@genexus/d2c
v0.2.26
Published
Deploy to Cloud for GeneXus Frontend generators (ex: Angular)
Keywords
Readme
deploy-to-cloud-frontend
Deploy to Cloud for GeneXus Frontend generators (ex: Angular)
This library provides CLIs in order to:
- Request Deployment Authorization to GX D2C Cloud
- Requst Cloud Provider Credentials to be able to make the Upload
- Confirm a successful deployment to D2C
Release & publish process
Publishing a new version to npm is fully automated through a single GitHub Actions workflow (.github/workflows/publish.yml, named Publish Package To NPM in the Actions tab) — there is no manual npm publish step. Only repo admins or maintainers may run it — anyone else's dispatch fails immediately, since it pushes straight to main using an App token that bypasses the branch's PR/review rules.
To ship a new version: go to Actions → Publish Package To NPM → Run workflow and choose the bump type (patch, minor or major). It runs four jobs in sequence:
- authorize - fails the run immediately unless the triggering actor has admin or maintain permission on the repo.
- check_changes - checks whether
mainhas any commits since the lastv*tag. If not, the run stops here — nothing is bumped or published, so re-running the workflow with no new changes can't produce empty releases likev2.0.1,v2.0.2, etc. - create_release - validates dependency licenses against the allow-list, blocks on high/critical production dependency vulnerabilities (
npm audit), then checks the repository for open critical/high GitHub code scanning alerts (Dependabot alerts aren't checked here — the Dependabot Alerts API requires a permissionGITHUB_TOKENcan never be granted). If any are found, the run fails and no version is bumped — unless thebypass_security_gateinput is set totrue, which is only permitted for repository admins (checked against whoever triggered that specific run, not the original dispatcher, so re-running someone else's dispatch can't be used to bypass this) and never bypasses the license/vulnerability checks. On success it runsnpm version <bump>, which commits and tags the new version, then pushes both the commit and thev<version>tag atomically straight tomainusing a GitHub App installation token, scoped to this repo, that's a bypass actor on the org's PR/signature rulesets (its pushed commits come back GitHub-verified). - publish (skipped entirely when
dry_runistrue) - checks out the new tag, re-checks the critical/high code scanning gate as a non-blocking report, builds the package (npm run build), generates an SPDX SBOM, and publishes it to npmjs.org. If it fails, retry it from the Actions tab with Re-run failed jobs — that only re-runs this job, without bumping the version again.
Set the dry_run input to true to run every check and the version bump locally without pushing anything or running the publish job — useful to validate a release is safe to cut without actually shipping it. This workflow can also be dispatched from any branch (e.g. to try out a change to the workflow file itself), but only a run dispatched from the default branch may actually push a tag or publish — dispatching from any other branch is always treated as a dry run, regardless of the dry_run input.
Note: this repo doesn't run lint/tests as part of create_release yet — package.json has no lint script, and npm test currently fails locally for pre-existing reasons unrelated to releases. See the commented-out steps in the create_release job to re-enable them once fixed.
Usage
Generate Credentials for Static Deployment
d2c-prepareConfirm Deployment with D2C
d2c-confirmConfiguration
#Required
SET D2C_AUTH=%AuthToken%
SET D2C_DEPLOY_ID=<guid>
#Optional (Default Value)
SET D2C_SERVER_TYPE=awss3 (default)
SET D2C_SERVER_ID=sandbox-angular.gxapps.cloud (default)D2C Required Services
1. Service: AuthorizeDeployment
This service is called before deploying to AWS S3, in order to get new Temporal AWS Credentials.
Request
POST Content-Type: Application/json
Body:
{
"authToken": "myAuthToken",
"path": "1234567",
"serverId": "sandbox-angular.gxapps.cloud",
"serverType": "awss3",
"appName": "MyFirstAngularApp"
}Response
Content-Type: Application/json
{
"code": 1,
"credential": {
"sessionToken": "dsfdsfs",
"accessKeyId": "AKIA4EZIEMMO5XXXXXXX",
"secretAccessKey": "xxxxxxx",
"expiration": "2090-07-15T23:28:33.359Z",
"type": "aws"
},
"properties": {
"bucketName": "gx-angular-deployments"
}
}JSON Field Code
ErrorCodes {
ErrorUnknown = 0,
Ok = 1,
ErrorNotAuthorized = 2,
TokenExpired = 3
}Service Responsabilities:
- Validate OAuth Token
- Validate User is authorized to deploy on VDir ("path")
- Validate server name: (sandbox-angular.gxapps.cloud)
- Call AWS STS Service to Request New Temporal Credential.
2. Service: ConfirmDeployment
This service is called after deploying to AWS S3, in order to notify D2C that a successfully deploy has been completed.
Request
POST Content-Type: Application/json
Body:
{
"authToken": "myAuthToken",
"path": "1234567",
"serverId": "sandbox-angular.gxapps.cloud",
"serverType": "awss3",
"appName": "MyFirstAngularApp",
"deployStatus": DeployStatus
""
}Response
Content-Type: Application/json
{
"code":1,
"description":"success"
}JSON Field Code
ErrorCodes {
ErrorUnknown = 0,
Ok = 1,
ErrorNotAuthorized = 2,
TokenExpired = 3
}
DeployStatus {
ErrorUnknown = 0,
Ok = 1,
UploadFailed = 2
}Service Responsabilities:
- Validate OAuth Token
- Validate User is authorized to deploy on VDir ("path")
- Validate server name: (sandbox-angular.gxapps.cloud)
- Update Database with recent deployment
