Files
brave-sync-deployment/.gitea/workflows/deploy.yaml
T
feedc0de ea50a260fa
Validate, publish, and deploy Brave Sync / validate (push) Failing after 15s
Validate, publish, and deploy Brave Sync / image (push) Skipped
Validate, publish, and deploy Brave Sync / chart (push) Skipped
Validate, publish, and deploy Brave Sync / deploy (push) Skipped
Initial commit with the existing deployment files
2026-10-09 11:39:38 +02:00

156 lines
7.2 KiB
YAML

name: Validate, publish, and deploy Brave Sync
on:
pull_request:
push:
branches: [main]
env:
HELM_VERSION: v4.2.2
HELM_SHA256: 9adafecab4d406853bba163a70e9f104f47dbbf65ce24b7653bae7e36150bcb6
KUBECTL_VERSION: v1.36.3
KUBERNETES_API: https://host.containers.internal:6443
KUBERNETES_TLS_SERVER_NAME: 192.168.0.2
IMAGE: registry.brunner.ninja/feedc0de/brave-sync
jobs:
validate:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
- name: Install pinned Helm
run: |
curl -fsSL -o "${RUNNER_TEMP}/helm.tgz" "https://get.helm.sh/helm-${HELM_VERSION}-linux-amd64.tar.gz"
printf '%s %s\n' "${HELM_SHA256}" "${RUNNER_TEMP}/helm.tgz" | sha256sum --check
tar -xzf "${RUNNER_TEMP}/helm.tgz" -C "${RUNNER_TEMP}" --strip-components=1 linux-amd64/helm
echo "${RUNNER_TEMP}" >> "${GITHUB_PATH}"
- name: Lint and render the packaged chart
run: ./test.sh
image:
if: gitea.event_name == 'push' && gitea.ref == 'refs/heads/main'
needs: validate
runs-on: linux_amd64
timeout-minutes: 30
steps:
- uses: actions/checkout@v4
- name: Install pinned Helm for the runtime smoke test
run: |
curl -fsSL -o "${RUNNER_TEMP}/helm.tgz" "https://get.helm.sh/helm-${HELM_VERSION}-linux-amd64.tar.gz"
printf '%s %s\n' "${HELM_SHA256}" "${RUNNER_TEMP}/helm.tgz" | sha256sum --check
tar -xzf "${RUNNER_TEMP}/helm.tgz" -C "${RUNNER_TEMP}" --strip-components=1 linux-amd64/helm
echo "${RUNNER_TEMP}" >> "${GITHUB_PATH}"
- name: Build and smoke test the pinned upstream server
env:
COMMIT_SHA: ${{ gitea.sha }}
run: |
set -euo pipefail
upstream_commit=$(<upstream-commit.txt)
image_tag="sha-${COMMIT_SHA:0:12}"
podman build --pull=always \
--build-arg "UPSTREAM_COMMIT=${upstream_commit}" \
--label "org.opencontainers.image.revision=${COMMIT_SHA}" \
--tag "${IMAGE}:${image_tag}" image
./smoke-test.sh "${IMAGE}:${image_tag}"
- name: Publish image to Quay
env:
COMMIT_SHA: ${{ gitea.sha }}
QUAY_USERNAME: ${{ secrets.QUAY_USERNAME }}
QUAY_TOKEN: ${{ secrets.QUAY_TOKEN }}
run: |
set -euo pipefail
test -n "${QUAY_USERNAME}"
test -n "${QUAY_TOKEN}"
authfile="${RUNNER_TEMP}/quay-auth.json"
trap 'rm -f "${authfile}"' EXIT
printf '%s' "${QUAY_TOKEN}" | podman login registry.brunner.ninja \
--authfile "${authfile}" --username "${QUAY_USERNAME}" --password-stdin
podman push --authfile "${authfile}" "${IMAGE}:sha-${COMMIT_SHA:0:12}"
chart:
if: gitea.event_name == 'push' && gitea.ref == 'refs/heads/main'
needs: image
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
- name: Install pinned Helm
run: |
curl -fsSL -o "${RUNNER_TEMP}/helm.tgz" "https://get.helm.sh/helm-${HELM_VERSION}-linux-amd64.tar.gz"
printf '%s %s\n' "${HELM_SHA256}" "${RUNNER_TEMP}/helm.tgz" | sha256sum --check
tar -xzf "${RUNNER_TEMP}/helm.tgz" -C "${RUNNER_TEMP}" --strip-components=1 linux-amd64/helm
echo "${RUNNER_TEMP}" >> "${GITHUB_PATH}"
- name: Publish matching chart to public Helm repository
