@@ -3,6 +3,7 @@ name: Deploy-Test-Cleanup Pipeline
33permissions :
44 contents : read
55 actions : read
6+ id-token : write
67on :
78 workflow_run :
89 workflows : ["Build Docker and Optional Push"]
2324jobs :
2425 deploy :
2526 runs-on : ubuntu-latest
27+ environment : production
2628 outputs :
2729 RESOURCE_GROUP_NAME : ${{ steps.check_create_rg.outputs.RESOURCE_GROUP_NAME }}
2830 WEBAPP_URL : ${{ steps.get_output.outputs.WEBAPP_URL }}
@@ -31,15 +33,15 @@ jobs:
3133 uses : actions/checkout@v6
3234
3335 - name : Login to Azure
34- run : |
35- az login --service-principal -u ${{ secrets.AZURE_CLIENT_ID }} -p ${{ secrets.AZURE_CLIENT_SECRET }} --tenant ${{ secrets.AZURE_TENANT_ID }}
36+ uses : azure/login@v2
37+ with :
38+ client-id : ${{ secrets.AZURE_CLIENT_ID }}
39+ tenant-id : ${{ secrets.AZURE_TENANT_ID }}
40+ subscription-id : ${{ secrets.AZURE_SUBSCRIPTION_ID }}
3641
3742 - name : Run Quota Check
3843 id : quota-check
3944 env :
40- AZURE_CLIENT_ID : ${{ secrets.AZURE_CLIENT_ID }}
41- AZURE_TENANT_ID : ${{ secrets.AZURE_TENANT_ID }}
42- AZURE_CLIENT_SECRET : ${{ secrets.AZURE_CLIENT_SECRET }}
4345 AZURE_SUBSCRIPTION_ID : ${{ secrets.AZURE_SUBSCRIPTION_ID }}
4446 AZURE_REGIONS : ${{ vars.AZURE_REGIONS }}
4547 GPT_MIN_CAPACITY : ${{ env.GPT_MIN_CAPACITY }}
@@ -182,14 +184,17 @@ jobs:
182184 if : always() && needs.deploy.outputs.RESOURCE_GROUP_NAME != ''
183185 needs : [deploy, e2e-test]
184186 runs-on : ubuntu-latest
187+ environment : production
185188 env :
186189 RESOURCE_GROUP_NAME : ${{ needs.deploy.outputs.RESOURCE_GROUP_NAME }}
187190 steps :
188191
189192 - name : Login to Azure
190- run : |
191- az login --service-principal -u ${{ secrets.AZURE_CLIENT_ID }} -p ${{ secrets.AZURE_CLIENT_SECRET }} --tenant ${{ secrets.AZURE_TENANT_ID }}
192- az account set --subscription "${{ secrets.AZURE_SUBSCRIPTION_ID }}"
193+ uses : azure/login@v2
194+ with :
195+ client-id : ${{ secrets.AZURE_CLIENT_ID }}
196+ tenant-id : ${{ secrets.AZURE_TENANT_ID }}
197+ subscription-id : ${{ secrets.AZURE_SUBSCRIPTION_ID }}
193198
194199 - name : Assign Contributor role to Service Principal
195200 if : always()
0 commit comments