# Set up CI/CD for `prod`

Extend an existing dev-only CI/CD workflow so your application also deploys to production, with manual approval.

## Before you begin

You have completed [Set up CI/CD for `dev`](set-up-cicd-for-dev.md), which sets up an app repository and a CI/CD workflow for your `dev` environment.

## Step 1: Replace `.gp.cicd.json` with the full template

[Set up CI/CD for `dev`](set-up-cicd-for-dev.md) installed the dev-only `.gp.cicd.json` template.
Replace it with the full template, which adds the production section:

```bash title="hello-world/"
gh api repos/oslokommune/golden-path-templates/contents/templates/gh-cicd-app/.gp.cicd.json \
  --jq '.content' | base64 -d > .gp.cicd.json
```

Re-apply the `dev` values you set during app repository setup, and fill in the production values. You can find them in
`common-config.yml` in your IaC repository's `prod` environment directory.

| Field                     | Description                                              | Example        |
| ------------------------- | -------------------------------------------------------- | -------------- |
| `<team-name>`             | Your team name                                           | `pirates`      |
| `<repo-iac>`              | Infrastructure-as-code repository name                   | `pirates-iac`  |
| `<dev-aws-account-id>`    | AWS account ID for `dev`                                 | `123456789012` |
| `<dev-environment-name>`  | Name of your `dev` AWS environment                       | `pirates-dev`  |
| `<prod-aws-account-id>`   | AWS account ID for `prod`                                | `987654321098` |
| `<prod-environment-name>` | Name of your `prod` AWS environment                      | `pirates-prod` |
| `<dev-iac-directory>`     | The directory containing IaC for your `dev` environment  | `stacks/dev`   |
| `<prod-iac-directory>`    | The directory containing IaC for your `prod` environment | `stacks/prod`  |
| `<aws-region>`            | Your AWS region                                          | `eu-west-1`    |

## Step 2: Protect GitHub Actions environment targeting production

This enables manual approval for deployments to production, and ensures that deployments to production only can be made from the default branch. This should **only** be set up for production, not for other environments.

<!-- prettier-ignore-start -->
!!! info "Manual approval"
    You can turn off manual approval of production deployments if you want to, but we **strongly recommend** that you
    enable it during initial setup to reduce the risk of negatively affecting your production environment.
<!-- prettier-ignore-end -->

<!-- Python-Markdown needs 4-space indentation to nest a list inside a list item. -->
<!-- prettier-ignore -->
1. Go to **Settings > Environments > New environment**
1. Set the name to match the name of your production environment:
    - For an application repository: `<environment>` (for example, `pirates-prod`)
    - For an application monorepo: `<environment>-<app-name>` (for example, `pirates-prod-swordsmith`)
1. Set **Required reviewers** to your GitHub team
1. Click **Save protection rules**
1. Under **Deployment branches and tags**, select **Selected branches** and add your default branch (`main` or `master`)

## Step 3: Enable production deployment in the workflow

<!-- "Uncomment" is the standard term for removing the comment markers that disabled the job. -->
<!-- vale Vale.Spelling = NO -->

Uncomment the production deployment job that you commented out in
[Step 3.2 of Set up CI/CD for `dev`](set-up-cicd-for-dev.md#step-32-disable-production-deployment).

<!-- vale Vale.Spelling = YES -->

## Step 4: Create a pull request

Push the branch and create a pull request.

Verify that the build job succeeds and that no deployment occurs.

## Step 5: Merge and deploy

Merge the pull request.

## Verify

Commit a change to your application and verify that the pipeline:

- deploys to `dev` first, then production
- asks for your confirmation before deploying to production (if you enabled environment protection).
