From 15618b66ce08af11e71f1733de6ead25e55f843c Mon Sep 17 00:00:00 2001 From: RG756 Date: Thu, 10 Sep 2026 21:07:24 +0900 Subject: [PATCH 1/9] Add CodeBuild project and buildspec for CI pipeline --- buildspec.yml | 19 ++++++++ project-d-serverless-api/codebuild.tf | 67 +++++++++++++++++++++++++++ 2 files changed, 86 insertions(+) create mode 100644 buildspec.yml create mode 100644 project-d-serverless-api/codebuild.tf diff --git a/buildspec.yml b/buildspec.yml new file mode 100644 index 0000000..7e59c16 --- /dev/null +++ b/buildspec.yml @@ -0,0 +1,19 @@ +version: 0.2 + +phases: + install: + runtime-versions: + python: 3.11 + commands: + - pip install pytest boto3 moto + + build: + commands: + - echo "Running unit tests..." + - cd project-d-serverless-api + - python -m pytest tests/ -v + +artifacts: + files: + - project-d-serverless-api/lambda/index.py + discard-paths: no \ No newline at end of file diff --git a/project-d-serverless-api/codebuild.tf b/project-d-serverless-api/codebuild.tf new file mode 100644 index 0000000..6c958ef --- /dev/null +++ b/project-d-serverless-api/codebuild.tf @@ -0,0 +1,67 @@ +# CodeBuild用IAMロール +resource "aws_iam_role" "codebuild_role" { + name = "codebuild-project-d-role" + + assume_role_policy = jsonencode({ + Version = "2012-10-17" + Statement = [{ + Effect = "Allow" + Principal = { Service = "codebuild.amazonaws.com" } + Action = "sts:AssumeRole" + }] + }) +} + +resource "aws_iam_role_policy" "codebuild_policy" { + role = aws_iam_role.codebuild_role.name + + policy = jsonencode({ + Version = "2012-10-17" + Statement = [ + { + Effect = "Allow" + Action = [ + "logs:CreateLogGroup", + "logs:CreateLogStream", + "logs:PutLogEvents" + ] + Resource = "*" + }, + { + Effect = "Allow" + Action = [ + "s3:GetObject", + "s3:PutObject", + "s3:GetBucketAcl", + "s3:GetBucketLocation" + ] + Resource = "*" + } + ] + }) +} + +# CodeBuildプロジェクト +resource "aws_codebuild_project" "project_d" { + name = "project-d-build" + description = "CI build and test for Project D serverless API" + service_role = aws_iam_role.codebuild_role.arn + build_timeout = 10 + + source { + type = "GITHUB" + location = "https://github.com/RG756/cloud-engineering-learning" + buildspec = "buildspec.yml" + git_clone_depth = 1 + } + + environment { + compute_type = "BUILD_GENERAL1_SMALL" + image = "aws/codebuild/standard:7.0" + type = "LINUX_CONTAINER" + } + + artifacts { + type = "NO_ARTIFACTS" + } +} \ No newline at end of file From 7748a567f8d8d8b67f645ef31c241212eedb3b59 Mon Sep 17 00:00:00 2001 From: RG756 Date: Thu, 10 Sep 2026 21:48:43 +0900 Subject: [PATCH 2/9] Fix CodeBuild source config: remove unsupported connection_arn --- project-d-serverless-api/codebuild.tf | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/project-d-serverless-api/codebuild.tf b/project-d-serverless-api/codebuild.tf index 6c958ef..4b04ef7 100644 --- a/project-d-serverless-api/codebuild.tf +++ b/project-d-serverless-api/codebuild.tf @@ -43,16 +43,21 @@ resource "aws_iam_role_policy" "codebuild_policy" { # CodeBuildプロジェクト resource "aws_codebuild_project" "project_d" { - name = "project-d-build" - description = "CI build and test for Project D serverless API" - service_role = aws_iam_role.codebuild_role.arn - build_timeout = 10 + name = "project-d-build" + description = "CI build and test for Project D serverless API" + service_role = aws_iam_role.codebuild_role.arn + build_timeout = 10 + source_version = "e-phase2-codebuild-deploy" source { type = "GITHUB" location = "https://github.com/RG756/cloud-engineering-learning" buildspec = "buildspec.yml" git_clone_depth = 1 + + git_submodules_config { + fetch_submodules = false + } } environment { From 6455f7f2f33d4e0bde414312614761dd9be0d005 Mon Sep 17 00:00:00 2001 From: RG756 Date: Tue, 15 Sep 2026 23:02:15 +0900 Subject: [PATCH 3/9] Add CodeDeploy app and deployment group for Lambda --- project-d-serverless-api/codedeploy.tf | 37 ++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 project-d-serverless-api/codedeploy.tf diff --git a/project-d-serverless-api/codedeploy.tf b/project-d-serverless-api/codedeploy.tf new file mode 100644 index 0000000..d952ff1 --- /dev/null +++ b/project-d-serverless-api/codedeploy.tf @@ -0,0 +1,37 @@ +# CodeDeploy用IAMロール +resource "aws_iam_role" "codedeploy_role" { + name = "codedeploy-project-d-role" + + assume_role_policy = jsonencode({ + Version = "2012-10-17" + Statement = [{ + Effect = "Allow" + Principal = { Service = "codedeploy.amazonaws.com" } + Action = "sts:AssumeRole" + }] + }) +} + +resource "aws_iam_role_policy_attachment" "codedeploy_policy" { + role = aws_iam_role.codedeploy_role.name + policy_arn = "arn:aws:iam::aws:policy/service-role/AWSCodeDeployRoleForLambda" +} + +# CodeDeployアプリケーション +resource "aws_codedeploy_app" "project_d" { + name = "project-d-deploy" + compute_platform = "Lambda" +} + +# CodeDeployデプロイグループ +resource "aws_codedeploy_deployment_group" "project_d" { + app_name = aws_codedeploy_app.project_d.name + deployment_group_name = "project-d-deployment-group" + service_role_arn = aws_iam_role.codedeploy_role.arn + deployment_config_name = "CodeDeployDefault.LambdaAllAtOnce" + + deployment_style { + deployment_option = "WITH_TRAFFIC_CONTROL" + deployment_type = "BLUE_GREEN" + } +} \ No newline at end of file From 8bf406313ce65b4dafce88731a4bf7e266fe8e2a Mon Sep 17 00:00:00 2001 From: RG756 Date: Tue, 15 Sep 2026 23:27:56 +0900 Subject: [PATCH 4/9] Add appspec.yml and CodeDeploy integration to buildspec --- appspec.yml | 9 +++++++++ buildspec.yml | 13 +++++++++++++ project-d-serverless-api/codebuild.tf | 15 +++++++++++++++ 3 files changed, 37 insertions(+) create mode 100644 appspec.yml diff --git a/appspec.yml b/appspec.yml new file mode 100644 index 0000000..b5e382a --- /dev/null +++ b/appspec.yml @@ -0,0 +1,9 @@ +version: 0.0 +Resources: + - myLambdaFunction: + Type: AWS::Lambda::Function + Properties: + Name: "project-d-api" + Alias: "live" + CurrentVersion: "" + TargetVersion: "" \ No newline at end of file diff --git a/buildspec.yml b/buildspec.yml index 7e59c16..4fa763b 100644 --- a/buildspec.yml +++ b/buildspec.yml @@ -12,8 +12,21 @@ phases: - echo "Running unit tests..." - cd project-d-serverless-api - python -m pytest tests/ -v + - cd .. + + post_build: + commands: + - echo "Publishing new Lambda version..." + - aws lambda publish-version --function-name project-d-api --query 'Version' --output text > /tmp/new_version.txt + - NEW_VERSION=$(cat /tmp/new_version.txt) + - echo "New version is $NEW_VERSION" + - sed -i "s//$(aws lambda list-aliases --function-name project-d-api --query 'Aliases[?Name==`live`].FunctionVersion' --output text)/g" appspec.yml + - sed -i "s//$NEW_VERSION/g" appspec.yml + - echo "Creating CodeDeploy deployment..." + - aws deploy create-deployment --application-name project-d-deploy --deployment-group-name project-d-deployment-group --revision revisionType=AppSpecContent,appSpecContent={content="$(cat appspec.yml)"} artifacts: files: + - appspec.yml - project-d-serverless-api/lambda/index.py discard-paths: no \ No newline at end of file diff --git a/project-d-serverless-api/codebuild.tf b/project-d-serverless-api/codebuild.tf index 4b04ef7..cf03937 100644 --- a/project-d-serverless-api/codebuild.tf +++ b/project-d-serverless-api/codebuild.tf @@ -36,6 +36,21 @@ resource "aws_iam_role_policy" "codebuild_policy" { "s3:GetBucketLocation" ] Resource = "*" + }, + { + Effect = "Allow" + Action = [ + "lambda:PublishVersion", + "lambda:ListAliases", + "lambda:GetAlias", + "lambda:UpdateAlias", + "codedeploy:CreateDeployment", + "codedeploy:GetDeployment", + "codedeploy:GetDeploymentConfig", + "codedeploy:RegisterApplicationRevision", + "codedeploy:GetApplicationRevision" + ] + Resource = "*" } ] }) From c06a6a35a22a5d7b9a82145ac16bd5e9374cb98c Mon Sep 17 00:00:00 2001 From: RG756 Date: Tue, 15 Sep 2026 23:49:15 +0900 Subject: [PATCH 5/9] Fix buildspec post_build: use python json to escape appspec content --- buildspec.yml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/buildspec.yml b/buildspec.yml index 4fa763b..2368c74 100644 --- a/buildspec.yml +++ b/buildspec.yml @@ -20,10 +20,11 @@ phases: - aws lambda publish-version --function-name project-d-api --query 'Version' --output text > /tmp/new_version.txt - NEW_VERSION=$(cat /tmp/new_version.txt) - echo "New version is $NEW_VERSION" - - sed -i "s//$(aws lambda list-aliases --function-name project-d-api --query 'Aliases[?Name==`live`].FunctionVersion' --output text)/g" appspec.yml + - CURRENT_VERSION=$(aws lambda list-aliases --function-name project-d-api --query 'Aliases[?Name==`live`].FunctionVersion' --output text) + - echo "Current version is $CURRENT_VERSION" + - sed -i "s//$CURRENT_VERSION/g" appspec.yml - sed -i "s//$NEW_VERSION/g" appspec.yml - - echo "Creating CodeDeploy deployment..." - - aws deploy create-deployment --application-name project-d-deploy --deployment-group-name project-d-deployment-group --revision revisionType=AppSpecContent,appSpecContent={content="$(cat appspec.yml)"} + - aws deploy create-deployment --application-name project-d-deploy --deployment-group-name project-d-deployment-group --revision "revisionType=AppSpecContent,appSpecContent={content=$(python3 -c 'import json,sys; print(json.dumps(open("appspec.yml").read()))')}" artifacts: files: From e79c1553fd4ad2bc98713d908ff3a5be712958aa Mon Sep 17 00:00:00 2001 From: RG756 Date: Wed, 16 Sep 2026 00:02:22 +0900 Subject: [PATCH 6/9] Fix appspec format and buildspec CodeDeploy command --- appspec.yml | 3 ++- buildspec.yml | 3 ++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/appspec.yml b/appspec.yml index b5e382a..9dcdab2 100644 --- a/appspec.yml +++ b/appspec.yml @@ -6,4 +6,5 @@ Resources: Name: "project-d-api" Alias: "live" CurrentVersion: "" - TargetVersion: "" \ No newline at end of file + TargetVersion: "" +Hooks: [] \ No newline at end of file diff --git a/buildspec.yml b/buildspec.yml index 2368c74..578aa84 100644 --- a/buildspec.yml +++ b/buildspec.yml @@ -24,7 +24,8 @@ phases: - echo "Current version is $CURRENT_VERSION" - sed -i "s//$CURRENT_VERSION/g" appspec.yml - sed -i "s//$NEW_VERSION/g" appspec.yml - - aws deploy create-deployment --application-name project-d-deploy --deployment-group-name project-d-deployment-group --revision "revisionType=AppSpecContent,appSpecContent={content=$(python3 -c 'import json,sys; print(json.dumps(open("appspec.yml").read()))')}" + - APPSPEC_CONTENT=$(python3 -c 'import json; print(json.dumps(open("appspec.yml").read()))') + - aws deploy create-deployment --application-name project-d-deploy --deployment-group-name project-d-deployment-group --revision "revisionType=AppSpecContent,appSpecContent={content=$APPSPEC_CONTENT,sha256=$(echo -n $APPSPEC_CONTENT | sha256sum | cut -d' ' -f1)}" artifacts: files: From cda4cfb43b955dd0f0046c885977afeecdd7de8e Mon Sep 17 00:00:00 2001 From: RG756 Date: Wed, 16 Sep 2026 00:10:56 +0900 Subject: [PATCH 7/9] Fix CodeDeploy revision: remove sha256 from appspec content --- buildspec.