Update CI/CD to build once and push to Harbor
- Add image variable substitution to docker-compose.yml - Build image in CI, push to Harbor registry - Deploy pulls from Harbor instead of rebuilding - Supports both local dev (build) and prod (pull from registry)
This commit is contained in:
70
.github/workflows/deploy.yml
vendored
70
.github/workflows/deploy.yml
vendored
@ -9,10 +9,11 @@ on:
|
|||||||
|
|
||||||
env:
|
env:
|
||||||
NODE_VERSION: '20'
|
NODE_VERSION: '20'
|
||||||
|
IMAGE_NAME: apartment-api
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# Test Job - Runs first, blocks deployment if tests fail
|
# Test Job - Runs first, blocks everything if tests fail
|
||||||
# ============================================================
|
# ============================================================
|
||||||
test:
|
test:
|
||||||
name: Run Tests
|
name: Run Tests
|
||||||
@ -50,37 +51,84 @@ jobs:
|
|||||||
NODE_ENV: test
|
NODE_ENV: test
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# Deploy Job - Only runs on main branch after tests pass
|
# Build & Push Job - Build image and push to Harbor
|
||||||
# ============================================================
|
# ============================================================
|
||||||
deploy:
|
build:
|
||||||
name: Deploy to Production
|
name: Build & Push Image
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
needs: test
|
needs: test
|
||||||
if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request'
|
if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request'
|
||||||
|
|
||||||
|
outputs:
|
||||||
|
image_tag: ${{ steps.meta.outputs.tags }}
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Set up Docker Buildx
|
||||||
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
|
- name: Log in to Harbor
|
||||||
|
uses: docker/login-action@v3
|
||||||
|
with:
|
||||||
|
registry: ${{ secrets.HARBOR_REGISTRY }}
|
||||||
|
username: ${{ secrets.HARBOR_USERNAME }}
|
||||||
|
password: ${{ secrets.HARBOR_PASSWORD }}
|
||||||
|
|
||||||
|
- name: Extract metadata for Docker
|
||||||
|
id: meta
|
||||||
|
uses: docker/metadata-action@v5
|
||||||
|
with:
|
||||||
|
images: ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}
|
||||||
|
tags: |
|
||||||
|
type=sha,prefix=
|
||||||
|
type=raw,value=latest
|
||||||
|
|
||||||
|
- name: Build and push Docker image
|
||||||
|
uses: docker/build-push-action@v5
|
||||||
|
with:
|
||||||
|
context: .
|
||||||
|
push: true
|
||||||
|
tags: ${{ steps.meta.outputs.tags }}
|
||||||
|
cache-from: type=gha
|
||||||
|
cache-to: type=gha,mode=max
|
||||||
|
|
||||||
|
# ============================================================
|
||||||
|
# Deploy Job - Pull image and restart on production server
|
||||||
|
# ============================================================
|
||||||
|
deploy:
|
||||||
|
name: Deploy to Production
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
needs: build
|
||||||
|
if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request'
|
||||||
|
|
||||||
|
steps:
|
||||||
- name: Deploy via SSH
|
- name: Deploy via SSH
|
||||||
uses: appleboy/ssh-action@v1.0.3
|
uses: appleboy/ssh-action@v1.0.3
|
||||||
|
env:
|
||||||
|
HARBOR_REGISTRY: ${{ secrets.HARBOR_REGISTRY }}
|
||||||
|
HARBOR_PROJECT: ${{ secrets.HARBOR_PROJECT }}
|
||||||
with:
|
with:
|
||||||
host: ${{ secrets.SSH_HOST }}
|
host: ${{ secrets.SSH_HOST }}
|
||||||
username: ${{ secrets.SSH_USER }}
|
username: ${{ secrets.SSH_USER }}
|
||||||
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||||
port: ${{ secrets.SSH_PORT || 22 }}
|
port: ${{ secrets.SSH_PORT }}
|
||||||
|
envs: HARBOR_REGISTRY,HARBOR_PROJECT
|
||||||
script: |
|
script: |
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
# Navigate to deployment directory
|
# Navigate to deployment directory
|
||||||
cd ${{ secrets.DEPLOY_PATH }}
|
cd ${{ secrets.DEPLOY_PATH }}
|
||||||
|
|
||||||
# Pull latest code
|
# Log in to Harbor
|
||||||
git fetch origin main
|
echo "${{ secrets.HARBOR_PASSWORD }}" | docker login ${{ secrets.HARBOR_REGISTRY }} -u ${{ secrets.HARBOR_USERNAME }} --password-stdin
|
||||||
git reset --hard origin/main
|
|
||||||
|
|
||||||
# Rebuild and restart container
|
# Set image to pull from Harbor and pull it
|
||||||
docker compose build --no-cache
|
export IMAGE="${HARBOR_REGISTRY}/${HARBOR_PROJECT}/apartment-api:latest"
|
||||||
|
docker compose pull
|
||||||
|
|
||||||
|
# Restart with new image
|
||||||
docker compose up -d
|
docker compose up -d
|
||||||
|
|
||||||
# Clean up old images
|
# Clean up old images
|
||||||
@ -105,7 +153,7 @@ jobs:
|
|||||||
host: ${{ secrets.SSH_HOST }}
|
host: ${{ secrets.SSH_HOST }}
|
||||||
username: ${{ secrets.SSH_USER }}
|
username: ${{ secrets.SSH_USER }}
|
||||||
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||||
port: ${{ secrets.SSH_PORT || 22 }}
|
port: ${{ secrets.SSH_PORT }}
|
||||||
script: |
|
script: |
|
||||||
# Test health endpoint via Traefik
|
# Test health endpoint via Traefik
|
||||||
HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" https://apartments.maverickapplications.com/api/health || echo "000")
|
HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" https://apartments.maverickapplications.com/api/health || echo "000")
|
||||||
|
|||||||
@ -1,5 +1,6 @@
|
|||||||
services:
|
services:
|
||||||
apartment-api:
|
apartment-api:
|
||||||
|
image: ${IMAGE:-apartment-api:latest}
|
||||||
build: .
|
build: .
|
||||||
container_name: apartment-api
|
container_name: apartment-api
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
|||||||
Reference in New Issue
Block a user