-role-secret-policy.json delete mode 100644 project/server/vendor/aws/ecs-task-execution-role.json delete mode 100644 project/server/vendor/aws/ecs-task-role-exec-policy.json delete mode 100644 project/server/vendor/aws/s3-snapshot-defer-policy.json diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml deleted file mode 100644 index 8d0b0a53..00000000 --- a/.github/workflows/deploy.yaml +++ /dev/null @@ -1,81 +0,0 @@ -name: deploy - -on: - push: - branches: - - main - -jobs: - deploy: - name: deploy - runs-on: ubuntu-latest - environment: production - permissions: - contents: read - attestations: write - id-token: write - steps: - - name: checkout - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - with: - lfs: true - - - name: configure credentials - uses: aws-actions/configure-aws-credentials@e7f100cf4c008499ea8adda475de1042d6975c7b # v6.2.0 - with: - aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} - aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} - aws-region: ${{ vars.AWS_REGION }} - - - name: login to ecr - id: login-ecr - uses: aws-actions/amazon-ecr-login@d539f0932e70871a027e9d5a9d8fc38589180a64 # v2.1.6 - - - name: set up qemu - uses: docker/setup-qemu-action@06116385d9baf250c9f4dcb4858b16962ea869c3 # v4.1.0 - - - name: set up docker buildx - uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0 - - - name: build and push - id: push - uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0 - env: - ECR_TAG_LATEST: ${{ steps.login-ecr.outputs.registry }}/${{ vars.ECR_REPOSITORY }}:latest - ECR_TAG_COMMIT: ${{ steps.login-ecr.outputs.registry }}/${{ vars.ECR_REPOSITORY }}:${{ github.sha }} - with: - context: project/server - platforms: linux/amd64,linux/arm64 - build-contexts: | - schema=schema - sqlc-plugin=tool/sqlc-generate-typescript-plugin/target/wasm32-wasip1/release - push: true - tags: ${{ env.ECR_TAG_LATEST }},${{ env.ECR_TAG_COMMIT }} - # inline caching isn't particularly effective 🫤 - cache-from: type=gha - cache-to: type=gha,mode=max - - - name: generate artifact attestation - uses: actions/attest@59d89421af93a897026c735860bf21b6eb4f7b26 # v4.1.0 - with: - subject-name: ${{ steps.login-ecr.outputs.registry }}/${{ vars.ECR_REPOSITORY }} - subject-digest: ${{ steps.push.outputs.digest }} - push-to-registry: true - - - name: update task definition - id: task-def - uses: aws-actions/amazon-ecs-render-task-definition@6853cfae8c3a7d978fbf68b5a55453395541dfbb # v1.8.5 - with: - task-definition: project/server/vendor/aws/ecs-task-definition.json - container-name: ${{ vars.ECS_TASK_DEFINITION_CONTAINER_NAME }} - image: ${{ steps.login-ecr.outputs.registry }}/${{ vars.ECR_REPOSITORY }}:${{ github.sha }} - - - name: deploy task definition - uses: aws-actions/amazon-ecs-deploy-task-definition@a310a830f5c14e583e35d84e4e1ec7dd177c3c9c # v2.6.2 - with: - task-definition: ${{ steps.task-def.outputs.task-definition }} - service: ${{ vars.ECS_SERVICE }} - cluster: ${{ vars.ECS_CLUSTER }} - wait-for-service-stability: true - service-managed-ebs-volume-name: "snapshot0" - service-managed-ebs-volume: '{"filesystemType": "xfs", "iops": 5000, "sizeInGiB": 50, "throughput": 800, "volumeType": "gp3", "encrypted": false, "roleArn": "arn:aws:iam::647181292512:role/ohf-device-database-infrastructure-role"}' diff --git a/project/server/docker/entrypoint.sh b/project/server/docker/entrypoint.sh index 502973c3..91680632 100755 --- a/project/server/docker/entrypoint.sh +++ b/project/server/docker/entrypoint.sh @@ -2,8 +2,6 @@ set -e -export NODE_OPTIONS="${NODE_OPTIONS:-$(node docker/node-options.ts)}" - case "${NODE_ENTRYPOINT}" in "nest") node --enable-source-maps out/server/main-nest.mjs diff --git a/project/server/docker/node-options.ts b/project/server/docker/node-options.ts deleted file mode 100644 index e6a942d0..00000000 --- a/project/server/docker/node-options.ts +++ /dev/null @@ -1,24 +0,0 @@ -import { env, stdout } from "node:process"; - -void (async () => { - // source memory limit from ECS task definition - maxOldSpaceSize: { - const uriVariable = "ECS_CONTAINER_METADATA_URI_V4"; - - if (!Object.hasOwn(env, uriVariable)) { - break maxOldSpaceSize; - } - - const response = await