blog: Zola site, nginx image, Forgejo deploy pipeline
This commit is contained in:
commit
a4b677f898
23 changed files with 561 additions and 0 deletions
104
.forgejo/workflows/deploy.yaml
Normal file
104
.forgejo/workflows/deploy.yaml
Normal file
|
|
@ -0,0 +1,104 @@
|
|||
name: Build and Deploy to Production
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
|
||||
jobs:
|
||||
# Same job as in test.yaml (non-main branches); duplicated so a broken
|
||||
# build blocks deploy — Forgejo has no cross-workflow needs.
|
||||
check:
|
||||
runs-on: nix-latest
|
||||
steps:
|
||||
- name: Prepare container for actions
|
||||
run: |
|
||||
echo "experimental-features = nix-command flakes" >> /etc/nix/nix.conf
|
||||
nix-env -iA nixpkgs.nodejs_22
|
||||
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Build site
|
||||
run: nix develop -c zola build
|
||||
|
||||
build:
|
||||
runs-on: arch-latest
|
||||
needs: check
|
||||
container:
|
||||
image: gcr.io/kaniko-project/executor:debug
|
||||
outputs:
|
||||
image_tag: ${{ steps.build_image.outputs.image_tag }}
|
||||
steps:
|
||||
- name: Build and push Docker Image using Kaniko
|
||||
id: build_image
|
||||
run: |
|
||||
# Tags
|
||||
SHORT_SHA=${GITHUB_SHA::8}
|
||||
IMAGE_BASE=${{ secrets.FORGEJO_REGISTRY }}/${{ secrets.FORGEJO_USER }}/blog
|
||||
IMAGE_TAG=${IMAGE_BASE}:${SHORT_SHA}
|
||||
IMAGE_LATEST=${IMAGE_BASE}:latest
|
||||
|
||||
# Auth Conf
|
||||
mkdir -p /kaniko/.docker
|
||||
echo "{\"auths\":{\"${{ secrets.FORGEJO_REGISTRY }}\":{\"auth\":\"$(echo -n ${{ secrets.FORGEJO_USER }}:${{ secrets.FORGEJO_TOKEN }} | base64)\"}}}" > /kaniko/.docker/config.json
|
||||
|
||||
# Build & push
|
||||
/kaniko/executor \
|
||||
--context=git://${{ secrets.FORGEJO_REGISTRY }}/${{ github.repository }}.git \
|
||||
--git=branch=${{ github.ref_name }} \
|
||||
--destination=$IMAGE_TAG \
|
||||
--destination=$IMAGE_LATEST
|
||||
|
||||
# Output the specific tag for deployment
|
||||
echo "image_tag=${IMAGE_TAG}" >> $GITHUB_OUTPUT
|
||||
|
||||
deploy:
|
||||
runs-on: arch-latest
|
||||
needs: build
|
||||
steps:
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
pacman -Syu --noconfirm nodejs openssh rsync
|
||||
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Deploy docker-compose.yml
|
||||
uses: easingthemes/ssh-deploy@v5.1.0
|
||||
with:
|
||||
SSH_PRIVATE_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
||||
REMOTE_HOST: ${{ secrets.DEPLOY_IP }}
|
||||
REMOTE_USER: ${{ secrets.DEPLOY_USER }}
|
||||
SOURCE: "docker-compose.yml"
|
||||
TARGET: "/opt/blog/"
|
||||
|
||||
- name: Deploy and update container
|
||||
uses: appleboy/ssh-action@v1.2.3
|
||||
env:
|
||||
NEW_IMAGE: ${{ needs.build.outputs.image_tag }}
|
||||
with:
|
||||
host: ${{ secrets.DEPLOY_IP }}
|
||||
username: ${{ secrets.DEPLOY_USER }}
|
||||
key: ${{ secrets.DEPLOY_SSH_KEY }}
|
||||
envs: NEW_IMAGE
|
||||
script: |
|
||||
cd /opt/blog
|
||||
|
||||
sed -i "s|image:.*|image: $NEW_IMAGE|" docker-compose.yml
|
||||
|
||||
docker pull $NEW_IMAGE
|
||||
docker compose up -d
|
||||
|
||||
# Wait for the image HEALTHCHECK to report healthy.
|
||||
for i in $(seq 1 18); do
|
||||
status=$(docker inspect --format '{{.State.Health.Status}}' blog 2>/dev/null || echo missing)
|
||||
if [ "$status" = "healthy" ]; then
|
||||
echo "Deployment successful!"
|
||||
exit 0
|
||||
fi
|
||||
sleep 5
|
||||
done
|
||||
echo "blog never became healthy (last status: $status)" >&2
|
||||
docker logs --tail 50 blog
|
||||
exit 1
|
||||
Loading…
Add table
Add a link
Reference in a new issue