Podman fails with 'cannot clone: Operation not permitted' on this runner because it cannot create namespaces. The runner environment lacks the capabilities for namespace-based container isolation. Solution: Add --isolation=chroot flag to use chroot instead of namespaces. This works in restricted environments without CAP_SYS_ADMIN or user namespace support. Trade-off: Chroot isolation is slower but functional on unprivileged runners. Reviewed-on: graham/towerops-web#224
174 lines
5.4 KiB
YAML
174 lines
5.4 KiB
YAML
name: Production Deployment
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
|
|
env:
|
|
REGISTRY: git.mcintire.me
|
|
IMAGE_NAME: graham/towerops-web
|
|
|
|
jobs:
|
|
test-exunit:
|
|
name: Run ExUnit Tests
|
|
runs-on: ubuntu-22.04
|
|
env:
|
|
MIX_ENV: test
|
|
DATABASE_URL: ecto://postgres:postgres@postgres/towerops_test
|
|
|
|
services:
|
|
postgres:
|
|
image: timescale/timescaledb:latest-pg17
|
|
env:
|
|
POSTGRES_USER: postgres
|
|
POSTGRES_PASSWORD: postgres
|
|
POSTGRES_DB: towerops_test
|
|
options: >-
|
|
--health-cmd pg_isready
|
|
--health-interval 10s
|
|
--health-timeout 5s
|
|
--health-retries 5
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: https://github.com/actions/checkout@v4
|
|
|
|
- name: Set up Elixir
|
|
uses: https://github.com/erlef/setup-beam@v1
|
|
with:
|
|
version-type: strict
|
|
elixir-version: '1.18.1'
|
|
otp-version: '27.2'
|
|
|
|
- name: Cache Mix
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: ~/.mix
|
|
key: ${{ runner.os }}-mix-1.18.1-27.2
|
|
restore-keys: ${{ runner.os }}-mix-
|
|
|
|
- name: Cache deps
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: deps
|
|
key: ${{ runner.os }}-deps-${{ hashFiles('mix.lock') }}
|
|
restore-keys: ${{ runner.os }}-deps-
|
|
|
|
- name: Cache _build
|
|
uses: https://github.com/actions/cache@v4
|
|
with:
|
|
path: _build
|
|
key: ${{ runner.os }}-build-v2-${{ hashFiles('lib/**/*.ex') }}-${{ hashFiles('mix.lock') }}
|
|
restore-keys: ${{ runner.os }}-build-v2-
|
|
|
|
- name: Install system dependencies
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y libssl-dev libsnmp-dev snmp-mibs-downloader postgresql-client
|
|
|
|
- name: Install dependencies
|
|
run: mix deps.get
|
|
|
|
- name: Compile C NIF
|
|
run: make -C c_src
|
|
|
|
- name: Compile (warnings as errors)
|
|
run: mix compile --warnings-as-errors
|
|
|
|
- name: Run tests
|
|
run: mix test
|
|
|
|
build-image:
|
|
name: Build and Push Docker Image
|
|
runs-on: ubuntu-22.04
|
|
needs: [test-exunit]
|
|
outputs:
|
|
image_tag: ${{ steps.tag.outputs.tag }}
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: https://github.com/actions/checkout@v4
|
|
|
|
- name: Generate image tag
|
|
id: tag
|
|
run: |
|
|
BRANCH=${GITHUB_REF#refs/heads/}
|
|
TIMESTAMP=$(date +%s)
|
|
SHORT_SHA=$(git rev-parse --short=7 HEAD | cut -c1-7)
|
|
TAG="${BRANCH}-${TIMESTAMP}-${SHORT_SHA}"
|
|
echo "tag=${TAG}" >> $GITHUB_OUTPUT
|
|
echo "Full image tag: ${TAG}"
|
|
|
|
- name: Install Podman
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y podman
|
|
|
|
- name: Build and push with Podman
|
|
run: |
|
|
IMAGE_TAG="${{ steps.tag.outputs.tag }}"
|
|
|
|
# Build with chroot isolation (no namespaces required)
|
|
podman build \
|
|
--isolation=chroot \
|
|
--build-arg MIX_ENV=prod \
|
|
--file k8s/Dockerfile \
|
|
--tag "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${IMAGE_TAG}" \
|
|
--tag "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:production" \
|
|
.
|
|
|
|
# Login and push both tags
|
|
echo "${{ secrets.REGISTRY_PASSWORD }}" | podman login \
|
|
--username "${{ secrets.REGISTRY_USER }}" \
|
|
--password-stdin \
|
|
"${{ secrets.REGISTRY_URL }}"
|
|
|
|
podman push "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${IMAGE_TAG}"
|
|
podman push "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:production"
|
|
|
|
update-manifest:
|
|
name: Update Deployment Manifest
|
|
runs-on: ubuntu-22.04
|
|
needs: [build-image]
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: https://github.com/actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Update deployment manifest
|
|
run: |
|
|
IMAGE_TAG="${{ needs.build-image.outputs.image_tag }}"
|
|
|
|
git config user.name "Forgejo Actions"
|
|
git config user.email "actions@git.mcintire.me"
|
|
|
|
git fetch origin production
|
|
git checkout production
|
|
git pull origin production --rebase
|
|
git merge origin/main --no-edit
|
|
|
|
sed -i "s|image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:.*|image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${IMAGE_TAG}|g" k8s/deployment.yaml
|
|
|
|
git add k8s/deployment.yaml
|
|
if git diff --staged --quiet; then
|
|
echo "No changes to deployment.yaml"
|
|
else
|
|
git commit -m "chore: update production image to ${IMAGE_TAG} [skip ci]"
|
|
git push origin production
|
|
fi
|
|
|
|
- name: Deployment summary
|
|
run: |
|
|
echo "### ✅ Production Deployment Complete" >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "**Image:** \`${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ needs.build-image.outputs.image_tag }}\`" >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "FluxCD will automatically apply the changes to the cluster." >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "**Monitor deployment:**" >> $GITHUB_STEP_SUMMARY
|
|
echo "\`\`\`bash" >> $GITHUB_STEP_SUMMARY
|
|
echo "kubectl rollout status deployment/towerops -n towerops" >> $GITHUB_STEP_SUMMARY
|
|
echo "\`\`\`" >> $GITHUB_STEP_SUMMARY
|