Fix CI/CD best practice violations
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Failing after 1s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Has been skipped
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped

- Use SHA-based image tags instead of 'latest' for deployments
- Pass exact image tag from build job to deploy job
- Add default for SSH_PORT
- Health check now fails deploy if not passing
- Added script_stop for proper error handling
This commit is contained in:
2026-01-22 15:27:21 -07:00
parent 0c387b1bcc
commit d3733dbebe

View File

@ -60,12 +60,20 @@ jobs:
if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request'
outputs:
image_tag: ${{ steps.meta.outputs.tags }}
image_tag: ${{ steps.set-tag.outputs.tag }}
full_image: ${{ steps.set-tag.outputs.full_image }}
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set image tag
id: set-tag
run: |
SHORT_SHA=$(echo "${{ github.sha }}" | cut -c1-7)
echo "tag=${SHORT_SHA}" >> $GITHUB_OUTPUT
echo "full_image=${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${SHORT_SHA}" >> $GITHUB_OUTPUT
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
@ -76,21 +84,14 @@ jobs:
username: ${{ secrets.HARBOR_USERNAME }}
password: ${{ secrets.HARBOR_PASSWORD }}
- name: Extract metadata for Docker
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}
tags: |
type=sha,prefix=
type=raw,value=latest
- name: Build and push Docker image
uses: docker/build-push-action@v5
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
tags: |
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${{ steps.set-tag.outputs.tag }}
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:latest
cache-from: type=gha
cache-to: type=gha,mode=max
@ -106,29 +107,31 @@ jobs:
steps:
- name: Deploy via SSH
uses: appleboy/ssh-action@v1.0.3
env:
HARBOR_REGISTRY: ${{ secrets.HARBOR_REGISTRY }}
HARBOR_PROJECT: ${{ secrets.HARBOR_PROJECT }}
with:
host: ${{ secrets.SSH_HOST }}
username: ${{ secrets.SSH_USER }}
key: ${{ secrets.SSH_PRIVATE_KEY }}
port: ${{ secrets.SSH_PORT }}
envs: HARBOR_REGISTRY,HARBOR_PROJECT
port: ${{ secrets.SSH_PORT || 22 }}
envs: IMAGE
script_stop: true
script: |
set -e
# Image to deploy (using specific SHA tag, not latest)
IMAGE="${{ needs.build.outputs.full_image }}"
echo "Deploying image: $IMAGE"
# Navigate to deployment directory
cd ${{ secrets.DEPLOY_PATH }}
# Log in to Harbor
# Log in to Harbor (credentials are masked by Gitea Actions)
echo "${{ secrets.HARBOR_PASSWORD }}" | docker login ${{ secrets.HARBOR_REGISTRY }} -u ${{ secrets.HARBOR_USERNAME }} --password-stdin
# Set image to pull from Harbor and pull it
export IMAGE="${HARBOR_REGISTRY}/${HARBOR_PROJECT}/apartment-api:latest"
docker compose pull
# Pull the specific image
docker pull "$IMAGE"
# Restart with new image
# Update and restart with new image
export IMAGE
docker compose up -d
# Clean up old images
@ -153,9 +156,9 @@ jobs:
host: ${{ secrets.SSH_HOST }}
username: ${{ secrets.SSH_USER }}
key: ${{ secrets.SSH_PRIVATE_KEY }}
port: ${{ secrets.SSH_PORT }}
port: ${{ secrets.SSH_PORT || 22 }}
script: |
# Test health endpoint via Traefik
# Test health endpoint
HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" https://apartments.maverickapplications.com/api/health || echo "000")
if [ "$HTTP_CODE" = "200" ]; then
@ -163,4 +166,5 @@ jobs:
else
echo "WARNING: Health check returned HTTP $HTTP_CODE"
echo "Container may still be initializing..."
exit 1
fi