Skip to content

Deployment

Account topology

AccountPurpose
cicdCodePipeline + CodeBuild; holds no customer data
devautomatic deploys of main and dev* branches
stagepre-production, manual approval
prodproduction, manual approval

One-time onboarding

  1. Create the four accounts (AWS Organizations recommended, with SCPs: block root usage, require CloudTrail — the standard compliance baseline).

  2. Bootstrap each environment account (trust the CI/CD account):

    Terminal window
    # in dev, stage, prod accounts:
    npx cdk bootstrap aws://<account>/us-east-1 \
    --trust <cicd-account-id> \
    --cloudformation-execution-policies arn:aws:iam::aws:policy/AdministratorAccess
  3. Create the GitHub CodeStar connection in the CI/CD account (Console → Developer Tools → Connections → GitHub App), and note its ARN.

  4. Deploy the pipeline:

    Terminal window
    pnpm deploy:pipeline --connection-arn=arn:aws:codestar-connections:us-east-1:<cicd>:connection/<uuid>

    (Pushing to main or any branch starting with dev now triggers: build → test → synth → dev.)

  5. DNS delegation. Each environment creates its own hosted zone (dev.frond.cntnus.app, stage.frond.cntnus.app, frond.cntnus.app). In the parent zone (cntnus.app), create NS records pointing the subdomains at the name servers of each environment’s zone (readable from Route 53 after first deploy). ACM validation uses DNS, so certificates issue automatically once delegation exists.

  6. Security contacts. Deploy with -c securityContactEmail=… -c budgetAlertEmail=… in prod to wire alert subscriptions.

  7. Security Hub — enable CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices standards in each account (see the SOC 2 guide).

Promotion flow

main, dev* ──push──▶ Source ──▶ Synth (install/build/test/synth) ──▶ Deploy dev
▲ │
└──────────── pipeline self-mutation ◀──────┘
│ manual approval
▼
Deploy stage
│ manual approval
▼
Deploy prod

The pipeline is self-mutating: infra changes on main update the pipeline itself before stages deploy.

Local deploys (escape hatch)

Terminal window
cd infra
npx cdk -a 'npx ts-node bin/app.ts' deploy -c env=dev --all

Requires credentials for the dev account only. Stage/prod deploys from workstations are disabled by policy (documented, enforced via the account’s permission boundary; the pipeline role is the only deployer).

Rollbacks

  • Frontends: CloudFront serves immutable assets; redeploying the previous commit restores instantly (or use CloudFront invalidation).
  • API: Lambda versions are immutable — roll back by deploying the previous git commit; the pipeline retains build history.
  • Data: S3 versioning + DynamoDB PITR (see the disaster-recovery guide).