-
-
Notifications
You must be signed in to change notification settings - Fork 0
131 lines (121 loc) · 4.48 KB
/
Copy pathdocker.yml
File metadata and controls
131 lines (121 loc) · 4.48 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
name: Docker image
# main is production: every push to main builds the image, then updates the
# server — a release published from develop as well as a data commit from the
# sync. The image is pushed nowhere: the server rebuilds its own, and this build
# only checks that it builds.
#
# On a pull request touching the image (Dockerfile, dependencies, Next config),
# build only: the regression is caught before merging.
#
# Also called by the sync when it pushed with GITHUB_TOKEN, for lack of a
# deploy key: such a push triggers no workflow.
on:
push:
branches: [main]
pull_request:
paths:
- Dockerfile
- docker-compose.yml
- package.json
- package-lock.json
- next.config.ts
workflow_call:
inputs:
ref:
description: Commit to build (defaults to the triggering one)
type: string
default: ""
deploy:
description: Deploy to the server once the image is built
type: boolean
default: false
secrets:
DEPLOY_SSH_KEY:
required: false
DEPLOY_KNOWN_HOSTS:
required: false
workflow_dispatch:
inputs:
deploy:
description: Deploy to the server once the image is built
type: boolean
default: true
permissions:
contents: read
jobs:
build:
name: Build the image
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.ref }}
persist-credentials: false
- uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Build
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
push: false
tags: mlbb:ci
cache-from: type=gha
cache-to: type=gha,mode=max
# The server follows the documented deployment: it pulls main and rebuilds
# its container. Inactive until the repository settings are filled in (see
# docs/wiki/Data-and-sync.md).
deploy:
name: Deploy to the server
needs: build
if: (inputs.deploy || (github.event_name == 'push' && github.ref == 'refs/heads/main')) && vars.DEPLOY_HOST != ''
runs-on: ubuntu-latest
timeout-minutes: 30
concurrency:
group: deploy
cancel-in-progress: false
steps:
- name: Update the server and rebuild the container
env:
SSH_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
KNOWN_HOSTS: ${{ secrets.DEPLOY_KNOWN_HOSTS }}
SSH_HOST: ${{ vars.DEPLOY_HOST }}
SSH_USER: ${{ vars.DEPLOY_USER }}
APP_DIR: ${{ vars.DEPLOY_PATH }}
SSH_PORT: ${{ vars.DEPLOY_PORT || '22' }}
run: |
install -d -m 700 ~/.ssh
printf '%s\n' "$SSH_KEY" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
# Without a known fingerprint, do not connect: accepting the one the
# server presents would expose the deployment to interception.
if [ -z "$KNOWN_HOSTS" ]; then
echo "::error::DEPLOY_KNOWN_HOSTS missing (output of ssh-keyscan -p <port> <host>, checked by hand)"
exit 1
fi
printf '%s\n' "$KNOWN_HOSTS" > ~/.ssh/known_hosts
ssh -i ~/.ssh/deploy_key -p "$SSH_PORT" "$SSH_USER@$SSH_HOST" \
"cd '$APP_DIR' && git pull --ff-only origin main && docker compose up -d --build"
# A green deploy must mean a working site, not only a container that
# started: check what production serves once it answers again.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.ref }}
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
- name: Wait for the site to answer
env:
SITE_URL: ${{ vars.SITE_URL || 'https://mlbbdex.com' }}
run: |
deadline=$((SECONDS + 300))
until [ "$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "$SITE_URL/api/health")" = "200" ]; do
if [ "$SECONDS" -ge "$deadline" ]; then
echo "::error::$SITE_URL/api/health did not answer 200 within 5 minutes of the deployment"
exit 1
fi
sleep 10
done
- name: Smoke check of production
env:
SITE_URL: ${{ vars.SITE_URL || 'https://mlbbdex.com' }}
run: node scripts/smoke-check.mjs "$SITE_URL"