feat(ci): run db migrations from github ci with environment-scoped secrets (#4957)

* feat(ci): run db migrations from github ci with environment-scoped secrets

* fix(ci): pass environment input via env var instead of shell interpolation

* fix(ci): rename migration environments to db-* to avoid collision with Vercel's Production env

* improvement(ci): resolve migration db url from prefixed repo secrets, drop github environments

* fix(ci): dev migrations use db:push only, matching previous behavior

* improvement(ci): reject pooled (pgbouncer) database urls for migrations

* Revert "improvement(ci): reject pooled (pgbouncer) database urls for migrations"

This reverts commit 3b80d8387b.
This commit is contained in:
Theodore Li
2026-06-10 20:22:20 -04:00
committed by GitHub
parent 1a5cf49449
commit 02529843f0
2 changed files with 52 additions and 14 deletions
+25 -10
View File
@@ -46,10 +46,33 @@ jobs:
echo "ℹ️ Not a release commit"
fi
# Run database migrations before images are pushed: the ECR push triggers
# CodePipeline, so migrating first guarantees the schema is in place before
# the new app version deploys (replaces the removed ECS migration sidecar)
migrate:
name: Migrate DB
needs: [test-build]
if: >-
github.event_name == 'push' &&
(github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging')
uses: ./.github/workflows/migrations.yml
with:
environment: ${{ github.ref == 'refs/heads/main' && 'production' || 'staging' }}
secrets: inherit
# Same ordering for dev (schema push before the dev image lands in ECR)
migrate-dev:
name: Migrate Dev DB
if: github.event_name == 'push' && github.ref == 'refs/heads/dev'
uses: ./.github/workflows/migrations.yml
with:
environment: dev
secrets: inherit
# Dev: build all 3 images for ECR only (no GHCR, no ARM64)
build-dev:
name: Build Dev ECR
needs: [detect-version]
needs: [detect-version, migrate-dev]
if: github.event_name == 'push' && github.ref == 'refs/heads/dev'
runs-on: blacksmith-8vcpu-ubuntu-2404
permissions:
@@ -108,7 +131,7 @@ jobs:
# Main/staging: build AMD64 images and push to ECR + GHCR
build-amd64:
name: Build AMD64
needs: [test-build, detect-version]
needs: [test-build, detect-version, migrate]
if: >-
github.event_name == 'push' &&
(github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging')
@@ -318,14 +341,6 @@ jobs:
docker manifest push "${IMAGE_BASE}:${VERSION}"
fi
# Run database migrations for dev
migrate-dev:
name: Migrate Dev DB
needs: [build-dev]
if: github.event_name == 'push' && github.ref == 'refs/heads/dev'
uses: ./.github/workflows/migrations.yml
secrets: inherit
# Check if docs changed
check-docs-changes:
name: Check Docs Changes
+27 -4
View File
@@ -2,7 +2,21 @@ name: Database Migrations
on:
workflow_call:
inputs:
environment:
description: Target environment (production, staging, or dev)
required: true
type: string
workflow_dispatch:
inputs:
environment:
description: Target environment
required: true
type: choice
options:
- production
- staging
- dev
permissions:
contents: read
@@ -35,15 +49,24 @@ jobs:
- name: Install dependencies
run: bun install --frozen-lockfile
# The expression maps the explicit environment input to exactly one repo
# secret, so the job never holds another environment's database URL. An
# unknown environment resolves to empty and the guard below fails the job.
- name: Apply database schema changes
working-directory: ./packages/db
env:
DATABASE_URL: ${{ github.ref == 'refs/heads/main' && secrets.DATABASE_URL || github.ref == 'refs/heads/dev' && secrets.DEV_DATABASE_URL || secrets.STAGING_DATABASE_URL }}
DATABASE_URL: ${{ inputs.environment == 'production' && secrets.DATABASE_URL || inputs.environment == 'staging' && secrets.STAGING_DATABASE_URL || inputs.environment == 'dev' && secrets.DEV_DATABASE_URL || '' }}
ENVIRONMENT: ${{ inputs.environment }}
run: |
if [ "${{ github.ref }}" = "refs/heads/dev" ]; then
echo "Dev environment detected — pushing schema with drizzle-kit (db:push)"
if [ -z "$DATABASE_URL" ]; then
echo "ERROR: no database URL secret resolved for environment '${ENVIRONMENT}'" >&2
exit 1
fi
if [ "${ENVIRONMENT}" = "dev" ]; then
echo "Dev environment — pushing schema directly (db:push)"
bun run db:push --force
else
echo "Applying versioned migrations (db:migrate)"
bun run ./scripts/migrate.ts
fi
fi