From 01bab5be9ffe492d2d8f3dc9d1a1e95cfbf3db7d Mon Sep 17 00:00:00 2001 From: "@permadeath.com" Date: Thu, 20 Aug 2026 22:55:59 -0400 Subject: [PATCH] fix(forces): fail on a missing AWS session before the download, not after --- scripts/deploy.sh | 18 ++++++++++++++---- 1 file changed, 14 insertions(+), 4 deletions(-) diff --git a/scripts/deploy.sh b/scripts/deploy.sh index bfca7bd..be5ee7c 100755 --- a/scripts/deploy.sh +++ b/scripts/deploy.sh @@ -76,6 +76,20 @@ if [ -z "$version" ] && { [ -z "$megamek" ] || [ -z "$bridge" ]; }; then echo "deploy: which MegaMek? scripts/deploy.sh 0.51.0" >&2 exit 2 fi +# Before anything is fetched, dumped or built. A cold run is a 600MB download, +# two minutes of JVM and two cargo builds, and finding out after all of it that +# the login expired is the whole reason this is up here. A dry run uploads +# nothing, so it needs none of it. +if [ -z "$dry_run" ]; then + : "${AWS_PROFILE:?set AWS_PROFILE; default credentials are almost never the right account}" + + # The variable being set says nothing about the session behind it. + if ! aws sts get-caller-identity --query Account --output text >/dev/null; then + echo "deploy: no working AWS session for profile $AWS_PROFILE; log in again" >&2 + exit 1 + fi +fi + command -v jq >/dev/null || { echo "deploy: jq is not installed; it writes releases.auto.tfvars.json" >&2 exit 1 @@ -175,10 +189,6 @@ if [ -n "$dry_run" ]; then exit 0 fi -aws sts get-caller-identity >/dev/null 2>&1 || { - echo "deploy: no working AWS credentials; sign in and retry" >&2 - exit 1 -} bucket="$(tofu -chdir="$infra/envs/lance.blue" output -raw assets_helm_bucket)" # Immutable because a prefix is written once: the ref names this commit and -- 2.51.2