Fix CI/CD best practice violations
- Use SHA-based image tags instead of 'latest' for deployments - Pass exact image tag from build job to deploy job - Add default for SSH_PORT - Health check now fails deploy if not passing - Added script_stop for proper error handling
This commit is contained in:
50
.github/workflows/deploy.yml
vendored
50
.github/workflows/deploy.yml
vendored
@ -60,12 +60,20 @@ jobs:
|
|||||||
if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request'
|
if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request'
|
||||||
|
|
||||||
outputs:
|
outputs:
|
||||||
image_tag: ${{ steps.meta.outputs.tags }}
|
image_tag: ${{ steps.set-tag.outputs.tag }}
|
||||||
|
full_image: ${{ steps.set-tag.outputs.full_image }}
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Set image tag
|
||||||
|
id: set-tag
|
||||||
|
run: |
|
||||||
|
SHORT_SHA=$(echo "${{ github.sha }}" | cut -c1-7)
|
||||||
|
echo "tag=${SHORT_SHA}" >> $GITHUB_OUTPUT
|
||||||
|
echo "full_image=${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${SHORT_SHA}" >> $GITHUB_OUTPUT
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
@ -76,21 +84,14 @@ jobs:
|
|||||||
username: ${{ secrets.HARBOR_USERNAME }}
|
username: ${{ secrets.HARBOR_USERNAME }}
|
||||||
password: ${{ secrets.HARBOR_PASSWORD }}
|
password: ${{ secrets.HARBOR_PASSWORD }}
|
||||||
|
|
||||||
- name: Extract metadata for Docker
|
|
||||||
id: meta
|
|
||||||
uses: docker/metadata-action@v5
|
|
||||||
with:
|
|
||||||
images: ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}
|
|
||||||
tags: |
|
|
||||||
type=sha,prefix=
|
|
||||||
type=raw,value=latest
|
|
||||||
|
|
||||||
- name: Build and push Docker image
|
- name: Build and push Docker image
|
||||||
uses: docker/build-push-action@v5
|
uses: docker/build-push-action@v5
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
push: true
|
push: true
|
||||||
tags: ${{ steps.meta.outputs.tags }}
|
tags: |
|
||||||
|
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${{ steps.set-tag.outputs.tag }}
|
||||||
|
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:latest
|
||||||
cache-from: type=gha
|
cache-from: type=gha
|
||||||
cache-to: type=gha,mode=max
|
cache-to: type=gha,mode=max
|
||||||
|
|
||||||
@ -106,29 +107,31 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Deploy via SSH
|
- name: Deploy via SSH
|
||||||
uses: appleboy/ssh-action@v1.0.3
|
uses: appleboy/ssh-action@v1.0.3
|
||||||
env:
|
|
||||||
HARBOR_REGISTRY: ${{ secrets.HARBOR_REGISTRY }}
|
|
||||||
HARBOR_PROJECT: ${{ secrets.HARBOR_PROJECT }}
|
|
||||||
with:
|
with:
|
||||||
host: ${{ secrets.SSH_HOST }}
|
host: ${{ secrets.SSH_HOST }}
|
||||||
username: ${{ secrets.SSH_USER }}
|
username: ${{ secrets.SSH_USER }}
|
||||||
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||||
port: ${{ secrets.SSH_PORT }}
|
port: ${{ secrets.SSH_PORT || 22 }}
|
||||||
envs: HARBOR_REGISTRY,HARBOR_PROJECT
|
envs: IMAGE
|
||||||
|
script_stop: true
|
||||||
script: |
|
script: |
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
|
# Image to deploy (using specific SHA tag, not latest)
|
||||||
|
IMAGE="${{ needs.build.outputs.full_image }}"
|
||||||
|
echo "Deploying image: $IMAGE"
|
||||||
|
|
||||||
# Navigate to deployment directory
|
# Navigate to deployment directory
|
||||||
cd ${{ secrets.DEPLOY_PATH }}
|
cd ${{ secrets.DEPLOY_PATH }}
|
||||||
|
|
||||||
# Log in to Harbor
|
# Log in to Harbor (credentials are masked by Gitea Actions)
|
||||||
echo "${{ secrets.HARBOR_PASSWORD }}" | docker login ${{ secrets.HARBOR_REGISTRY }} -u ${{ secrets.HARBOR_USERNAME }} --password-stdin
|
echo "${{ secrets.HARBOR_PASSWORD }}" | docker login ${{ secrets.HARBOR_REGISTRY }} -u ${{ secrets.HARBOR_USERNAME }} --password-stdin
|
||||||
|
|
||||||
# Set image to pull from Harbor and pull it
|
# Pull the specific image
|
||||||
export IMAGE="${HARBOR_REGISTRY}/${HARBOR_PROJECT}/apartment-api:latest"
|
docker pull "$IMAGE"
|
||||||
docker compose pull
|
|
||||||
|
|
||||||
# Restart with new image
|
# Update and restart with new image
|
||||||
|
export IMAGE
|
||||||
docker compose up -d
|
docker compose up -d
|
||||||
|
|
||||||
# Clean up old images
|
# Clean up old images
|
||||||
@ -153,9 +156,9 @@ jobs:
|
|||||||
host: ${{ secrets.SSH_HOST }}
|
host: ${{ secrets.SSH_HOST }}
|
||||||
username: ${{ secrets.SSH_USER }}
|
username: ${{ secrets.SSH_USER }}
|
||||||
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||||
port: ${{ secrets.SSH_PORT }}
|
port: ${{ secrets.SSH_PORT || 22 }}
|
||||||
script: |
|
script: |
|
||||||
# Test health endpoint via Traefik
|
# Test health endpoint
|
||||||
HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" https://apartments.maverickapplications.com/api/health || echo "000")
|
HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" https://apartments.maverickapplications.com/api/health || echo "000")
|
||||||
|
|
||||||
if [ "$HTTP_CODE" = "200" ]; then
|
if [ "$HTTP_CODE" = "200" ]; then
|
||||||
@ -163,4 +166,5 @@ jobs:
|
|||||||
else
|
else
|
||||||
echo "WARNING: Health check returned HTTP $HTTP_CODE"
|
echo "WARNING: Health check returned HTTP $HTTP_CODE"
|
||||||
echo "Container may still be initializing..."
|
echo "Container may still be initializing..."
|
||||||
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|||||||
Reference in New Issue
Block a user