284 lines
9.1 KiB
YAML
284 lines
9.1 KiB
YAML
name: Production Deployment
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- production
|
|
|
|
env:
|
|
REGISTRY: git.mcintire.me
|
|
IMAGE_NAME: graham/towerops-web
|
|
|
|
jobs:
|
|
test-exunit:
|
|
name: Run ExUnit Tests
|
|
runs-on: ubuntu-22.04
|
|
env:
|
|
MIX_ENV: test
|
|
DATABASE_URL: ecto://postgres:postgres@postgres/towerops_test
|
|
|
|
services:
|
|
postgres:
|
|
image: timescale/timescaledb:latest-pg17
|
|
env:
|
|
POSTGRES_USER: postgres
|
|
POSTGRES_PASSWORD: postgres
|
|
POSTGRES_DB: towerops_test
|
|
options: >-
|
|
--health-cmd pg_isready
|
|
--health-interval 10s
|
|
--health-timeout 5s
|
|
--health-retries 5
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: https://github.com/actions/checkout@v4
|
|
|
|
- name: Set up Elixir
|
|
uses: https://github.com/erlef/setup-beam@v1
|
|
with:
|
|
version-type: strict
|
|
elixir-version: '1.18.1'
|
|
otp-version: '27.2'
|
|
|
|
- name: Cache Mix
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: ~/.mix
|
|
key: ${{ runner.os }}-mix-1.18.1-27.2
|
|
restore-keys: ${{ runner.os }}-mix-
|
|
|
|
- name: Cache deps
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: deps
|
|
key: ${{ runner.os }}-deps-${{ hashFiles('mix.lock') }}
|
|
restore-keys: ${{ runner.os }}-deps-
|
|
|
|
- name: Cache _build
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: _build
|
|
key: ${{ runner.os }}-build-${{ hashFiles('lib/**/*.ex') }}-${{ hashFiles('mix.lock') }}
|
|
restore-keys: ${{ runner.os }}-build-
|
|
|
|
- name: Install system dependencies
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y libssl-dev libsnmp-dev snmp-mibs-downloader postgresql-client
|
|
|
|
- name: Install dependencies
|
|
run: mix deps.get
|
|
|
|
- name: Compile (warnings as errors)
|
|
run: mix compile --warnings-as-errors
|
|
|
|
- name: Run tests
|
|
run: mix test
|
|
|
|
test-e2e:
|
|
name: Run E2E Tests
|
|
runs-on: ubuntu-22.04
|
|
env:
|
|
MIX_ENV: dev
|
|
DATABASE_URL: ecto://postgres:postgres@postgres/towerops_dev
|
|
|
|
services:
|
|
postgres:
|
|
image: timescale/timescaledb:latest-pg17
|
|
env:
|
|
POSTGRES_USER: postgres
|
|
POSTGRES_PASSWORD: postgres
|
|
POSTGRES_DB: towerops_dev
|
|
options: >-
|
|
--health-cmd pg_isready
|
|
--health-interval 10s
|
|
--health-timeout 5s
|
|
--health-retries 5
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: https://github.com/actions/checkout@v4
|
|
|
|
- name: Set up Elixir
|
|
uses: https://github.com/erlef/setup-beam@v1
|
|
with:
|
|
version-type: strict
|
|
elixir-version: '1.18.1'
|
|
otp-version: '27.2'
|
|
|
|
- name: Set up Node.js
|
|
uses: https://github.com/actions/setup-node@v4
|
|
with:
|
|
node-version: '20'
|
|
|
|
- name: Cache Mix
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: ~/.mix
|
|
key: ${{ runner.os }}-mix-1.18.1-27.2
|
|
restore-keys: ${{ runner.os }}-mix-
|
|
|
|
- name: Cache deps
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: deps
|
|
key: ${{ runner.os }}-deps-${{ hashFiles('mix.lock') }}
|
|
restore-keys: ${{ runner.os }}-deps-
|
|
|
|
- name: Cache _build
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: _build
|
|
key: ${{ runner.os }}-build-${{ hashFiles('lib/**/*.ex') }}-${{ hashFiles('mix.lock') }}
|
|
restore-keys: ${{ runner.os }}-build-
|
|
|
|
- name: Cache npm
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: e2e/node_modules
|
|
key: ${{ runner.os }}-npm-${{ hashFiles('e2e/package-lock.json') }}
|
|
restore-keys: ${{ runner.os }}-npm-
|
|
|
|
- name: Cache Playwright browsers
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: ~/.cache/ms-playwright
|
|
key: ${{ runner.os }}-playwright-${{ hashFiles('e2e/package-lock.json') }}
|
|
restore-keys: ${{ runner.os }}-playwright-
|
|
|
|
- name: Install system dependencies
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y libssl-dev libsnmp-dev snmp-mibs-downloader postgresql-client
|
|
|
|
- name: Install Elixir dependencies
|
|
run: mix deps.get
|
|
|
|
- name: Setup database
|
|
run: |
|
|
mix ecto.create
|
|
mix ecto.load --skip-if-loaded
|
|
mix run priv/repo/seeds_e2e.exs
|
|
|
|
- name: Start Phoenix server in background
|
|
run: |
|
|
mix phx.server > phoenix.log 2>&1 &