fetch(`${env[uriVariable]}/task`); - if (!response.ok) { - break maxOldSpaceSize; - } - - const data = await response.json(); - - const memoryLimit = data.Limits.Memory; - const maxOldSpaceSize = Math.floor(memoryLimit * 0.75); - - stdout.write(`--max-old-space-size=${maxOldSpaceSize}`); - } -})(); diff --git a/project/server/vendor/aws/ecs-ci-policy.json b/project/server/vendor/aws/ecs-ci-policy.json deleted file mode 100644 index b700212f..00000000 --- a/project/server/vendor/aws/ecs-ci-policy.json +++ /dev/null @@ -1,41 +0,0 @@ -{ - "Version": "2012-10-17", - "Statement": [ - { - "Effect": "Allow", - "Action": [ - "ecr:GetDownloadUrlForLayer", - "ecr:BatchGetImage", - "ecr:CompleteLayerUpload", - "ecr:UploadLayerPart", - "ecr:InitiateLayerUpload", - "ecr:BatchCheckLayerAvailability", - "ecr:PutImage" - ], - "Resource": "arn:aws:ecr:eu-north-1:647181292512:repository/ohf-device-database" - }, - { - "Effect": "Allow", - "Action": "ecr:GetAuthorizationToken", - "Resource": "*" - }, - { - "Effect": "Allow", - "Action": ["ecs:RegisterTaskDefinition", "ecs:TagResource"], - "Resource": "arn:aws:ecs:eu-north-1:647181292512:task-definition/ohf-device-database:*" - }, - { - "Effect": "Allow", - "Action": ["ecs:DescribeServices", "ecs:UpdateService"], - "Resource": "arn:aws:ecs:eu-north-1:647181292512:service/ohf-device-database/ohf-device-database" - }, - { - "Effect": "Allow", - "Action": "iam:PassRole", - "Resource": [ - "arn:aws:iam::647181292512:role/ohf-device-database-task-execution-role", - "arn:aws:iam::647181292512:role/ohf-device-database-task-role" - ] - } - ] -} diff --git a/project/server/vendor/aws/ecs-task-definition.json b/project/server/vendor/aws/ecs-task-definition.json deleted file mode 100644 index 827c0fd3..00000000 --- a/project/server/vendor/aws/ecs-task-definition.json +++ /dev/null @@ -1,158 +0,0 @@ -{ - "containerDefinitions": [ - { - "environment": [ - { - "name": "HOST", - "value": "0.0.0.0" - }, - { - "name": "EXTERNAL_AUTHORITY", - "value": "device-database.eco-dev-aws.openhomefoundation.com" - }, - { - "name": "INITIALLY_CONCURRENT", - "value": "true" - }, - { - "name": "DATABASE_PATH_STAGING", - "value": "/volume/database/staging.db" - }, - { - "name": "DATABASE_PATH_DERIVED", - "value": "/volume/database/derived.db" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_ENDPOINT", - "value": "https://s3.eu-north-1.amazonaws.com" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_ENDPOINT_1", - "value": "https://s3.nl-ams.scw.cloud" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_REGION", - "value": "eu-north-1" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_REGION_1", - "value": "nl-ams" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_BUCKET", - "value": "ohf-device-database-snapshot-defer" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_BUCKET_1", - "value": "device-database-snapshot-defer" - }, - { - "name": "SNAPSHOT_DEFER_TARGET", - "value": "object-store" - }, - { - "name": "DATABASE_SNAPSHOT_DESTINATION_STAGING", - "value": "/volume/snapshot/staging.db" - }, - { - "name": "SCHEDULER_ENABLE", - "value": "true" - } - ], - "secrets": [ - { - "name": "SIGNING_VOUCHER", - "valueFrom": "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu:SIGNING_VOUCHER::" - }, - { - "name": "VENDOR_SLACK_CALLBACK_SIGNING_KEY", - "valueFrom": "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu:VENDOR_SLACK_CALLBACK_SIGNING_KEY::" - }, - { - "name": "VENDOR_SLACK_BOT_TOKEN", - "valueFrom": "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu:VENDOR_SLACK_BOT_TOKEN::" - }, - { - "name": "INTROSPECTION_BEARER_TOKEN", - "valueFrom": "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu:INTROSPECTION_BEARER_TOKEN::" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_ACCESS_KEY_ID", - "valueFrom": "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu:SNAPSHOT_DEFER_OBJECT_STORE_ACCESS_KEY_ID::" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_ACCESS_KEY_ID_1", - "valueFrom": "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu:SNAPSHOT_DEFER_OBJECT_STORE_ACCESS_KEY_ID_1::" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_SECRET_ACCESS_KEY", - "valueFrom": "