-
Notifications
You must be signed in to change notification settings - Fork 401
67 lines (57 loc) · 1.94 KB
/
dispatch_analytics.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
name: Dispatch analytics
# PROCESS
#
# 1. Trade GitHub JWT token with AWS credentials for the analytics account
# 2. Invoke a Lambda function dispatcher synchronously with the read-only scoped JWT token
# 3. The dispatcher function will call GitHub APIs to read data from the last hour and aggregate for operational analytics
# USAGE
#
# NOTE: meant to use as a scheduled task only (or manually for debugging purposes).
on:
workflow_dispatch:
schedule:
- cron: "0 * * * *"
permissions:
contents: read
jobs:
dispatch_token:
if: github.repository == 'aws-powertools/powertools-lambda-python'
concurrency:
group: analytics
runs-on: ubuntu-latest
environment: analytics
permissions:
id-token: write
actions: read
checks: read
contents: read # previously we needed `write` to use GH_TOKEN in our dispatcher (Lambda)
deployments: read
issues: read
discussions: read
packages: read
pages: read
pull-requests: read
repository-projects: read
security-events: read
statuses: read
steps:
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4.0.2
with:
aws-region: eu-central-1
role-to-assume: ${{ secrets.AWS_LAYERS_ROLE_ARN }}
mask-aws-account-id: true
- name: Invoke Lambda function
run: |
payload=$(echo -n '{"githubToken": "${{ secrets.GITHUB_TOKEN }}"}' | base64)
response=$(aws lambda invoke \
--function-name "${{ secrets.AWS_ANALYTICS_DISPATCHER_ARN }}" \
--payload "$payload" \
response.json \
--query 'FunctionError' \
--output text)
cat response.json ; echo # add newline at the end
if [ "$response" != "None" ]; then
echo "Error invoking lambda function: $response. Aborting."
exit 1
fi