Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 0 additions & 43 deletions .github/actions/deploy-ecs/action.yml

This file was deleted.

111 changes: 96 additions & 15 deletions .github/workflows/deploy-ferrous.yml
Original file line number Diff line number Diff line change
@@ -1,28 +1,41 @@
name: Build and Push to Harbor
name: Build and Deploy

on:
workflow_dispatch:
push:
branches:
- carmen/fleet-deploy
- automation/bors/auto
- main

permissions:
contents: read
contents: write

env:
GIT_VERSION: ferrous-systems/bors@${{ github.sha }}
IMAGE_NAME: ops/bors
IMAGE: ${{ vars.REGISTRY }}/ops/bors

jobs:
deploy-bors:
name: Deploy Bors to Ferrous Systems Harbor
deploy-staging:
name: Deploy Bors to ferrous-systems-test
runs-on: ubuntu-latest
environment: deployment
environment: fleet-deploy
concurrency:
group: deployment
group: deploy-staging
cancel-in-progress: true
if: github.repository_owner == 'ferrous-systems'
# if: ${{ github.branch }} == 'automation/bors/auto'

steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
persist-credentials: true

# - run: |-
# git config --get user.name
# git config --get user.email
# git checkout -b carmen/weee
# git push origin carmen/weee

- name: Authenticate to Harbor
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
Expand All @@ -35,14 +48,82 @@

- name: Build and tag the container image
env:
REGISTRY: ${{ vars.REGISTRY }}
REPOSITORY: ops/bors
IMAGE_TAG: latest
IMAGE_TAG: staging
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
tags: ${{ env.REGISTRY }}/${{ env.REPOSITORY }}:${{ env.IMAGE_TAG }}
tags: |
${{ env.IMAGE }}:staging
${{ env.IMAGE }}:${{ env.IMAGE_TAG }}
push: true
cache-from: type=gha
cache-to: type=gha,mode=max
build-args: GIT_VERSION=ferrous-systems/bors@${{ github.sha }}
cache-from: type=registry,ref=${{ env.IMAGE }}:build-cache
cache-to: type=registry,ref=${{ env.IMAGE }}:build-cache
build-args: GIT_VERSION=${{ env.GIT_VERSION }}

- name: Deploy to ferrous-systems-test
uses: ferrous-systems/shared-github-actions/fleet-deploy@1d0a7ec52a703035257b78e207ec0ec96ec2cae1
with:
target: ferrous-systems-test
patch: |-
apiVersion: apps/v1
kind: Deployment
metadata:
name: bors
spec:
template:
spec:
containers:
- name: bors
image: ${{ env.IMAGE }}:${{ github.sha }}


# - name: Create the deployment kustomization
# run: |-
# cat >fleet/env.yaml <<-EOF
# apiVersion: apps/v1
# EOF

# - name: Push to ferrous-systems-test branch
# run: |
# git config user.name "github-actions[bot]"
# git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
# git checkout -B automation/fleet/ferrous-systems-test
# git add deployment/env.yaml
# git commit -m "Deploy commit ${{ github.sha }}"
# git push --force origin automation/fleet/ferrous-systems-test

# - name: Wait for ref to deploy
# run: ci/wait-ref-deployed.sh bors-test ${{ env.GIT_VERSION }}

deploy-production:
strategy:
matrix:
org: [ferrous-systems, ferrocene]
name: Deploy Bors to ${{ matrix.org }}
runs-on: ubuntu-latest
needs: deploy-staging
environment: fleet-deploy
concurrency:
group: deploy-production
queue: single
if: github.branch == 'main' # || github.branch == 'carmen/fleet-deploy'

steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: automation/fleet/ferrous-systems-test

- name: Push to ${{ matrix.org }} branch
run: |-
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git checkout -B automation/fleet/${{ matrix.org }}
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
Comment thread
dotcarmen marked this conversation as resolved.
Dismissed
git push --force origin automation/fleet/${{ matrix.org }}
Comment thread
dotcarmen marked this conversation as resolved.
Dismissed

- name: Wait for ref to deploy
run: |-
declare -A subdomains
subdomains[ferrous-systems]="bors"
subdomains[ferrocene]="ferrocene-bors"
ci/wait-ref-deployed.sh "${subdomains[${{ matrix.org }}]}" ${{ env.GIT_VERSION }}
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
Comment thread
dotcarmen marked this conversation as resolved.
Dismissed
Comment thread
dotcarmen marked this conversation as resolved.
Dismissed
27 changes: 0 additions & 27 deletions .github/workflows/deploy-production.yml

This file was deleted.

29 changes: 0 additions & 29 deletions .github/workflows/deploy-staging.yml

This file was deleted.

25 changes: 25 additions & 0 deletions ci/wait-ref-deployed.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
#!/bin/bash

# Waits for the ref to be successfully deployed

set -eu
IFS=$'\n\t'

if [[ $# -ne 2 ]]; then
echo "usage: $0 <subdomain> <git_version>"
exit 1
fi

subdomain="$1"
git_version="$2"

while true; do
response="$(curl --silent "https://${subdomain}2.infra.ferrous-systems.net/.internal/git_version")"
echo "response: $response"
if [[ "$response" == "$git_version" ]]; then
echo "successfully deployed"
exit 0
fi

sleep 1
done
51 changes: 51 additions & 0 deletions fleet/deployment.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: bors
spec:
replicas: 1
selector:
matchLabels:
app: bors
template:
metadata:
labels:
app: bors
spec:
imagePullSecrets:
- name: imagepull
volumes:
- name: bors-permissions
configMap:
name: bors-permissions
containers:
- name: bors
ports:
- containerPort: 8080
env:
- name: CMD_PREFIX
value: '@handlebors'
- name: PERMISSIONS
value: /etc/bors/permissions
- name: DATABASE_URL
valueFrom:
secretKeyRef:
name: database-cluster-app
key: uri
envFrom:
- configMapRef:
# sets the following variables:
# - APP_ID
# - OAUTH_CLIENT_ID
name: github-app
- configMapRef:
# - WEB_URL
name: deployment
- secretRef:
# - PRIVATE_KEY
# - OAUTH_CLIENT_SECRET
# - WEBHOOK_SECRET
name: github-app
volumeMounts:
- name: bors-permissions
mountPath: /etc/bors/permissions
2 changes: 2 additions & 0 deletions fleet/fleet.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
kustomize:
dir: ''
6 changes: 6 additions & 0 deletions fleet/kustomization.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
resources:
- deployment.yaml
- service.yaml
patches:
# set by CI
- path: env.yaml
11 changes: 11 additions & 0 deletions fleet/service.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
apiVersion: v1
kind: Service
metadata:
name: bors
spec:
selector:
app: bors
ports:
- name: http
port: 8080
protocol: TCP
Loading