|
|
echo $! > phoenix.pid
|
|
echo "Phoenix server started with PID $(cat phoenix.pid)"
|
|
sleep 10
|
|
echo "=== Phoenix startup logs (after 10s) ==="
|
|
cat phoenix.log || echo "No logs yet"
|
|
echo "=== Process status ==="
|
|
ps aux | grep $(cat phoenix.pid) || echo "Process not found"
|
|
env:
|
|
SECRET_KEY_BASE: ${{ secrets.SECRET_KEY_BASE || 'dev_secret_key_base_for_testing_only_min_64_chars_required_here' }}
|
|
PHX_HOST: localhost
|
|
|
|
- name: Wait for Phoenix to start
|
|
run: |
|
|
timeout 60 bash -c 'until curl -f http://localhost:4000/health; do sleep 2; done'
|
|
|
|
- name: Show Phoenix logs on failure
|
|
if: failure()
|
|
run: |
|
|
echo "=== Full Phoenix logs ==="
|
|
cat phoenix.log || echo "No log file found"
|
|
echo "=== Process status ==="
|
|
ps aux | grep phoenix || echo "No Phoenix processes found"
|
|
|
|
- name: Install Playwright dependencies
|
|
working-directory: e2e
|
|
run: |
|
|
npm ci
|
|
npx playwright install --with-deps
|
|
|
|
- name: Run e2e tests
|
|
working-directory: e2e
|
|
run: npm test
|
|
env:
|
|
CI: true
|
|
TEST_USER_EMAIL: test@example.com
|
|
TEST_USER_PASSWORD: TestPassword123!
|
|
TEST_USER_TOTP_SECRET: JBSWY3DPEHPK3PXP
|
|
|
|
- name: Upload test results
|
|
if: failure()
|
|
uses: https://github.com/actions/upload-artifact@v4
|
|
with:
|
|
name: playwright-report
|
|
path: e2e/playwright-report/
|
|
retention-days: 7
|
|
|
|
build-and-deploy:
|
|
name: Build and Deploy to Production
|
|
runs-on: ubuntu-22.04
|
|
# Only require ExUnit tests to pass, e2e is optional
|
|
needs: [test-exunit]
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: https://github.com/actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0 # Need full history for git operations
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: https://github.com/docker/setup-buildx-action@v3
|
|
with:
|
|
buildkitd-flags: --allow-insecure-entitlement security.insecure
|
|
cleanup: true
|
|
|
|
- name: Log in to Container Registry
|
|
uses: https://github.com/docker/login-action@v3
|
|
with:
|
|
registry: ${{ secrets.REGISTRY_URL }}
|
|
username: ${{ secrets.REGISTRY_USER }}
|
|
password: ${{ secrets.REGISTRY_PASSWORD }}
|
|
|
|
- name: Generate image tag
|
|
id: tag
|
|
run: |
|
|
BRANCH=${GITHUB_REF#refs/heads/}
|
|
TIMESTAMP=$(date +%s)
|
|
SHORT_SHA=$(git rev-parse --short=7 HEAD)
|
|
TAG="${BRANCH}-${TIMESTAMP}-${SHORT_SHA}"
|
|
echo "tag=${TAG}" >> $GITHUB_OUTPUT
|
|
echo "Full image tag: ${TAG}"
|
|
|
|
- name: Build and push Docker image
|
|
uses: https://github.com/docker/build-push-action@v5
|
|
with:
|
|
context: .
|
|
file: k8s/Dockerfile
|
|
push: true
|
|
tags: |
|
|
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.tag.outputs.tag }}
|
|
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:production
|
|
cache-from: type=registry,ref=${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:buildcache
|
|
cache-to: type=registry,ref=${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:buildcache,mode=max
|
|
build-args: |
|
|
MIX_ENV=prod
|
|
|
|
- name: Update deployment manifest
|
|
run: |
|
|
IMAGE_TAG="${{ steps.tag.outputs.tag }}"
|
|
sed -i "s|image: ${REGISTRY}/${IMAGE_NAME}:.*|image: ${REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG}|g" k8s/deployment.yaml
|
|
|
|
git config user.name "Forgejo Actions"
|
|
git config user.email "actions@git.mcintire.me"
|
|
git add k8s/deployment.yaml
|
|
git commit -m "chore: update production image to ${IMAGE_TAG} [skip ci]" || echo "No changes to commit"
|
|
git push origin production
|
|
|
|
- name: Deployment summary
|
|
run: |
|
|
echo "### ✅ Production Deployment Complete" >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "**Image:** \`${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.tag.outputs.tag }}\`" >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "FluxCD will automatically apply the changes to the cluster." >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "**Monitor deployment:**" >> $GITHUB_STEP_SUMMARY
|
|
echo "\`\`\`bash" >> $GITHUB_STEP_SUMMARY
|
|
echo "kubectl rollout status deployment/towerops -n towerops" >> $GITHUB_STEP_SUMMARY
|
|
echo "\`\`\`" >> $GITHUB_STEP_SUMMARY
|