mirror of
https://github.com/nolen777/eagle0.git
synced 2026-07-28 21:35:42 +00:00
* Next steps for productionization * Run deploy job on self-hosted runner for secure SSH * Temporarily disable production environment to debug runner * Use ubuntu-latest for deploy job * Add remote_tags to oci_push for latest tag
128 lines
4.4 KiB
YAML
128 lines
4.4 KiB
YAML
name: Docker Build and Push
|
|
|
|
on:
|
|
push:
|
|
branches: [ "main" ]
|
|
paths:
|
|
- 'src/main/cpp/**'
|
|
- 'src/main/scala/**'
|
|
- 'src/main/protobuf/**'
|
|
- 'src/main/resources/**'
|
|
- 'ci/BUILD.bazel'
|
|
- 'MODULE.bazel'
|
|
- '.github/workflows/docker_build.yml'
|
|
workflow_dispatch:
|
|
inputs:
|
|
push_images:
|
|
description: 'Push images to container registry'
|
|
required: true
|
|
default: 'false'
|
|
type: boolean
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build-eagle:
|
|
runs-on: self-hosted
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
with:
|
|
lfs: false
|
|
|
|
- name: Build Eagle Docker image
|
|
run: bazel build //ci:eagle_server_image
|
|
|
|
- name: Login to DigitalOcean Container Registry
|
|
if: github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && github.event.inputs.push_images == 'true')
|
|
env:
|
|
DO_TOKEN: ${{ secrets.DO_REGISTRY_TOKEN }}
|
|
run: |
|
|
mkdir -p ~/.docker
|
|
AUTH=$(echo -n "${DO_TOKEN}:${DO_TOKEN}" | base64)
|
|
echo "{\"auths\":{\"registry.digitalocean.com\":{\"auth\":\"${AUTH}\"}}}" > ~/.docker/config.json
|
|
# Also set for current directory in case Bazel uses different home
|
|
mkdir -p .docker
|
|
cp ~/.docker/config.json .docker/
|
|
|
|
- name: Push Eagle image to DO registry
|
|
if: github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && github.event.inputs.push_images == 'true')
|
|
env:
|
|
DOCKER_CONFIG: ${{ github.workspace }}/.docker
|
|
run: bazel run //ci:eagle_server_push
|
|
|
|
build-shardok:
|
|
runs-on: self-hosted
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
with:
|
|
lfs: false
|
|
|
|
- name: Build Shardok Docker image (cross-compile for Linux)
|
|
run: bazel build --platforms=//:linux_x86_64 //ci:shardok_server_image
|
|
|
|
- name: Login to DigitalOcean Container Registry
|
|
if: github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && github.event.inputs.push_images == 'true')
|
|
env:
|
|
DO_TOKEN: ${{ secrets.DO_REGISTRY_TOKEN }}
|
|
run: |
|
|
mkdir -p ~/.docker
|
|
AUTH=$(echo -n "${DO_TOKEN}:${DO_TOKEN}" | base64)
|
|
echo "{\"auths\":{\"registry.digitalocean.com\":{\"auth\":\"${AUTH}\"}}}" > ~/.docker/config.json
|
|
# Also set for current directory in case Bazel uses different home
|
|
mkdir -p .docker
|
|
cp ~/.docker/config.json .docker/
|
|
|
|
- name: Push Shardok image to DO registry
|
|
if: github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && github.event.inputs.push_images == 'true')
|
|
env:
|
|
DOCKER_CONFIG: ${{ github.workspace }}/.docker
|
|
# Note: Don't use --platforms here. The image is already built for Linux,
|
|
# but the push script runs on the host (macOS) and needs native tools.
|
|
run: bazel run //ci:shardok_server_push
|
|
|
|
deploy:
|
|
runs-on: ubuntu-latest
|
|
needs: [build-eagle, build-shardok]
|
|
if: github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && github.event.inputs.push_images == 'true')
|
|
environment: production
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Copy config files to droplet
|
|
uses: appleboy/scp-action@v0.1.7
|
|
with:
|
|
host: ${{ secrets.DO_DROPLET_IP }}
|
|
username: deploy
|
|
key: ${{ secrets.DO_SSH_KEY }}
|
|
source: "docker-compose.prod.yml,nginx/nginx.conf"
|
|
target: "/opt/eagle0"
|
|
|
|
- name: Deploy to production droplet
|
|
uses: appleboy/ssh-action@v1.0.3
|
|
with:
|
|
host: ${{ secrets.DO_DROPLET_IP }}
|
|
username: deploy
|
|
key: ${{ secrets.DO_SSH_KEY }}
|
|
script: |
|
|
cd /opt/eagle0
|
|
|
|
# Login to registry
|
|
echo "${{ secrets.DO_REGISTRY_TOKEN }}" | docker login registry.digitalocean.com -u "${{ secrets.DO_REGISTRY_TOKEN }}" --password-stdin
|
|
|
|
# Pull latest images
|
|
docker compose -f docker-compose.prod.yml pull
|
|
|
|
# Restart services
|
|
docker compose -f docker-compose.prod.yml up -d --remove-orphans
|
|
|
|
# Wait for health checks
|
|
sleep 10
|
|
docker compose -f docker-compose.prod.yml ps
|
|
|
|
# Cleanup old images
|
|
docker image prune -f
|