Validate, publish, and deploy Brave Sync / validate (push) Failing after 15s
Validate, publish, and deploy Brave Sync / image (push) Skipped
Validate, publish, and deploy Brave Sync / chart (push) Skipped
Validate, publish, and deploy Brave Sync / deploy (push) Skipped
156 lines
7.2 KiB
YAML
156 lines
7.2 KiB
YAML
name: Validate, publish, and deploy Brave Sync
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches: [main]
|
|
|
|
env:
|
|
HELM_VERSION: v4.2.2
|
|
HELM_SHA256: 9adafecab4d406853bba163a70e9f104f47dbbf65ce24b7653bae7e36150bcb6
|
|
KUBECTL_VERSION: v1.36.3
|
|
KUBERNETES_API: https://host.containers.internal:6443
|
|
KUBERNETES_TLS_SERVER_NAME: 192.168.0.2
|
|
IMAGE: registry.brunner.ninja/feedc0de/brave-sync
|
|
|
|
jobs:
|
|
validate:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install pinned Helm
|
|
run: |
|
|
curl -fsSL -o "${RUNNER_TEMP}/helm.tgz" "https://get.helm.sh/helm-${HELM_VERSION}-linux-amd64.tar.gz"
|
|
printf '%s %s\n' "${HELM_SHA256}" "${RUNNER_TEMP}/helm.tgz" | sha256sum --check
|
|
tar -xzf "${RUNNER_TEMP}/helm.tgz" -C "${RUNNER_TEMP}" --strip-components=1 linux-amd64/helm
|
|
echo "${RUNNER_TEMP}" >> "${GITHUB_PATH}"
|
|
- name: Lint and render the packaged chart
|
|
run: ./test.sh
|
|
|
|
image:
|
|
if: gitea.event_name == 'push' && gitea.ref == 'refs/heads/main'
|
|
needs: validate
|
|
runs-on: linux_amd64
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install pinned Helm for the runtime smoke test
|
|
run: |
|
|
curl -fsSL -o "${RUNNER_TEMP}/helm.tgz" "https://get.helm.sh/helm-${HELM_VERSION}-linux-amd64.tar.gz"
|
|
printf '%s %s\n' "${HELM_SHA256}" "${RUNNER_TEMP}/helm.tgz" | sha256sum --check
|
|
tar -xzf "${RUNNER_TEMP}/helm.tgz" -C "${RUNNER_TEMP}" --strip-components=1 linux-amd64/helm
|
|
echo "${RUNNER_TEMP}" >> "${GITHUB_PATH}"
|
|
- name: Build and smoke test the pinned upstream server
|
|
env:
|
|
COMMIT_SHA: ${{ gitea.sha }}
|
|
run: |
|
|
set -euo pipefail
|
|
upstream_commit=$(<upstream-commit.txt)
|
|
image_tag="sha-${COMMIT_SHA:0:12}"
|
|
podman build --pull=always \
|
|
--build-arg "UPSTREAM_COMMIT=${upstream_commit}" \
|
|
--label "org.opencontainers.image.revision=${COMMIT_SHA}" \
|
|
--tag "${IMAGE}:${image_tag}" image
|
|
./smoke-test.sh "${IMAGE}:${image_tag}"
|
|
- name: Publish image to Quay
|
|
env:
|
|
COMMIT_SHA: ${{ gitea.sha }}
|
|
QUAY_USERNAME: ${{ secrets.QUAY_USERNAME }}
|
|
QUAY_TOKEN: ${{ secrets.QUAY_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
test -n "${QUAY_USERNAME}"
|
|
test -n "${QUAY_TOKEN}"
|
|
authfile="${RUNNER_TEMP}/quay-auth.json"
|
|
trap 'rm -f "${authfile}"' EXIT
|
|
printf '%s' "${QUAY_TOKEN}" | podman login registry.brunner.ninja \
|
|
--authfile "${authfile}" --username "${QUAY_USERNAME}" --password-stdin
|
|
podman push --authfile "${authfile}" "${IMAGE}:sha-${COMMIT_SHA:0:12}"
|
|
|
|
chart:
|
|
if: gitea.event_name == 'push' && gitea.ref == 'refs/heads/main'
|
|
needs: image
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install pinned Helm
|
|
run: |
|
|
curl -fsSL -o "${RUNNER_TEMP}/helm.tgz" "https://get.helm.sh/helm-${HELM_VERSION}-linux-amd64.tar.gz"
|
|
printf '%s %s\n' "${HELM_SHA256}" "${RUNNER_TEMP}/helm.tgz" | sha256sum --check
|
|
tar -xzf "${RUNNER_TEMP}/helm.tgz" -C "${RUNNER_TEMP}" --strip-components=1 linux-amd64/helm
|
|
echo "${RUNNER_TEMP}" >> "${GITHUB_PATH}"
|
|
- name: Publish matching chart to public Helm repository
|
|
env:
|
|
COMMIT_SHA: ${{ gitea.sha }}
|
|
