stages: - build - deploy variables: CACHIX_CACHE: "towerops" # Nix configuration NIX_CONFIG: | experimental-features = nix-command flakes substituters = https://cache.nixos.org https://towerops.cachix.org trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= towerops.cachix.org-1:YOUR_PUBLIC_KEY_HERE workflow: auto_cancel: on_new_commit: interruptible build: stage: build interruptible: true tags: - nix # Requires GitLab Runner with Nix installed image: nixos/nix:latest # Or use a custom runner with NixOS before_script: # Install and authenticate Cachix - nix-env -iA cachix -f https://cachix.org/api/v1/install - echo "$CACHIX_AUTH_TOKEN" | cachix authtoken - cachix use $CACHIX_CACHE script: # Build Docker image using Nix - nix build .#dockerImage --print-build-logs --accept-flake-config # Load image into Docker (requires Docker socket mounted in runner) - nix-shell -p docker --run "docker load < result" # Tag the image - IMAGE_TAG=$(nix-shell -p docker --run "docker images --format '{{.Repository}}:{{.Tag}}' | grep registry.gitlab.com/towerops/towerops | head -1") - nix-shell -p docker --run "docker tag $IMAGE_TAG $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA" - nix-shell -p docker --run "docker tag $IMAGE_TAG $CI_REGISTRY_IMAGE:latest" # Login and push to GitLab registry - echo "$CI_REGISTRY_PASSWORD" | nix-shell -p docker --run "docker login -u $CI_REGISTRY_USER --password-stdin $CI_REGISTRY" - nix-shell -p docker --run "docker push $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA" - nix-shell -p docker --run "docker push $CI_REGISTRY_IMAGE:latest" # Push to Cachix for future builds - nix path-info --json .#dockerImage | jq -r '.[].path' | cachix push $CACHIX_CACHE rules: - if: $CI_COMMIT_BRANCH == "main" cache: key: nix-store paths: - .nix-cache/ deploy: stage: deploy needs: - job: build artifacts: false tags: - home image: name: bitnami/kubectl:latest entrypoint: [""] script: - kubectl config get-contexts - kubectl config use-context towerops/towerops:home-cluster-agent # Set deployment timestamp (ISO 8601 format in UTC) - DEPLOY_TIMESTAMP=$(date -u +"%Y-%m-%dT%H:%M:%SZ") - echo "Deploying at $DEPLOY_TIMESTAMP" # Deploy new version (migrations run on app start) - kubectl set image deployment/towerops towerops=$CI_REGISTRY_IMAGE:$CI_COMMIT_SHA -n towerops - kubectl set env deployment/towerops DEPLOY_TIMESTAMP=$DEPLOY_TIMESTAMP -n towerops # Don't wait for rollout completion - let Kubernetes handle it asynchronously environment: name: production kubernetes: namespace: towerops rules: - if: $CI_COMMIT_BRANCH == "main"