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/buildspec.yml b/buildspec.yml index 578aa84..420434c 100644 --- a/buildspec.yml +++ b/buildspec.yml @@ -25,7 +25,7 @@ phases: - sed -i "s//$CURRENT_VERSION/g" appspec.yml - sed -i "s//$NEW_VERSION/g" appspec.yml - APPSPEC_CONTENT=$(python3 -c 'import json; print(json.dumps(open("appspec.yml").read()))') - - aws deploy create-deployment --application-name project-d-deploy --deployment-group-name project-d-deployment-group --revision "revisionType=AppSpecContent,appSpecContent={content=$APPSPEC_CONTENT,sha256=$(echo -n $APPSPEC_CONTENT | sha256sum | cut -d' ' -f1)}" + - aws deploy create-deployment --application-name project-d-deploy --deployment-group-name project-d-deployment-group --revision "revisionType=AppSpecContent,appSpecContent={content=$APPSPEC_CONTENT}" artifacts: files: From 42bd8878c39a7a6520825e51ee63a96f6cc332c5 Mon Sep 17 00:00:00 2001 From: RG756 Date: Wed, 16 Sep 2026 16:20:09 +0900 Subject: [PATCH 8/9] Fix CodeDeploy: use Python subprocess to pass appspec as JSON --- buildspec.yml | 20 ++++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/buildspec.yml b/buildspec.yml index 420434c..f8fc9ba 100644 --- a/buildspec.yml +++ b/buildspec.yml @@ -24,8 +24,24 @@ phases: - echo "Current version is $CURRENT_VERSION" - sed -i "s//$CURRENT_VERSION/g" appspec.yml - sed -i "s//$NEW_VERSION/g" appspec.yml - - APPSPEC_CONTENT=$(python3 -c 'import json; print(json.dumps(open("appspec.yml").read()))') - - aws deploy create-deployment --application-name project-d-deploy --deployment-group-name project-d-deployment-group --revision "revisionType=AppSpecContent,appSpecContent={content=$APPSPEC_CONTENT}" + - | + python3 -c " + import json, subprocess + with open('appspec.yml') as f: + content = f.read() + revision = { + 'revisionType': 'AppSpecContent', + 'appSpecContent': {'content': content} + } + cmd = ['aws', 'deploy', 'create-deployment', + '--application-name', 'project-d-deploy', + '--deployment-group-name', 'project-d-deployment-group', + '--revision', json.dumps(revision)] + result = subprocess.run(cmd, capture_output=True, text=True) + print(result.stdout) + print(result.stderr) + exit(result.returncode) + " artifacts: files: From cc74590de091b90843e25e1b9119b6ea68c855c0 Mon Sep 17 00:00:00 2001 From: RG756 Date: Wed, 16 Sep 2026 20:41:27 +0900 Subject: [PATCH 9/9] Add CodeBuild trigger to GitHub Actions CI pipeline --- .github/workflows/ci.yml | 25 ++++++++++++++++++++++++- 1 file changed, 24 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5521923..8264fd6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -26,4 +26,27 @@ jobs: - name: Run unit tests run: | - pytest project-d-serverless-api/tests/ -v \ No newline at end of file + pytest project-d-serverless-api/tests/ -v + + deploy: + name: Trigger CodeBuild + runs-on: ubuntu-latest + needs: test + if: github.ref == 'refs/heads/main' && github.event_name == 'push' + + steps: + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@v4 + with: + aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} + aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} + aws-region: ap-northeast-1 + + - name: Trigger CodeBuild + run: | + BUILD_ID=$(aws codebuild start-build \ + --project-name project-d-build \ + --source-version main \ + --query 'build.id' \ + --output text) + echo "Started CodeBuild: $BUILD_ID" \ No newline at end of file