Skip to content

ci(deploy): each network signs with its own deployer key - #83

Merged
xgreenx merged 1 commit into
mainfrom
ci/ens-deploy-per-network-keys
Oct 5, 2026
Merged

xgreenx merged 1 commit into
mainfrom
ci/ens-deploy-per-network-keys

Conversation

@xgreenx

@xgreenx xgreenx commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

"Deploy the ENS resolver" named one key and one role of an AWS account that no longer exists, so it could not run. Each network has its own deployer key in its own account.

Changes

  • Key: alias/libid-<network>-deployer. testnet signs as the owner of testnet.handles.link, mainnet as the owner of handles.link.
  • Role: unchanged in the file; it is the environment's AWS_DEPLOYER_ROLE_ARN secret, now set on testnet and mainnet to the roles of https://github.com/grndd-systems/deployment/pull/130.
  • ens_name: required, no default, since the name differs by network.
  • The header describes the two keys and the subject the roles trust.

Verified

  • A dry run on testnet from this branch: the role is assumed, the signer is the testnet deployer, and it owns testnet.handles.link on Sepolia (run linked in a comment).

Not verified / known issues

  • mainnet: a dry run waits for a reviewer's approval.
  • ENS_RPC_URL is set on neither environment, so a run takes rpc_url.

Assisted-by: Claude Fable 5.1

The resolver deploy named one key and one role of an AWS account that no
longer exists. Each network has its own deployer key in its own account:
`testnet` signs with alias/libid-testnet-deployer, the owner of
`testnet.handles.link`, and `mainnet` with alias/libid-mainnet-deployer,
the owner of `handles.link`. The role comes from the environment's
AWS_DEPLOYER_ROLE_ARN secret, and the name to point is asked for rather
than defaulted, since it differs by network.

Assisted-by: Claude Fable 5.1
Signed-off-by: Green Baneling <XgreenX9999@gmail.com>
@xgreenx

xgreenx commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Dry run on testnet from this branch: https://github.com/libid-org/libID-contracts/actions/runs/37245691401 — the role is assumed, the signer is 0xDAEb247f5A90C53F2D7A80A81f6cb6acB0D8b907 (alias/libid-testnet-deployer), the chain is 11155111 and the signer owns testnet.handles.link.

@xgreenx xgreenx self-assigned this Oct 5, 2026
@xgreenx
xgreenx merged commit d43673a into main Oct 5, 2026
12 checks passed
@xgreenx
xgreenx deleted the ci/ens-deploy-per-network-keys branch October 5, 2026 00:00

This branch was successfully deployed

2 active deployments
mainnet — 21bed48a Deployed Oct 5, 2026 by xgreenx via handles.link on mainnet #9
testnet — 21bed48a Deployed Oct 4, 2026 by xgreenx via testnet.handles.link on testnet #8
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant