Diffstat (limited to '.github')
| -rw-r--r-- | .github/workflows/build-and-deploy-prod.yml (renamed from .github/workflows/build-and-deploy.yml) | 44 | ||||
| -rw-r--r-- | .github/workflows/build-and-deploy-stage.yml | 89 |
2 files changed, 117 insertions, 16 deletions
diff --git a/.github/workflows/build-and-deploy.yml b/.github/workflows/build-and-deploy-prod.yml index e014dd0..a180d39 100644 --- a/.github/workflows/build-and-deploy.yml +++ b/.github/workflows/build-and-deploy-prod.yml @@ -1,4 +1,4 @@ -name: Publish Docker image +name: Docker image building and publishing onto Production on: push: tags: @@ -8,6 +8,8 @@ jobs: if: github.repository == 'SayaAndy/saya-today-web' runs-on: ubuntu-latest environment: Production + permissions: + packages: write steps: - name: Checkout uses: actions/checkout@v4 @@ -18,24 +20,25 @@ jobs: output: static/output.css params: "--minify" - name: Set up QEMU - uses: docker/setup-qemu-action@v1 + uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v1 + uses: docker/setup-buildx-action@v3 - name: Login to GitHub Container Registry - uses: docker/login-action@v1 + uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.repository_owner }} password: ${{ secrets.GHCR_TOKEN }} - name: Build and push - uses: docker/build-push-action@v2 + uses: docker/build-push-action@v6 with: context: . file: ./Dockerfile push: true tags: | - ghcr.io/SayaAndy/saya-today-web:latest - ghcr.io/SayaAndy/saya-today-web:${{ github.ref_name }} + ghcr.io/sayaandy/saya-today-web:latest + ghcr.io/sayaandy/saya-today-web:stable + ghcr.io/sayaandy/saya-today-web:${{ github.ref_name }} deploy: if: github.repository == 'SayaAndy/saya-today-web' @@ -45,22 +48,31 @@ jobs: steps: - name: Checkout uses: actions/checkout@v4 - - name: Set up SSH private key + + - name: Set up SSH connection for pl.saya.today + run: | + mkdir -p ~/.ssh + (cat <<EOF + ${{ secrets.SVC_GITHUB_PK }} + EOF + ) > ~/.ssh/id_ed25519 + chmod 600 ~/.ssh/id_ed25519 + sed -i 's/\r$//' ~/.ssh/id_ed25519 + ssh-keyscan -H pl.saya.today >> ~/.ssh/known_hosts + + - name: Test SSH connection run: | - echo "${{ secrets.SVC_GITHUB_PK }}" > deploy/private_key.pem - chmod 600 deploy/private_key.pem + ssh -o ConnectTimeout=10 -i ~/.ssh/id_ed25519 svc_github@pl.saya.today "echo 'SSH connection successful'" + - name: Install Ansible shell: bash run: | sudo apt update sudo apt install -y ansible + - name: Run Ansible playbook env: ANSIBLE_HOST_KEY_CHECKING: False working-directory: ./deploy - run: > - ansible-playbook -i inventory.yml -l stage playbook.yml - --private-key private_key.pem - -e saya_today_web.b2.key_id=${{ secrets.B2_KEY_ID }} - -e saya_today_web.b2.application_key=${{ secrets.B2_APPLICATION_KEY }} - -e saya_today_web.tag=${{ github.ref_name }} + run: | + ansible-playbook -i inventory.yml -l prod playbook.yml --private-key ~/.ssh/id_ed25519 -u svc_github -e saya_today_web_auth_salt=${{ secrets.AUTH_SALT }} -e saya_today_web_b2_key_id=${{ secrets.B2_KEY_ID }} -e saya_today_web_b2_application_key=${{ secrets.B2_APPLICATION_KEY }} -e saya_today_web_environment=prod -e saya_today_web_tag=${{ github.ref_name }} diff --git a/.github/workflows/build-and-deploy-stage.yml b/.github/workflows/build-and-deploy-stage.yml new file mode 100644 index 0000000..0aea0a4 --- /dev/null +++ b/.github/workflows/build-and-deploy-stage.yml @@ -0,0 +1,89 @@ +name: Docker image building and publishing onto Stage +on: + push: + branches: [stage] +jobs: + build-and-push: + if: github.repository == 'SayaAndy/saya-today-web' + runs-on: ubuntu-latest + environment: Stage + permissions: + packages: write + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Generate output.css with tailwindcss + uses: ZoeyVid/tailwindcss-update@main + with: + input: static/input.css + output: static/output.css + params: "--minify" + + - name: Set up QEMU + uses: docker/setup-qemu-action@v3 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Login to GitHub Container Registry + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.repository_owner }} + password: ${{ secrets.GHCR_TOKEN }} + + - name: Set github short sha + id: ghss_vars + run: echo "sha_short=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT + + - name: Build and push + uses: docker/build-push-action@v6 + with: + context: . + file: ./Dockerfile + push: true + tags: | + ghcr.io/sayaandy/saya-today-web:latest + ghcr.io/sayaandy/saya-today-web:commit-${{ steps.ghss_vars.outputs.sha_short }} + + deploy: + if: github.repository == 'SayaAndy/saya-today-web' + runs-on: ubuntu-latest + environment: Stage + needs: [build-and-push] + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Set up SSH connection for pl.saya.today + run: | + mkdir -p ~/.ssh + (cat <<EOF + ${{ secrets.SVC_GITHUB_PK }} + EOF + ) > ~/.ssh/id_ed25519 + chmod 600 ~/.ssh/id_ed25519 + sed -i 's/\r$//' ~/.ssh/id_ed25519 + ssh-keyscan -H pl.saya.today >> ~/.ssh/known_hosts + + - name: Test SSH connection + run: | + ssh -o ConnectTimeout=10 -i ~/.ssh/id_ed25519 svc_github@pl.saya.today "echo 'SSH connection successful'" + + - name: Install Ansible + shell: bash + run: | + sudo apt update + sudo apt install -y ansible + + - name: Set github short sha + id: ghss_vars + run: echo "sha_short=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT + + - name: Run Ansible playbook + env: + ANSIBLE_HOST_KEY_CHECKING: False + working-directory: ./deploy + run: | + ansible-playbook -i inventory.yml -l stage playbook.yml --private-key ~/.ssh/id_ed25519 -u svc_github -e saya_today_web_auth_salt=${{ secrets.AUTH_SALT }} -e saya_today_web_b2_key_id=${{ secrets.B2_KEY_ID }} -e saya_today_web_b2_application_key=${{ secrets.B2_APPLICATION_KEY }} -e saya_today_web_environment=stage -e saya_today_web_tag=commit-${{ steps.ghss_vars.outputs.sha_short }} |