From 14638faefd0f301c389f837f7eaad77982e17648 Mon Sep 17 00:00:00 2001 From: Gerard Louis Recinto Date: Fri, 2 Oct 2026 09:22:48 -0700 Subject: [PATCH] wire the stripe pro price id and publishable key into the azure deploy --- .github/workflows/deploy-azure.yml | 5 ++++- infra/azure/main.bicep | 4 ++++ infra/azure/main.parameters.json | 3 +++ infra/azure/modules/container-app.bicep | 8 ++++++++ 4 files changed, 19 insertions(+), 1 deletion(-) diff --git a/.github/workflows/deploy-azure.yml b/.github/workflows/deploy-azure.yml index 15301896d..e848b2a19 100644 --- a/.github/workflows/deploy-azure.yml +++ b/.github/workflows/deploy-azure.yml @@ -11,7 +11,8 @@ # subscription/resource group. No client secret is stored anywhere - this is # exactly what azure/login's OIDC mode is for. Once created, set these as # repository variables (not secrets, they aren't sensitive on their own): -# AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_SUBSCRIPTION_ID +# AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_SUBSCRIPTION_ID, +# STRIPE_PUBLISHABLE_KEY, STRIPE_PRO_PRICE_ID # And these as repository secrets: # STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, ALERT_EMAIL # @@ -75,6 +76,8 @@ jobs: -p alertEmail="${{ secrets.ALERT_EMAIL }}" \ -p stripeSecretKey="${{ secrets.STRIPE_SECRET_KEY }}" \ -p stripeWebhookSecret="${{ secrets.STRIPE_WEBHOOK_SECRET }}" \ + -p stripePublishableKey="${{ vars.STRIPE_PUBLISHABLE_KEY }}" \ + -p stripeProPriceId="${{ vars.STRIPE_PRO_PRICE_ID }}" \ -o json > deploy-output.json acr_login_server=$(jq -r '.properties.outputs.acrLoginServer.value' deploy-output.json) echo "acrLoginServer=${acr_login_server}" >> "$GITHUB_OUTPUT" diff --git a/infra/azure/main.bicep b/infra/azure/main.bicep index 92d1801e5..afb31c347 100644 --- a/infra/azure/main.bicep +++ b/infra/azure/main.bicep @@ -45,6 +45,9 @@ param stripeWebhookSecret string @description('Stripe publishable key (not secret, but kept alongside the others for consistency).') param stripePublishableKey string = '' +@description('Stripe price ID for the Pro plan (price_...). Not secret. Empty leaves checkout for Pro unconfigured.') +param stripeProPriceId string = '' + var resourceToken = uniqueString(resourceGroup().id, appName) var logAnalyticsName = '${appName}-logs-${resourceToken}' var acrName = replace('${appName}acr${resourceToken}', '-', '') @@ -114,6 +117,7 @@ module containerApp 'modules/container-app.bicep' = { userAssignedIdentityClientId: identity.outputs.clientId keyVaultUri: keyVault.outputs.uri stripeEnabled: !empty(stripeSecretKey) && !empty(stripeWebhookSecret) + stripeProPriceId: stripeProPriceId } } diff --git a/infra/azure/main.parameters.json b/infra/azure/main.parameters.json index 5ca76dbec..e2384da3d 100644 --- a/infra/azure/main.parameters.json +++ b/infra/azure/main.parameters.json @@ -19,6 +19,9 @@ }, "stripePublishableKey": { "value": "" + }, + "stripeProPriceId": { + "value": "" } } } diff --git a/infra/azure/modules/container-app.bicep b/infra/azure/modules/container-app.bicep index 59ea5054f..f01202b79 100644 --- a/infra/azure/modules/container-app.bicep +++ b/infra/azure/modules/container-app.bicep @@ -17,6 +17,9 @@ param keyVaultUri string @description('True when real Stripe secrets were supplied to the deploy. While false the app gets no Key Vault secret references and runs in simulation mode.') param stripeEnabled bool = false +@description('Stripe price ID for the Pro plan. Plain env var, the ID is not a secret. Omitted from the container when empty.') +param stripeProPriceId string = '' + // Pinned to 1 replica: joltrin's embedded B-Tree engine has no documented // multi-process write-safety guarantee, and this deployment optimizes for // lowest cost over horizontal scale. CPU/memory/concurrency limits below @@ -100,6 +103,11 @@ resource containerApp 'Microsoft.App/containerApps@2023-11-02-preview' = { name: 'STRIPE_PUBLISHABLE_KEY' secretRef: 'stripe-publishable-key' } + ] : [], !empty(stripeProPriceId) ? [ + { + name: 'STRIPE_PRO_PRICE_ID' + value: stripeProPriceId + } ] : [], [ { name: 'AZURE_CLIENT_ID'