Deployment
Account topology
| Account | Purpose |
|---|---|
cicd | CodePipeline + CodeBuild; holds no customer data |
dev | automatic deploys of main and dev* branches |
stage | pre-production, manual approval |
prod | production, manual approval |
One-time onboarding
-
Create the four accounts (AWS Organizations recommended, with SCPs: block root usage, require CloudTrail — the standard compliance baseline).
-
Bootstrap each environment account (trust the CI/CD account):
Terminal window # in dev, stage, prod accounts:npx cdk bootstrap aws://<account>/us-east-1 \--trust <cicd-account-id> \--cloudformation-execution-policies arn:aws:iam::aws:policy/AdministratorAccess -
Create the GitHub CodeStar connection in the CI/CD account (Console → Developer Tools → Connections → GitHub App), and note its ARN.
-
Deploy the pipeline:
Terminal window pnpm deploy:pipeline --connection-arn=arn:aws:codestar-connections:us-east-1:<cicd>:connection/<uuid>(Pushing to
mainor any branch starting withdevnow triggers: build → test → synth → dev.) -
DNS delegation. Each environment creates its own hosted zone (
dev.frond.cntnus.app,stage.frond.cntnus.app,frond.cntnus.app). In the parent zone (cntnus.app), create NS records pointing the subdomains at the name servers of each environment’s zone (readable from Route 53 after first deploy). ACM validation uses DNS, so certificates issue automatically once delegation exists. -
Security contacts. Deploy with
-c securityContactEmail=… -c budgetAlertEmail=…in prod to wire alert subscriptions. -
Security Hub — enable
CIS AWS Foundations BenchmarkandAWS Foundational Security Best Practicesstandards in each account (see the SOC 2 guide).
Promotion flow
main, dev* ──push──▶ Source ──▶ Synth (install/build/test/synth) ──▶ Deploy dev ▲ │ └──────────── pipeline self-mutation ◀──────┘ │ manual approval ▼ Deploy stage │ manual approval ▼ Deploy prodThe pipeline is self-mutating: infra changes on main update the
pipeline itself before stages deploy.
Local deploys (escape hatch)
cd infranpx cdk -a 'npx ts-node bin/app.ts' deploy -c env=dev --allRequires credentials for the dev account only. Stage/prod deploys from workstations are disabled by policy (documented, enforced via the account’s permission boundary; the pipeline role is the only deployer).
Rollbacks
- Frontends: CloudFront serves immutable assets; redeploying the previous commit restores instantly (or use CloudFront invalidation).
- API: Lambda versions are immutable — roll back by deploying the previous git commit; the pipeline retains build history.
- Data: S3 versioning + DynamoDB PITR (see the disaster-recovery guide).