env:
COMMIT_SHA: ${{ gitea.sha }}
RUN_NUMBER: ${{ gitea.run_number }}
PACKAGE_USERNAME: ${{ secrets.PACKAGE_USERNAME }}
PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }}
run: |
set -euo pipefail
test -n "${PACKAGE_USERNAME}"
test -n "${PACKAGE_TOKEN}"
package=$(./package.sh "${RUNNER_TEMP}" "sha-${COMMIT_SHA:0:12}" "r${RUN_NUMBER}")
helm lint "${package}" --strict
helm template brave-sync "${package}" --namespace brave-sync > "${RUNNER_TEMP}/rendered.yaml"
curl --fail --silent --show-error --request POST \
--user "${PACKAGE_USERNAME}:${PACKAGE_TOKEN}" \
--upload-file "${package}" \
https://code.brunner.ninja/api/packages/feedc0de/helm/api/charts
deploy:
if: gitea.ref == 'refs/heads/main'
needs: chart
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- name: Install pinned clients
run: |
curl -fsSL -o "${RUNNER_TEMP}/helm.tgz" "https://get.helm.sh/helm-${HELM_VERSION}-linux-amd64.tar.gz"
printf '%s %s\n' "${HELM_SHA256}" "${RUNNER_TEMP}/helm.tgz" | sha256sum --check
tar -xzf "${RUNNER_TEMP}/helm.tgz" -C "${RUNNER_TEMP}" --strip-components=1 linux-amd64/helm
curl -fsSL -o "${RUNNER_TEMP}/kubectl" "https://dl.k8s.io/release/${KUBECTL_VERSION}/bin/linux/amd64/kubectl"
curl -fsSL -o "${RUNNER_TEMP}/kubectl.sha256" "https://dl.k8s.io/release/${KUBECTL_VERSION}/bin/linux/amd64/kubectl.sha256"
printf '%s %s\n' "$(cat "${RUNNER_TEMP}/kubectl.sha256")" "${RUNNER_TEMP}/kubectl" | sha256sum --check
chmod 0700 "${RUNNER_TEMP}/kubectl"
echo "${RUNNER_TEMP}" >> "${GITHUB_PATH}"
- name: Configure limited Kubernetes access
env:
KUBE_CONFIG_BASE64: ${{ secrets.KUBE_CONFIG_BASE64 }}
run: |
set -euo pipefail
test -n "${KUBE_CONFIG_BASE64}"
printf '%s' "${KUBE_CONFIG_BASE64}" | base64 --decode > "${RUNNER_TEMP}/kubeconfig"
chmod 0600 "${RUNNER_TEMP}/kubeconfig"
export KUBECONFIG="${RUNNER_TEMP}/kubeconfig"
kubectl config set-cluster cluster --server="${KUBERNETES_API}" \
--tls-server-name="${KUBERNETES_TLS_SERVER_NAME}" >/dev/null
- name: Update named resources and verify rollout
env:
COMMIT_SHA: ${{ gitea.sha }}
RUN_NUMBER: ${{ gitea.run_number }}
run: |
set -euo pipefail
export KUBECONFIG="${RUNNER_TEMP}/kubeconfig"
if ! existing=$(kubectl --namespace brave-sync get deployment/brave-sync 2>&1); then
if [[ "${existing}" == *NotFound* ]]; then
echo "Initial administrator install is required; published image and chart are ready."
exit 0
fi
echo "${existing}" >&2
exit 1
fi
package=$(./package.sh "${RUNNER_TEMP}" "sha-${COMMIT_SHA:0:12}" "r${RUN_NUMBER}")
helm template brave-sync "${package}" --namespace brave-sync > "${RUNNER_TEMP}/rendered.yaml"
kubectl --namespace brave-sync apply --filename "${RUNNER_TEMP}/rendered.yaml"
if ! kubectl --namespace brave-sync rollout status statefulset/brave-sync-dynamodb --timeout=5m \
|| ! kubectl --namespace brave-sync rollout status deployment/brave-sync-valkey --timeout=5m \
|| ! kubectl --namespace brave-sync rollout status deployment/brave-sync --timeout=5m; then
kubectl --namespace brave-sync get statefulset/brave-sync-dynamodb deployment/brave-sync-valkey deployment/brave-sync -o wide
exit 1
fi
image=$(kubectl --namespace brave-sync get deployment/brave-sync -o jsonpath='{.spec.template.spec.containers[0].image}')
test "${image}" = "${IMAGE}:sha-${COMMIT_SHA:0:12}"