Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .github/workflows/deploy-azure.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,8 @@
# subscription/resource group. No client secret is stored anywhere - this is
# exactly what azure/login's OIDC mode is for. Once created, set these as
# repository variables (not secrets, they aren't sensitive on their own):
# AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_SUBSCRIPTION_ID
# AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_SUBSCRIPTION_ID,
# STRIPE_PUBLISHABLE_KEY, STRIPE_PRO_PRICE_ID
# And these as repository secrets:
# STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, ALERT_EMAIL
#
Expand Down Expand Up @@ -75,6 +76,8 @@ jobs:
-p alertEmail="${{ secrets.ALERT_EMAIL }}" \
-p stripeSecretKey="${{ secrets.STRIPE_SECRET_KEY }}" \
-p stripeWebhookSecret="${{ secrets.STRIPE_WEBHOOK_SECRET }}" \
-p stripePublishableKey="${{ vars.STRIPE_PUBLISHABLE_KEY }}" \
-p stripeProPriceId="${{ vars.STRIPE_PRO_PRICE_ID }}" \
-o json > deploy-output.json
acr_login_server=$(jq -r '.properties.outputs.acrLoginServer.value' deploy-output.json)
echo "acrLoginServer=${acr_login_server}" >> "$GITHUB_OUTPUT"
Expand Down
4 changes: 4 additions & 0 deletions infra/azure/main.bicep
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,9 @@ param stripeWebhookSecret string
@description('Stripe publishable key (not secret, but kept alongside the others for consistency).')
param stripePublishableKey string = ''

@description('Stripe price ID for the Pro plan (price_...). Not secret. Empty leaves checkout for Pro unconfigured.')
param stripeProPriceId string = ''

var resourceToken = uniqueString(resourceGroup().id, appName)
var logAnalyticsName = '${appName}-logs-${resourceToken}'
var acrName = replace('${appName}acr${resourceToken}', '-', '')
Expand Down Expand Up @@ -114,6 +117,7 @@ module containerApp 'modules/container-app.bicep' = {
userAssignedIdentityClientId: identity.outputs.clientId
keyVaultUri: keyVault.outputs.uri
stripeEnabled: !empty(stripeSecretKey) && !empty(stripeWebhookSecret)
stripeProPriceId: stripeProPriceId
}
}

Expand Down
3 changes: 3 additions & 0 deletions infra/azure/main.parameters.json
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@
},
"stripePublishableKey": {
"value": ""
},
"stripeProPriceId": {
"value": ""
}
}
}
8 changes: 8 additions & 0 deletions infra/azure/modules/container-app.bicep
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@ param keyVaultUri string
@description('True when real Stripe secrets were supplied to the deploy. While false the app gets no Key Vault secret references and runs in simulation mode.')
param stripeEnabled bool = false

@description('Stripe price ID for the Pro plan. Plain env var, the ID is not a secret. Omitted from the container when empty.')
param stripeProPriceId string = ''

// Pinned to 1 replica: joltrin's embedded B-Tree engine has no documented
// multi-process write-safety guarantee, and this deployment optimizes for
// lowest cost over horizontal scale. CPU/memory/concurrency limits below
Expand Down Expand Up @@ -100,6 +103,11 @@ resource containerApp 'Microsoft.App/containerApps@2023-11-02-preview' = {
name: 'STRIPE_PUBLISHABLE_KEY'
secretRef: 'stripe-publishable-key'
}
] : [], !empty(stripeProPriceId) ? [
{
name: 'STRIPE_PRO_PRICE_ID'
value: stripeProPriceId
}
] : [], [
{
name: 'AZURE_CLIENT_ID'
Expand Down
Loading