Shared GitHub Actions and reusable workflows for the Understory organization.
This repository provides centralized, reusable CI/CD components that can be called from any repository in the Understory organization. It helps maintain consistency and reduces duplication across projects.
jobs:
build-and-deploy:
uses: understory-io/workflows/.github/workflows/lambda-ecr.yml@main
with:
ecr_repository_name: my-service
image_tag_prefix: prod-
artifacts_name: build-artifacts
secrets:
aws_access_key_id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws_secret_access_key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws_region: ${{ secrets.AWS_REGION }}steps:
- uses: understory-io/workflows/.github/actions/docker-build@main
with:
image_tag_prefix: dev-
app_path: ./src
ecr_repository_name: my-app
# ... AWS credentials| Action | Purpose | Key Features |
|---|---|---|
docker-build |
Build and push Docker images to ECR | Multi-platform support, automatic tagging |
lambda-deploy |
Deploy Docker images to Lambda | Environment-aware, automatic role assumption |
lambda-ecr- Build and push Lambda Docker imageslambda-netcore-ecr- Build and push .NET Core Lambda imagesglue- Deploy AWS Glue services
ci-go-library- CI pipeline for Go librariesci-go-library-mise- CI pipeline for Go libraries (Mise-based)ci-go-mise-lambda- Build/test/package for mise-based Go Lambda servicesbuild-netcore-library- Build .NET Core librariesbuild-deploy-netcore-library- Build and deploy .NET libraries
terraform- Plan on PRs with the result commented back, apply on push. Withsemgrep: trueit also lints the PR diff against the shared rules insemgrep/terraform.ymlplus the calling repo's.semgrep.yml, if any.
semgrep/terraform.yml holds Terraform lint rules every infrastructure repo gets through the terraform workflow. Fixtures sit beside it in semgrep/terraform.tf; add a # ruleid: and an # ok: case for every rule and run:
semgrep --test semgrep/To run the shared rules from a laptop, in any Terraform repo:
semgrep scan --config https://raw.githubusercontent.com/understory-io/workflows/main/semgrep/terraform.ymlCI fetches the rules at the exact commit of the workflow the caller resolved, and scans only what the PR changed (--baseline-commit), so existing findings do not fail a PR that did not touch them. Leave out --baseline-commit, as above, to see the whole backlog.
poeditor-check- Validate translationscrowdin-pull-translations- Pull Crowdin translations and open a PR
create-deployment-prs- Auto-update release PRspublish-releases- Publish releasesrelease-drafter-go- Draft Go releases
repo-data- Extract repository metadatapixel-collector- Collect component/package usage metrics
prod-→ Production environmentdev-→ Development environment
- Production: 189949407637
- Development: 115578597962
Most workflows require these organization secrets:
AWS_ACCESS_KEY_ID- AWS access keyAWS_SECRET_ACCESS_KEY- AWS secret keyAWS_REGION- AWS region (e.g., us-east-1)
Additional secrets for specific workflows:
GO_PRIVATE_MODULES_PAT- GitHub PAT for private Go modulesTF_API_TOKEN- Terraform Cloud token
- Create a feature branch
- Make your changes
- Test thoroughly (changes affect many repos!)
- Update documentation
- Submit a PR