-
Notifications
You must be signed in to change notification settings - Fork 2
115 lines (99 loc) · 3.5 KB
/
Copy pathdeploy.yml
File metadata and controls
115 lines (99 loc) · 3.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
name: App CI/CD (EC2 Rolling)
on:
push:
branches: [ "main" ]
jobs:
build-and-push:
runs-on: ubuntu-latest
permissions: { contents: read }
env:
IMAGE: ${{ secrets.DOCKERHUB_USERNAME }}/oneteam-mcp
TAG: ${{ github.sha }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-java@v4
with:
java-version: '21'
distribution: 'temurin'
- uses: gradle/actions/setup-gradle@v3
- run: chmod +x gradlew
- run: ./gradlew clean build
- uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_PASSWORD }}
- name: Debug TAG
run: echo "IMAGE=$IMAGE, TAG=$TAG"
- name: Build image
run: docker build -t $IMAGE:latest -t $IMAGE:$TAG .
- name: Push image
run: |
docker push $IMAGE:latest
docker push $IMAGE:$TAG
deploy:
needs: build-and-push
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Prepare remote folder & network
uses: appleboy/ssh-action@v1.0.3
with:
host: ${{ secrets.EC2_HOST }}
username: ${{ secrets.EC2_USER }}
key: ${{ secrets.SSH_KEY }}
script: |
mkdir -p /home/ubuntu/host
docker network create proxy || true
- name: Upload compose
uses: appleboy/scp-action@v0.1.7
with:
host: ${{ secrets.EC2_HOST }}
username: ${{ secrets.EC2_USER }}
key: ${{ secrets.SSH_KEY }}
source: "docker-compose.yml"
target: "/home/ubuntu/host/"
- name: Create .env on EC2
uses: appleboy/ssh-action@v1.0.3
with:
host: ${{ secrets.EC2_HOST }}
username: ${{ secrets.EC2_USER }}
key: ${{ secrets.SSH_KEY }}
script: |
cat > /home/ubuntu/host/.env << 'EOF'
DB_URL=${{ secrets.DB_URL }}
DB_USERNAME=${{ secrets.DB_USERNAME }}
DB_PASSWORD=${{ secrets.DB_PASSWORD }}
JWT_SECRET=${{ secrets.JWT_SECRET }}
ANTHROPIC_API_KEY=${{ secrets.ANTHROPIC_API_KEY }}
OPENAI_API_KEY=${{ secrets.OPENAI_API_KEY }}
BRAVE_API_KEY=${{ secrets.BRAVE_API_KEY }}
SEQUENTIAL_ST_KEY=${{ secrets.SEQUENTIAL_ST_KEY }}
DOCKERHUB_USERNAME=${{ secrets.DOCKERHUB_USERNAME }}
IMAGE_TAG=${{ github.sha }}
EOF
sed -i 's/\r$//' /home/ubuntu/host/.env
- name: Docker login on EC2
uses: appleboy/ssh-action@v1.0.3
with:
host: ${{ secrets.EC2_HOST }}
username: ${{ secrets.EC2_USER }}
key: ${{ secrets.SSH_KEY }}
script: |
echo '${{ secrets.DOCKERHUB_PASSWORD }}' | docker login -u '${{ secrets.DOCKERHUB_USERNAME }}' --password-stdin
- name: Pull & Up
uses: appleboy/ssh-action@v1.0.3
with:
host: ${{ secrets.EC2_HOST }}
username: ${{ secrets.EC2_USER }}
key: ${{ secrets.SSH_KEY }}
script: |
set -e
cd /home/ubuntu/host
docker compose pull app
docker compose up -d --remove-orphans --force-recreate app
for i in {1..30}; do
curl -fsS http://127.0.0.1:18080/actuator/health | grep -q '"status":"UP"' && ok=1 && break
sleep 3
done
test "$ok" = "1" || (echo "Healthcheck failed" && exit 1)
docker image prune -f