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu:SNAPSHOT_DEFER_OBJECT_STORE_SECRET_ACCESS_KEY::" - }, - { - "name": "SNAPSHOT_DEFER_OBJECT_STORE_SECRET_ACCESS_KEY_1", - "valueFrom": "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu:SNAPSHOT_DEFER_OBJECT_STORE_SECRET_ACCESS_KEY_1::" - } - ], - "essential": true, - "image": "647181292512.dkr.ecr.eu-north-1.amazonaws.com/ohf-device-database:latest", - "logConfiguration": { - "logDriver": "awslogs", - "options": { - "awslogs-group": "/ecs/ohf-device-database", - "awslogs-create-group": "true", - "awslogs-region": "eu-north-1", - "awslogs-stream-prefix": "ecs" - }, - "secretOptions": [] - }, - "mountPoints": [ - { - "containerPath": "/volume/database", - "readOnly": false, - "sourceVolume": "database0" - }, - { - "sourceVolume": "snapshot0", - "containerPath": "/volume/snapshot" - } - ], - "name": "server", - "portMappings": [ - { - "appProtocol": "http", - "containerPort": 3000, - "name": "server-3000-tcp", - "protocol": "tcp" - } - ] - } - ], - "executionRoleArn": "arn:aws:iam::647181292512:role/ohf-device-database-task-execution-role", - "taskRoleArn": "arn:aws:iam::647181292512:role/ohf-device-database-task-role", - "family": "ohf-device-database", - "memory": "2048", - "networkMode": "bridge", - "requiresCompatibilities": ["EC2"], - "runtimePlatform": { - "cpuArchitecture": "ARM64", - "operatingSystemFamily": "LINUX" - }, - "volumes": [ - { - "name": "database0", - "host": { - "sourcePath": "/mnt/database" - } - }, - { - "name": "snapshot0", - "configuredAtLaunch": true - } - ], - "tags": [ - { - "key": "awsApplication", - "value": "arn:aws:resource-groups:eu-north-1:647181292512:group/device-database/00xy9bh0rtnl265q6vczs6zufe" - } - ] -} diff --git a/project/server/vendor/aws/ecs-task-execution-role-secret-policy.json b/project/server/vendor/aws/ecs-task-execution-role-secret-policy.json deleted file mode 100644 index a9932b25..00000000 --- a/project/server/vendor/aws/ecs-task-execution-role-secret-policy.json +++ /dev/null @@ -1,12 +0,0 @@ -{ - "Version": "2012-10-17", - "Statement": [ - { - "Effect": "Allow", - "Action": ["secretsmanager:GetSecretValue"], - "Resource": [ - "arn:aws:secretsmanager:eu-north-1:647181292512:secret:ohf-device-database-wLJxKu" - ] - } - ] -} diff --git a/project/server/vendor/aws/ecs-task-execution-role.json b/project/server/vendor/aws/ecs-task-execution-role.json deleted file mode 100644 index fc161547..00000000 --- a/project/server/vendor/aws/ecs-task-execution-role.json +++ /dev/null @@ -1,13 +0,0 @@ -{ - "Version": "2012-10-17", - "Statement": [ - { - "Sid": "", - "Effect": "Allow", - "Principal": { - "Service": ["ecs-tasks.amazonaws.com"] - }, - "Action": "sts:AssumeRole" - } - ] -} diff --git a/project/server/vendor/aws/ecs-task-role-exec-policy.json b/project/server/vendor/aws/ecs-task-role-exec-policy.json deleted file mode 100644 index ff82451b..00000000 --- a/project/server/vendor/aws/ecs-task-role-exec-policy.json +++ /dev/null @@ -1,25 +0,0 @@ -{ - "Version": "2012-10-17", - "Statement": [ - { - "Effect": "Allow", - "Action": [ - "ssmmessages:CreateControlChannel", - "ssmmessages:CreateDataChannel", - "ssmmessages:OpenControlChannel", - "ssmmessages:OpenDataChannel" - ], - "Resource": "*" - }, - { - "Effect": "Allow", - "Action": ["logs:DescribeLogGroups"], - "Resource": "*" - }, - { - "Effect": "Allow", - "Action": ["logs:CreateLogStream", "logs:DescribeLogStreams", "logs:PutLogEvents"], - "Resource": "arn:aws:logs:eu-north-1:647181292512:log-group:/aws/ecs/ohf-device-database:*" - } - ] -} diff --git a/project/server/vendor/aws/s3-snapshot-defer-policy.json b/project/server/vendor/aws/s3-snapshot-defer-policy.json deleted file mode 100644 index 65ca4cc8..00000000 --- a/project/server/vendor/aws/s3-snapshot-defer-policy.json +++ /dev/null @@ -1,15 +0,0 @@ -{ - "Version": "2012-10-17", - "Statement": [ - { - "Effect": "Allow", - "Action": ["s3:GetBucketLocation", "s3:ListBucket"], - "Resource": "arn:aws:s3:::ohf-device-database-snapshot-defer" - }, - { - "Effect": "Allow", - "Action": ["s3:PutObject", "s3:DeleteObject", "s3:GetObject"], - "Resource": ["arn:aws:s3:::ohf-device-database-snapshot-defer/*"] - } - ] -}