aprs.me/.github/workflows/deploy.yml
Graham McIntire b93da46e4e
Fix K3s API TLS verification for Tailscale connection
Add insecure-skip-tls-verify flag to kubectl config to bypass certificate
validation when connecting via Tailscale IP. The K3s certificates don't
include the Tailscale IP in their SANs, causing TLS verification to fail.
2025-09-08 09:36:15 -05:00

107 lines
3.2 KiB
YAML

name: Build and Deploy
on:
push:
branches: [main]
# Cancel in-progress runs when a new run is triggered
concurrency:
group: deploy-${{ github.ref }}
cancel-in-progress: true
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}
jobs:
build-and-push:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
submodules: recursive
- name: Log in to the Container registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=ref,event=branch
type=sha,prefix={{branch}}-
type=raw,value=latest,enable={{is_default_branch}}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build and push Docker image
uses: docker/build-push-action@v5
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=registry,ref=${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest
cache-to: type=inline
deploy:
needs: build-and-push
runs-on: ubuntu-latest
steps:
- name: Setup Tailscale
uses: tailscale/github-action@v2
with:
oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }}
oauth-secret: ${{ secrets.TS_OAUTH_SECRET }}
tags: tag:ci
- name: Set kubeconfig
run: |
mkdir -p ~/.kube
echo "${{ secrets.TAILSCALE_KUBECONFIG }}" | base64 -d > ~/.kube/config
# Skip TLS verification for Tailscale IP connection
kubectl config set-cluster default --insecure-skip-tls-verify=true
- name: Deploy to K3s
run: |
# Get current timestamp in ISO8601 format
DEPLOYED_AT=$(date -u +"%Y-%m-%dT%H:%M:%SZ")
# Create a temporary patch file with the deployment timestamp
cat > /tmp/deployed-at-patch.yaml <<EOF
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: aprs
namespace: aprs
spec:
template:
spec:
containers:
- name: aprs
env:
- name: DEPLOYED_AT
value: "$DEPLOYED_AT"
EOF
# Apply the patch to set the deployment timestamp
kubectl patch statefulset aprs -n aprs --patch-file=/tmp/deployed-at-patch.yaml
# Update the image
kubectl set image statefulset/aprs aprs=${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest -n aprs
# Force a rollout to ensure latest image is pulled
kubectl rollout restart statefulset/aprs -n aprs
echo "Deployment initiated with timestamp $DEPLOYED_AT - not waiting for rollout to complete"