From c28541ebf45b954372027601d7d5ce85be232512 Mon Sep 17 00:00:00 2001 From: Carmen Donnelly Date: Fri, 18 Sep 2026 12:44:55 +0200 Subject: [PATCH] feat: fleet deployments --- .github/actions/deploy-ecs/action.yml | 43 --------- .github/workflows/deploy-ferrous.yml | 111 ++++++++++++++++++++---- .github/workflows/deploy-production.yml | 27 ------ .github/workflows/deploy-staging.yml | 29 ------- ci/wait-ref-deployed.sh | 25 ++++++ fleet/deployment.yaml | 51 +++++++++++ fleet/fleet.yaml | 2 + fleet/kustomization.yaml | 6 ++ fleet/service.yaml | 11 +++ 9 files changed, 191 insertions(+), 114 deletions(-) delete mode 100644 .github/actions/deploy-ecs/action.yml delete mode 100644 .github/workflows/deploy-production.yml delete mode 100644 .github/workflows/deploy-staging.yml create mode 100755 ci/wait-ref-deployed.sh create mode 100644 fleet/deployment.yaml create mode 100644 fleet/fleet.yaml create mode 100644 fleet/kustomization.yaml create mode 100644 fleet/service.yaml diff --git a/.github/actions/deploy-ecs/action.yml b/.github/actions/deploy-ecs/action.yml deleted file mode 100644 index 57b0d354..00000000 --- a/.github/actions/deploy-ecs/action.yml +++ /dev/null @@ -1,43 +0,0 @@ -name: Deploy to ECS -description: Build Docker image, push to ECR, and deploy to ECS - -inputs: - aws-iam: - description: AWS account ID to assume role in - required: true - -runs: - using: composite - steps: - - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 - with: - role-to-assume: arn:aws:iam::${{ inputs.aws-iam }}:role/gha-access - aws-region: us-east-2 - - - name: Login to Amazon ECR - id: login-ecr - uses: aws-actions/amazon-ecr-login@03f1aad4c6c7ffd436567f42f9384779290529bd # v2.1.7 - - - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - - - name: Build and tag the Docker image - env: - REGISTRY: ${{ steps.login-ecr.outputs.registry }} - REPOSITORY: bors - IMAGE_TAG: latest - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 - with: - context: . - tags: ${{ env.REGISTRY }}/${{ env.REPOSITORY }}:${{ env.IMAGE_TAG }} - push: true - cache-from: type=gha - cache-to: type=gha,mode=max - build-args: GIT_VERSION=${{ github.sha }} - - - name: Kick ECS to deploy new version - shell: bash - run: | - aws ecs update-service --service bors --cluster bors --force-new-deployment - # Poll every 15 seconds until a successful state has been reached. Fail after 40 failed checks. - aws ecs wait services-stable --services bors --cluster bors diff --git a/.github/workflows/deploy-ferrous.yml b/.github/workflows/deploy-ferrous.yml index 00bc4ef2..52e72a32 100644 --- a/.github/workflows/deploy-ferrous.yml +++ b/.github/workflows/deploy-ferrous.yml @@ -1,28 +1,41 @@ -name: Build and Push to Harbor +name: Build and Deploy on: workflow_dispatch: push: branches: + - carmen/fleet-deploy + - automation/bors/auto - main permissions: - contents: read + contents: write + +env: + GIT_VERSION: ferrous-systems/bors@${{ github.sha }} + IMAGE_NAME: ops/bors + IMAGE: ${{ vars.REGISTRY }}/ops/bors jobs: - deploy-bors: - name: Deploy Bors to Ferrous Systems Harbor + deploy-staging: + name: Deploy Bors to ferrous-systems-test runs-on: ubuntu-latest - environment: deployment + environment: fleet-deploy concurrency: - group: deployment + group: deploy-staging cancel-in-progress: true - if: github.repository_owner == 'ferrous-systems' + # if: ${{ github.branch }} == 'automation/bors/auto' steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - persist-credentials: false + persist-credentials: true + + # - run: |- + # git config --get user.name + # git config --get user.email + # git checkout -b carmen/weee + # git push origin carmen/weee - name: Authenticate to Harbor uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0 @@ -35,14 +48,82 @@ jobs: - name: Build and tag the container image env: - REGISTRY: ${{ vars.REGISTRY }} - REPOSITORY: ops/bors - IMAGE_TAG: latest + IMAGE_TAG: staging uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . - tags: ${{ env.REGISTRY }}/${{ env.REPOSITORY }}:${{ env.IMAGE_TAG }} + tags: | + ${{ env.IMAGE }}:staging + ${{ env.IMAGE }}:${{ env.IMAGE_TAG }} push: true - cache-from: type=gha - cache-to: type=gha,mode=max - build-args: GIT_VERSION=ferrous-systems/bors@${{ github.sha }} + cache-from: type=registry,ref=${{ env.IMAGE }}:build-cache + cache-to: type=registry,ref=${{ env.IMAGE }}:build-cache + build-args: GIT_VERSION=${{ env.GIT_VERSION }} + + - name: Deploy to ferrous-systems-test + uses: ferrous-systems/shared-github-actions/fleet-deploy@1d0a7ec52a703035257b78e207ec0ec96ec2cae1 + with: + target: ferrous-systems-test + patch: |- + apiVersion: apps/v1 + kind: Deployment + metadata: + name: bors + spec: + template: + spec: + containers: + - name: bors + image: ${{ env.IMAGE }}:${{ github.sha }} + + + # - name: Create the deployment kustomization + # run: |- + # cat >fleet/env.yaml <<-EOF + # apiVersion: apps/v1 + # EOF + + # - name: Push to ferrous-systems-test branch + # run: | + # git config user.name "github-actions[bot]" + # git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + # git checkout -B automation/fleet/ferrous-systems-test + # git add deployment/env.yaml + # git commit -m "Deploy commit ${{ github.sha }}" + # git push --force origin automation/fleet/ferrous-systems-test + + # - name: Wait for ref to deploy + # run: ci/wait-ref-deployed.sh bors-test ${{ env.GIT_VERSION }} + + deploy-production: + strategy: + matrix: + org: [ferrous-systems, ferrocene] + name: Deploy Bors to ${{ matrix.org }} + runs-on: ubuntu-latest + needs: deploy-staging + environment: fleet-deploy + concurrency: + group: deploy-production + queue: single + if: github.branch == 'main' # || github.branch == 'carmen/fleet-deploy' + + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + ref: automation/fleet/ferrous-systems-test + + - name: Push to ${{ matrix.org }} branch + run: |- + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git checkout -B automation/fleet/${{ matrix.org }} + git push --force origin automation/fleet/${{ matrix.org }} + + - name: Wait for ref to deploy + run: |- + declare -A subdomains + subdomains[ferrous-systems]="bors" + subdomains[ferrocene]="ferrocene-bors" + ci/wait-ref-deployed.sh "${subdomains[${{ matrix.org }}]}" ${{ env.GIT_VERSION }} diff --git a/.github/workflows/deploy-production.yml b/.github/workflows/deploy-production.yml deleted file mode 100644 index 1df6d314..00000000 --- a/.github/workflows/deploy-production.yml +++ /dev/null @@ -1,27 +0,0 @@ -name: Deploy production - -on: - workflow_dispatch: - -permissions: - contents: read - -jobs: - deploy-to-production: - name: Deploy to production - runs-on: ubuntu-latest - environment: production - concurrency: production - if: github.repository_owner == 'rust-lang' - permissions: - id-token: write # required for OIDC authentication to AWS - contents: read - steps: - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Deploy to ECS - uses: ./.github/actions/deploy-ecs - with: - aws-iam: "351621253146" diff --git a/.github/workflows/deploy-staging.yml b/.github/workflows/deploy-staging.yml deleted file mode 100644 index 57ee8843..00000000 --- a/.github/workflows/deploy-staging.yml +++ /dev/null @@ -1,29 +0,0 @@ -name: Deploy staging - -on: - push: - branches: - - main - -permissions: - contents: read - -jobs: - deploy-to-staging: - name: Deploy to staging - runs-on: ubuntu-latest - environment: staging - concurrency: staging - if: github.repository_owner == 'rust-lang' - permissions: - id-token: write # required for OIDC authentication to AWS - contents: read - steps: - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Deploy to ECS - uses: ./.github/actions/deploy-ecs - with: - aws-iam: "392478027976" diff --git a/ci/wait-ref-deployed.sh b/ci/wait-ref-deployed.sh new file mode 100755 index 00000000..cd564219 --- /dev/null +++ b/ci/wait-ref-deployed.sh @@ -0,0 +1,25 @@ +#!/bin/bash + +# Waits for the ref to be successfully deployed + +set -eu +IFS=$'\n\t' + +if [[ $# -ne 2 ]]; then + echo "usage: $0 " + exit 1 +fi + +subdomain="$1" +git_version="$2" + +while true; do + response="$(curl --silent "https://${subdomain}2.infra.ferrous-systems.net/.internal/git_version")" + echo "response: $response" + if [[ "$response" == "$git_version" ]]; then + echo "successfully deployed" + exit 0 + fi + + sleep 1 +done diff --git a/fleet/deployment.yaml b/fleet/deployment.yaml new file mode 100644 index 00000000..46f13a6b --- /dev/null +++ b/fleet/deployment.yaml @@ -0,0 +1,51 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: bors +spec: + replicas: 1 + selector: + matchLabels: + app: bors + template: + metadata: + labels: + app: bors + spec: + imagePullSecrets: + - name: imagepull + volumes: + - name: bors-permissions + configMap: + name: bors-permissions + containers: + - name: bors + ports: + - containerPort: 8080 + env: + - name: CMD_PREFIX + value: '@handlebors' + - name: PERMISSIONS + value: /etc/bors/permissions + - name: DATABASE_URL + valueFrom: + secretKeyRef: + name: database-cluster-app + key: uri + envFrom: + - configMapRef: + # sets the following variables: + # - APP_ID + # - OAUTH_CLIENT_ID + name: github-app + - configMapRef: + # - WEB_URL + name: deployment + - secretRef: + # - PRIVATE_KEY + # - OAUTH_CLIENT_SECRET + # - WEBHOOK_SECRET + name: github-app + volumeMounts: + - name: bors-permissions + mountPath: /etc/bors/permissions diff --git a/fleet/fleet.yaml b/fleet/fleet.yaml new file mode 100644 index 00000000..7abeca01 --- /dev/null +++ b/fleet/fleet.yaml @@ -0,0 +1,2 @@ +kustomize: + dir: '' diff --git a/fleet/kustomization.yaml b/fleet/kustomization.yaml new file mode 100644 index 00000000..29bdd0c8 --- /dev/null +++ b/fleet/kustomization.yaml @@ -0,0 +1,6 @@ +resources: + - deployment.yaml + - service.yaml +patches: + # set by CI + - path: env.yaml diff --git a/fleet/service.yaml b/fleet/service.yaml new file mode 100644 index 00000000..0815ee38 --- /dev/null +++ b/fleet/service.yaml @@ -0,0 +1,11 @@ +apiVersion: v1 +kind: Service +metadata: + name: bors +spec: + selector: + app: bors + ports: + - name: http + port: 8080 + protocol: TCP