RUN_NUMBER: ${{ gitea.run_number }}
|
|
PACKAGE_USERNAME: ${{ secrets.PACKAGE_USERNAME }}
|
|
PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
test -n "${PACKAGE_USERNAME}"
|
|
test -n "${PACKAGE_TOKEN}"
|
|
package=$(./package.sh "${RUNNER_TEMP}" "sha-${COMMIT_SHA:0:12}" "r${RUN_NUMBER}")
|
|
helm lint "${package}" --strict
|
|
helm template brave-sync "${package}" --namespace brave-sync > "${RUNNER_TEMP}/rendered.yaml"
|
|
curl --fail --silent --show-error --request POST \
|
|
--user "${PACKAGE_USERNAME}:${PACKAGE_TOKEN}" \
|
|
--upload-file "${package}" \
|
|
https://code.brunner.ninja/api/packages/feedc0de/helm/api/charts
|
|
|
|
deploy:
|
|
if: gitea.ref == 'refs/heads/main'
|
|
needs: chart
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 20
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install pinned clients
|
|
run: |
|
|
curl -fsSL -o "${RUNNER_TEMP}/helm.tgz" "https://get.helm.sh/helm-${HELM_VERSION}-linux-amd64.tar.gz"
|
|
printf '%s %s\n' "${HELM_SHA256}" "${RUNNER_TEMP}/helm.tgz" | sha256sum --check
|
|
tar -xzf "${RUNNER_TEMP}/helm.tgz" -C "${RUNNER_TEMP}" --strip-components=1 linux-amd64/helm
|
|
curl -fsSL -o "${RUNNER_TEMP}/kubectl" "https://dl.k8s.io/release/${KUBECTL_VERSION}/bin/linux/amd64/kubectl"
|
|
curl -fsSL -o "${RUNNER_TEMP}/kubectl.sha256" "https://dl.k8s.io/release/${KUBECTL_VERSION}/bin/linux/amd64/kubectl.sha256"
|
|
printf '%s %s\n' "$(cat "${RUNNER_TEMP}/kubectl.sha256")" "${RUNNER_TEMP}/kubectl" | sha256sum --check
|
|
chmod 0700 "${RUNNER_TEMP}/kubectl"
|
|
echo "${RUNNER_TEMP}" >> "${GITHUB_PATH}"
|
|
- name: Configure limited Kubernetes access
|
|
env:
|
|
KUBE_CONFIG_BASE64: ${{ secrets.KUBE_CONFIG_BASE64 }}
|
|
run: |
|
|
set -euo pipefail
|
|
test -n "${KUBE_CONFIG_BASE64}"
|
|
printf '%s' "${KUBE_CONFIG_BASE64}" | base64 --decode > "${RUNNER_TEMP}/kubeconfig"
|
|
chmod 0600 "${RUNNER_TEMP}/kubeconfig"
|
|
export KUBECONFIG="${RUNNER_TEMP}/kubeconfig"
|
|
kubectl config set-cluster cluster --server="${KUBERNETES_API}" \
|
|
--tls-server-name="${KUBERNETES_TLS_SERVER_NAME}" >/dev/null
|
|
- name: Update named resources and verify rollout
|
|
env:
|
|
COMMIT_SHA: ${{ gitea.sha }}
|
|
RUN_NUMBER: ${{ gitea.run_number }}
|
|
run: |
|
|
set -euo pipefail
|
|
export KUBECONFIG="${RUNNER_TEMP}/kubeconfig"
|
|
if ! existing=$(kubectl --namespace brave-sync get deployment/brave-sync 2>&1); then
|
|
if [[ "${existing}" == *NotFound* ]]; then
|
|
echo "Initial administrator install is required; published image and chart are ready."
|
|
exit 0
|
|
fi
|
|
echo "${existing}" >&2
|
|
exit 1
|
|
fi
|
|
package=$(./package.sh "${RUNNER_TEMP}" "sha-${COMMIT_SHA:0:12}" "r${RUN_NUMBER}")
|
|
helm template brave-sync "${package}" --namespace brave-sync > "${RUNNER_TEMP}/rendered.yaml"
|
|
kubectl --namespace brave-sync apply --filename "${RUNNER_TEMP}/rendered.yaml"
|
|
if ! kubectl --namespace brave-sync rollout status statefulset/brave-sync-dynamodb --timeout=5m \
|
|
|| ! kubectl --namespace brave-sync rollout status deployment/brave-sync-valkey --timeout=5m \
|
|
|| ! kubectl --namespace brave-sync rollout status deployment/brave-sync --timeout=5m; then
|
|
kubectl --namespace brave-sync get statefulset/brave-sync-dynamodb deployment/brave-sync-valkey deployment/brave-sync -o wide
|
|
exit 1
|
|
fi
|
|
image=$(kubectl --namespace brave-sync get deployment/brave-sync -o jsonpath='{.spec.template.spec.containers[0].image}')
|
|
test "${image}" = "${IMAGE}:sha-${COMMIT_SHA:0:12}"
|