diff --git a/.gitea/workflows/ci-build.yml b/.gitea/workflows/ci-build.yml index 99456a5..f1d4146 100644 --- a/.gitea/workflows/ci-build.yml +++ b/.gitea/workflows/ci-build.yml @@ -6,6 +6,11 @@ on: jobs: build: + outputs: + allow_push: ${{ steps.meta.outputs.allow_push }} + ref_name: ${{ steps.meta.outputs.ref_name }} + event_name: ${{ steps.meta.outputs.event_name }} + sha: ${{ steps.meta.outputs.sha }} runs-on: ubuntu-latest env: DEFAULT_BRANCH: main @@ -23,47 +28,77 @@ jobs: env: DEFAULT_BRANCH: ${{ env.DEFAULT_BRANCH }} run: | - ref_name="${GITHUB_REF_NAME:-${GITHUB_REF##*/}}" - event_name="${GITHUB_EVENT_NAME:-}" - sha="${GITHUB_SHA:-}" + git_ref="${GITEA_REF:-${GITHUB_REF:-}}" + ref_name="${GITEA_REF_NAME:-${GITHUB_REF_NAME:-}}" + if [ -z "$ref_name" ] && [ -n "$git_ref" ]; then + ref_name="${git_ref##*/}" + fi + event_name="${GITEA_EVENT_NAME:-${GITHUB_EVENT_NAME:-}}" + sha="${GITEA_SHA:-${GITHUB_SHA:-}}" + if [ -z "$sha" ]; then + sha="$(git rev-parse HEAD)" + fi - if [ "$ref_name" = "${DEFAULT_BRANCH:-main}" ]; then - echo "on_default=true" >> "$GITHUB_OUTPUT" + if [ "$ref_name" = "${DEFAULT_BRANCH:-main}" ] && [ "$event_name" != "pull_request" ]; then + echo "allow_push=true" >> "$GITHUB_OUTPUT" else - echo "on_default=false" >> "$GITHUB_OUTPUT" + echo "allow_push=false" >> "$GITHUB_OUTPUT" fi echo "ref_name=$ref_name" >> "$GITHUB_OUTPUT" echo "event_name=$event_name" >> "$GITHUB_OUTPUT" echo "sha=$sha" >> "$GITHUB_OUTPUT" + - name: Validate registry configuration + shell: bash + run: | + set -euo pipefail + if [ -z "${REGISTRY_URL}" ]; then + echo "::error::REGISTRY_URL secret not configured. Configure it with your Gitea container registry host." >&2 + exit 1 + fi + server_url="${GITEA_SERVER_URL:-${GITHUB_SERVER_URL:-}}" + server_host="${server_url#http://}" + server_host="${server_host#https://}" + server_host="${server_host%%/*}" + server_host="${server_host%%:*}" + registry_host="${REGISTRY_URL#http://}" + registry_host="${registry_host#https://}" + registry_host="${registry_host%%/*}" + registry_host="${registry_host%%:*}" + if [ -n "${server_host}" ] && ! printf '%s' "${registry_host}" | grep -qi "${server_host}"; then + echo "::warning::REGISTRY_URL (${REGISTRY_URL}) does not match current Gitea host (${server_host}). Ensure this registry endpoint is managed by Gitea." >&2 + fi + registry_repository="${registry_host}/allucanget/${REGISTRY_CONTAINER_NAME}" + echo "REGISTRY_HOST=${registry_host}" >> "$GITHUB_ENV" + echo "REGISTRY_REPOSITORY=${registry_repository}" >> "$GITHUB_ENV" + - name: Set up QEMU and Buildx uses: docker/setup-buildx-action@v3 - name: Log in to gitea registry - if: ${{ steps.meta.outputs.on_default == 'true' }} + if: ${{ steps.meta.outputs.allow_push == 'true' }} uses: docker/login-action@v3 - continue-on-error: true with: - registry: ${{ env.REGISTRY_URL }} + registry: ${{ env.REGISTRY_HOST }} username: ${{ env.REGISTRY_USERNAME }} password: ${{ env.REGISTRY_PASSWORD }} - name: Build image id: build-image env: - REGISTRY_URL: ${{ env.REGISTRY_URL }} + REGISTRY_REPOSITORY: ${{ env.REGISTRY_REPOSITORY }} REGISTRY_CONTAINER_NAME: ${{ env.REGISTRY_CONTAINER_NAME }} SHA_TAG: ${{ steps.meta.outputs.sha }} - PUSH_IMAGE: ${{ steps.meta.outputs.on_default == 'true' && steps.meta.outputs.event_name != 'pull_request' && env.REGISTRY_URL != '' && env.REGISTRY_USERNAME != '' && env.REGISTRY_PASSWORD != '' }} + PUSH_IMAGE: ${{ steps.meta.outputs.allow_push == 'true' && env.REGISTRY_HOST != '' && env.REGISTRY_USERNAME != '' && env.REGISTRY_PASSWORD != '' }} run: | set -eo pipefail LOG_FILE=build.log if [ "${PUSH_IMAGE}" = "true" ]; then docker buildx build \ - --push \ - --tag "${REGISTRY_URL}/allucanget/${REGISTRY_CONTAINER_NAME}:latest" \ - --tag "${REGISTRY_URL}/allucanget/${REGISTRY_CONTAINER_NAME}:${SHA_TAG}" \ + --load \ + --tag "${REGISTRY_REPOSITORY}:latest" \ + --tag "${REGISTRY_REPOSITORY}:${SHA_TAG}" \ --file Dockerfile \ . 2>&1 | tee "${LOG_FILE}" else @@ -74,6 +109,20 @@ jobs: . 2>&1 | tee "${LOG_FILE}" fi + - name: Push image + if: ${{ steps.meta.outputs.allow_push == 'true' }} + env: + REGISTRY_REPOSITORY: ${{ env.REGISTRY_REPOSITORY }} + SHA_TAG: ${{ steps.meta.outputs.sha }} + run: | + set -euo pipefail + if [ -z "${REGISTRY_REPOSITORY}" ]; then + echo "::error::REGISTRY_REPOSITORY not defined; cannot push image" >&2 + exit 1 + fi + docker push "${REGISTRY_REPOSITORY}:${SHA_TAG}" + docker push "${REGISTRY_REPOSITORY}:latest" + - name: Upload docker build logs if: failure() uses: actions/upload-artifact@v4 @@ -83,7 +132,7 @@ jobs: deploy: needs: build - if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request' + if: needs.build.outputs.allow_push == 'true' runs-on: ubuntu-latest env: REGISTRY_URL: ${{ secrets.REGISTRY_URL }} @@ -91,34 +140,67 @@ jobs: KUBE_CONFIG: ${{ secrets.KUBE_CONFIG }} STAGING_KUBE_CONFIG: ${{ secrets.STAGING_KUBE_CONFIG }} PROD_KUBE_CONFIG: ${{ secrets.PROD_KUBE_CONFIG }} + K8S_DEPLOY_ENABLED: ${{ secrets.K8S_DEPLOY_ENABLED }} steps: - name: Checkout uses: actions/checkout@v4 + - name: Resolve registry repository + run: | + set -euo pipefail + if [ -z "${REGISTRY_URL}" ]; then + echo "::error::REGISTRY_URL secret not configured. Configure it with your Gitea container registry host." >&2 + exit 1 + fi + registry_host="${REGISTRY_URL#http://}" + registry_host="${registry_host#https://}" + registry_host="${registry_host%%/*}" + registry_host="${registry_host%%:*}" + registry_repository="${registry_host}/allucanget/${REGISTRY_CONTAINER_NAME}" + echo "REGISTRY_HOST=${registry_host}" >> "$GITHUB_ENV" + echo "REGISTRY_REPOSITORY=${registry_repository}" >> "$GITHUB_ENV" + + - name: Report Kubernetes deployment toggle + run: | + set -euo pipefail + enabled="${K8S_DEPLOY_ENABLED:-}" + if [ "${enabled}" = "true" ]; then + echo "Kubernetes deployment is enabled for this run." + else + echo "::notice::Kubernetes deployment steps are disabled (set secrets.K8S_DEPLOY_ENABLED to 'true' to enable)." + fi + + - name: Capture commit metadata + id: commit_meta + run: | + set -euo pipefail + message="$(git log -1 --pretty=%B | tr '\n' ' ')" + echo "message=$message" >> "$GITHUB_OUTPUT" + - name: Set up kubectl for staging - if: github.event.head_commit && contains(github.event.head_commit.message, '[deploy staging]') + if: env.K8S_DEPLOY_ENABLED == 'true' && contains(steps.commit_meta.outputs.message, '[deploy staging]') uses: azure/k8s-set-context@v3 with: method: kubeconfig kubeconfig: ${{ env.STAGING_KUBE_CONFIG }} - name: Set up kubectl for production - if: github.event.head_commit && contains(github.event.head_commit.message, '[deploy production]') + if: env.K8S_DEPLOY_ENABLED == 'true' && contains(steps.commit_meta.outputs.message, '[deploy production]') uses: azure/k8s-set-context@v3 with: method: kubeconfig kubeconfig: ${{ env.PROD_KUBE_CONFIG }} - name: Deploy to staging - if: github.event.head_commit && contains(github.event.head_commit.message, '[deploy staging]') + if: env.K8S_DEPLOY_ENABLED == 'true' && contains(steps.commit_meta.outputs.message, '[deploy staging]') run: | - kubectl set image deployment/calminer-app calminer=${REGISTRY_URL}/allucanget/${REGISTRY_CONTAINER_NAME}:latest + kubectl set image deployment/calminer-app calminer=${REGISTRY_REPOSITORY}:latest kubectl apply -f k8s/configmap.yaml kubectl apply -f k8s/secret.yaml kubectl rollout status deployment/calminer-app - name: Collect staging deployment logs - if: github.event.head_commit && contains(github.event.head_commit.message, '[deploy staging]') + if: env.K8S_DEPLOY_ENABLED == 'true' && contains(steps.commit_meta.outputs.message, '[deploy staging]') run: | mkdir -p logs/deployment/staging kubectl get pods -o wide > logs/deployment/staging/pods.txt @@ -126,15 +208,15 @@ jobs: kubectl logs deployment/calminer-app --all-containers=true --tail=500 > logs/deployment/staging/calminer-app.log - name: Deploy to production - if: github.event.head_commit && contains(github.event.head_commit.message, '[deploy production]') + if: env.K8S_DEPLOY_ENABLED == 'true' && contains(steps.commit_meta.outputs.message, '[deploy production]') run: | - kubectl set image deployment/calminer-app calminer=${REGISTRY_URL}/allucanget/${REGISTRY_CONTAINER_NAME}:latest + kubectl set image deployment/calminer-app calminer=${REGISTRY_REPOSITORY}:latest kubectl apply -f k8s/configmap.yaml kubectl apply -f k8s/secret.yaml kubectl rollout status deployment/calminer-app - name: Collect production deployment logs - if: github.event.head_commit && contains(github.event.head_commit.message, '[deploy production]') + if: env.K8S_DEPLOY_ENABLED == 'true' && contains(steps.commit_meta.outputs.message, '[deploy production]') run: | mkdir -p logs/deployment/production kubectl get pods -o wide > logs/deployment/production/pods.txt diff --git a/.gitea/workflows/deploy-coolify.yml b/.gitea/workflows/deploy-coolify.yml new file mode 100644 index 0000000..3f02ef0 --- /dev/null +++ b/.gitea/workflows/deploy-coolify.yml @@ -0,0 +1,105 @@ +name: Deploy - Coolify + +on: + push: + branches: + - main + workflow_dispatch: + +jobs: + deploy: + runs-on: ubuntu-latest + env: + COOLIFY_BASE_URL: ${{ secrets.COOLIFY_BASE_URL }} + COOLIFY_API_TOKEN: ${{ secrets.COOLIFY_API_TOKEN }} + COOLIFY_APPLICATION_ID: ${{ secrets.COOLIFY_APPLICATION_ID }} + COOLIFY_DEPLOY_ENV: ${{ secrets.COOLIFY_DEPLOY_ENV }} + DOCKER_COMPOSE_PATH: docker-compose.prod.yml + ENV_FILE_PATH: deploy/.env + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Capture deployment context + id: context + run: | + set -euo pipefail + repo="${GITEA_REPOSITORY:-${GITHUB_REPOSITORY:-}}" + if [ -z "$repo" ]; then + repo="$(git remote get-url origin | sed 's#.*/\(.*\)\.git#\1#')" + fi + ref_name="${GITEA_REF_NAME:-${GITHUB_REF_NAME:-}}" + full_ref="${GITEA_REF:-${GITHUB_REF:-}}" + if [ -z "$ref_name" ] && [ -n "$full_ref" ]; then + ref_name="${full_ref##*/}" + fi + if [ -z "$ref_name" ]; then + ref_name="$(git rev-parse --abbrev-ref HEAD)" + fi + sha="${GITEA_SHA:-${GITHUB_SHA:-}}" + if [ -z "$sha" ]; then + sha="$(git rev-parse HEAD)" + fi + + echo "repository=$repo" >> "$GITHUB_OUTPUT" + echo "ref=${ref_name:-main}" >> "$GITHUB_OUTPUT" + echo "sha=$sha" >> "$GITHUB_OUTPUT" + + - name: Prepare compose bundle + run: | + set -euo pipefail + mkdir -p deploy + cp "$DOCKER_COMPOSE_PATH" deploy/docker-compose.yml + if [ -n "$COOLIFY_DEPLOY_ENV" ]; then + printf '%s\n' "$COOLIFY_DEPLOY_ENV" > "$ENV_FILE_PATH" + elif [ ! -f "$ENV_FILE_PATH" ]; then + echo "::error::COOLIFY_DEPLOY_ENV secret not configured and deploy/.env missing" >&2 + exit 1 + fi + + - name: Validate Coolify secrets + run: | + set -euo pipefail + missing=0 + for var in COOLIFY_BASE_URL COOLIFY_API_TOKEN COOLIFY_APPLICATION_ID; do + if [ -z "${!var}" ]; then + echo "::error::Missing required secret: $var" + missing=1 + fi + done + if [ "$missing" -eq 1 ]; then + exit 1 + fi + + - name: Trigger deployment via Coolify API + env: + HEAD_SHA: ${{ steps.context.outputs.sha }} + run: | + set -euo pipefail + api_url="$COOLIFY_BASE_URL/api/v1/applications/${COOLIFY_APPLICATION_ID}/deploy" + payload=$(jq -n --arg sha "$HEAD_SHA" '{ commitSha: $sha }') + response=$(curl -sS -w '\n%{http_code}' \ + -X POST "$api_url" \ + -H "Authorization: Bearer $COOLIFY_API_TOKEN" \ + -H "Content-Type: application/json" \ + -d "$payload") + body=$(echo "$response" | head -n -1) + status=$(echo "$response" | tail -n1) + echo "Deploy response status: $status" + echo "$body" + printf '%s' "$body" > deploy/coolify-response.json + if [ "$status" -ge 400 ]; then + echo "::error::Deployment request failed" + exit 1 + fi + + - name: Upload deployment bundle + if: always() + uses: actions/upload-artifact@v3 + with: + name: coolify-deploy-bundle + path: | + deploy/docker-compose.yml + deploy/.env + deploy/coolify-response.json + if-no-files-found: warn diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index cd3e264..e7f0f57 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -2,11 +2,7 @@ version: "3.8" services: app: - build: - context: . - dockerfile: Dockerfile - args: - APT_CACHE_URL: ${APT_CACHE_URL:-} + image: git.allucanget.biz/allucanget/calminer:latest environment: - ENVIRONMENT=production - DEBUG=false