name: Build & Deploy on: push: branches: [main] jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - uses: actions/setup-node@v4 with: node-version: 20 cache: npm - run: npm ci - run: npm run build - name: Upload build artifacts uses: actions/upload-artifact@v3 with: name: dist path: dist deploy: needs: build runs-on: ubuntu-latest if: github.ref == 'refs/heads/main' steps: - uses: actions/download-artifact@v3 with: name: dist path: dist - name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@v3 with: aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-region: ${{ secrets.AWS_REGION }} - name: Sync hashed assets to S3 uses: aws-actions/aws-cli-action@v2 with: command: >- s3 sync dist/ "s3://${{ secrets.BUCKET_NAME }}" --delete --exclude "index.html" --cache-control "public, max-age=31536000, immutable" - name: Upload index.html uses: aws-actions/aws-cli-action@v2 with: command: >- s3 cp dist/index.html "s3://${{ secrets.BUCKET_NAME }}/index.html" --cache-control "no-cache, no-store, must-revalidate" --content-type "text/html" - name: Invalidate CloudFront uses: aws-actions/aws-cli-action@v2 with: command: >- cloudfront create-invalidation --distribution-id "${{ secrets.CLOUDFRONT_ID }}" --paths "/" "/index.html"