mirror of
https://git.meshkee.com/cssd/cssd-front.git
synced 2026-10-10 19:13:18 +03:30
109 lines
3.2 KiB
YAML
109 lines
3.2 KiB
YAML
name: CSSD-Front-Publish
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "*" # run on any tag push
|
|
|
|
jobs:
|
|
build:
|
|
name: Run Publish Job
|
|
runs-on: ubuntu-latest
|
|
|
|
permissions:
|
|
contents: read
|
|
security-events: write
|
|
actions: read
|
|
packages: write
|
|
id-token: write
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: https://git.meshkee.com/actions/checkout@main
|
|
|
|
- name: Setup Docker buildx
|
|
uses: https://git.meshkee.com/actions/setup-buildx-action@master
|
|
|
|
- name: Log into registry git.meshkee.com
|
|
uses: https://git.meshkee.com/actions/login-action@master
|
|
with:
|
|
registry: git.meshkee.com
|
|
username: ${{ vars.DOCKER_USERNAME }}
|
|
password: ${{ vars.DOCKER_PASSWORD }}
|
|
|
|
- name: Build and push Docker image
|
|
id: build-and-push
|
|
uses: https://git.meshkee.com/actions/build-push-action@master
|
|
with:
|
|
context: .
|
|
push: true
|
|
tags: git.meshkee.com/${{ gitea.repository }}:${{ gitea.ref_name }}
|
|
# cache-from: type=local,src=/tmp/.buildx-cache
|
|
# cache-to: type=local,dest=/tmp/.buildx-cache
|
|
no-cache: true
|
|
secrets: |
|
|
gitea_token=${{ secrets.TOKEN }}
|
|
|
|
|
|
deploy:
|
|
name: Deploy Job
|
|
runs-on: ubuntu-latest
|
|
needs: build # Recommended: ensures deploy only runs if build succeeds
|
|
|
|
permissions:
|
|
contents: read
|
|
security-events: write
|
|
actions: read
|
|
id-token: write
|
|
|
|
steps:
|
|
- name: Deploy to server via native SSH
|
|
run: |
|
|
# 1. Setup SSH directory
|
|
mkdir -p ~/.ssh
|
|
chmod 700 ~/.ssh
|
|
|
|
# 2. Add host to known_hosts to bypass prompt
|
|
ssh-keyscan -H ${{ secrets.SSH_HOST }} >> ~/.ssh/known_hosts
|
|
|
|
# 3. Setup the private key
|
|
echo "${{ secrets.SSH_KEY }}" > ~/.ssh/id_rsa
|
|
chmod 600 ~/.ssh/id_rsa
|
|
|
|
# 4. Connect and execute commands
|
|
ssh -i ~/.ssh/id_rsa ${{ secrets.SSH_USER }}@${{ secrets.SSH_HOST }} << 'EOF'
|
|
cd /apps/admin-front
|
|
docker pull git.meshkee.com/${{ gitea.repository }}:${{ gitea.ref_name }}
|
|
IMAGE=git.meshkee.com/${{ gitea.repository }}:${{ gitea.ref_name }} docker compose up -d
|
|
EOF
|
|
|
|
|
|
# deploy:
|
|
# name: Deploy Job
|
|
# runs-on: ubuntu-latest
|
|
|
|
# permissions:
|
|
# contents: read
|
|
# security-events: write
|
|
# actions: read
|
|
# id-token: write
|
|
|
|
# steps:
|
|
# - name: Deploy to server
|
|
# uses: https://git.meshkee.com/actions/ssh-action@master
|
|
# with:
|
|
# host: ${{ secrets.SSH_HOST }}
|
|
# username: ${{ secrets.SSH_USER }}
|
|
# key: ${{ secrets.SSH_KEY }}
|
|
# port: 22
|
|
# script: |
|
|
# cd /apps/admin-front
|
|
# docker rm -f admin-front || true
|
|
# docker pull git.meshkee.com/${{ gitea.repository }}:${{ gitea.ref_name }}
|
|
# sleep 5
|
|
# IMAGE=git.meshkee.com/${{ gitea.repository }}:${{ gitea.ref_name }} docker compose up -d --remove-orphans
|
|
|
|
# sleep 10
|
|
# docker ps | grep admin-front
|
|
# curl -I https://admin.shirinibalout.com/user/dashboard || echo "Health check failed"
|