diff --git a/.github/workflows/call-docker-build-promote.yaml b/.github/workflows/call-docker-build-promote.yaml index e636f76..ff49e37 100644 --- a/.github/workflows/call-docker-build-promote.yaml +++ b/.github/workflows/call-docker-build-promote.yaml @@ -27,7 +27,7 @@ jobs: contents: read packages: write pull-requests: write - uses: mostlydevops/actions/.github/workflows/reusable-docker-build.yaml@main + uses: UffizziCloud/MostlyDevOps-actions/.github/workflows/reusable-docker-build.yaml@main with: # DON'T login to or push to Docker Hub dockerhub-enable: false @@ -37,21 +37,19 @@ jobs: image-names: | ghcr.io/${{ github.repository }} - scan-pr: - name: CVE Scan + deploy-uffizzi: + name: Deploy to Uffizzi if: github.event_name == 'pull_request' needs: docker-build-pr - permissions: - packages: read - uses: mostlydevops/actions/.github/workflows/reusable-trivy-scan-image.yaml@main + uses: UffizziCloud/MostlyDevOps-actions/.github/workflows/reusable-uffizzi.yaml@oidc secrets: - registry-username: ${{ github.actor }} - registry-password: ${{ secrets.GITHUB_TOKEN }} + github-token: ${{ secrets.GITOPS_WORDSMITH_K8S }} with: - image: 'ghcr.io/mostlydevops/wordsmith-api:${{ needs.docker-build-pr.outputs.image-tag }}' - exit-code: 1 - severity: HIGH,CRITICAL - ignore-unfixed: true + repo: UffizziCloud/MostlyDevOps-wordsmith-k8s + environment-dir: uffizzi + image: ghcr.io/${{ github.repository }} + tag: ${{ needs.docker-build-pr.outputs.image-tag }} + pr-number: ${{ github.event.number }} #### MERGE TO MAIN #### docker-build-merge: @@ -61,7 +59,7 @@ jobs: contents: read packages: write pull-requests: write - uses: mostlydevops/actions/.github/workflows/reusable-docker-build.yaml@main + uses: UffizziCloud/MostlyDevOps-actions/.github/workflows/reusable-docker-build.yaml@main with: dockerhub-enable: false ghcr-enable: true @@ -79,11 +77,27 @@ jobs: name: Call GitOps PR if: github.event_name == 'push' needs: docker-build-merge - uses: mostlydevops/actions/.github/workflows/reusable-gitops-pr.yaml@main + uses: UffizziCloud/MostlyDevOps-actions/.github/workflows/reusable-gitops-pr.yaml@main secrets: github-token: ${{ secrets.GITOPS_WORDSMITH_K8S }} with: - repo: mostlydevops/wordsmith-k8s + repo: UffizziCloud/MostlyDevOps-k8s environment-dir: production image: ghcr.io/${{ github.repository }}-stable tag: ${{ needs.docker-build-merge.outputs.image-tag }} + + scan-pr: + name: CVE Scan + if: github.event_name == 'push' + needs: docker-build-pr + permissions: + packages: read + uses: UffizziCloud/MostlyDevOps-actions/.github/workflows/reusable-trivy-scan-image.yaml@main + secrets: + registry-username: ${{ github.actor }} + registry-password: ${{ secrets.GITHUB_TOKEN }} + with: + image: 'ghcr.io/${{ github.repository }}:${{ needs.docker-build-pr.outputs.image-tag }}' + exit-code: 1 + severity: HIGH,CRITICAL + ignore-unfixed: true diff --git a/.github/workflows/call-uffizzi-delete.yaml b/.github/workflows/call-uffizzi-delete.yaml new file mode 100644 index 0000000..18cd0d5 --- /dev/null +++ b/.github/workflows/call-uffizzi-delete.yaml @@ -0,0 +1,19 @@ +--- +name: Close Pull Request + +on: + pull_request: + types: [closed] + +concurrency: + group: ${{ github.ref }}-${{ github.workflow }} + cancel-in-progress: true + +jobs: + delete-uffizzi: + name: Delete Uffizzi virtual cluster + uses: UffizziCloud/MostlyDevOps-actions/.github/workflows/reusable-uffizzi-delete.yaml@oidc + secrets: + github-token: ${{ secrets.GITOPS_WORDSMITH_K8S }} + with: + pr-number: ${{ github.event.number }}