nxtgauge-backend-rust/.github/workflows/build-and-deploy-ghcr.yml
Workflow config file is invalid. Please check your config file: yaml: line 57: could not find expected ':'
2026-06-14 22:57:54 +05:30

172 lines
6.3 KiB
YAML

name: build-and-deploy-ghcr
on:
push:
branches:
- main
- high-performance
workflow_dispatch:
permissions:
contents: read
packages: write
env:
K8S_NAMESPACE: nxtgauge
GITOPS_REPO: Traceworks2023/nxtgauge-gitops
jobs:
detect-changes:
runs-on: ubuntu-latest
outputs:
services: ${{ steps.detect.outputs.services }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 2
- name: Detect changed services
id: detect
shell: bash
run: |
set -euo pipefail
ALL_SERVICES='gateway users companies jobs leads job-seekers customers payments employees photographers makeup-artists tutors developers video-editors graphic-designers social-media-managers fitness-trainers catering-services ugc-content-creators cron'
if git rev-parse --verify HEAD^ >/dev/null 2>&1; then
CHANGED_FILES="$(git diff --name-only HEAD^ HEAD)"
else
CHANGED_FILES="$(git ls-files)"
fi
LAST_COMMIT_MSG="$(git log -1 --pretty=%B | tr '\n' ' ')"
FORCE_FULL_BUILD=false
if echo "$LAST_COMMIT_MSG" | grep -Eiq 'trigger build|force build|rebuild all'; then
FORCE_FULL_BUILD=true
elif echo "$CHANGED_FILES" | grep -Eq '^(\.github/workflows/|\.forgejo/workflows/|Dockerfile|Cargo\.toml|Cargo\.lock|crates/|scripts/)'; then
FORCE_FULL_BUILD=true
fi
if [ "$FORCE_FULL_BUILD" = true ]; then
SERVICES_JSON="$(printf '%s\n' $ALL_SERVICES | python3 -c 'import json,sys; print(json.dumps([line.strip() for line in sys.stdin if line.strip()]))')"
echo "services=$SERVICES_JSON" >> "$GITHUB_OUTPUT"
exit 0
fi
SERVICES_JSON="$(printf '%s\n' "$CHANGED_FILES" | python3 -c '
import json
import sys
mapping = {
"apps/gateway/": "gateway",
"apps/users/": "users",
"apps/companies/": "companies",
"apps/jobs/": "jobs",
"apps/leads/": "leads",
"apps/job_seekers/": "job-seekers",
"apps/customers/": "customers",
"apps/payments/": "payments",
"apps/employees/": "employees",
"apps/photographers/": "photographers",
"apps/makeup_artists/": "makeup-artists",
"apps/tutors/": "tutors",
"apps/developers/": "developers",
"apps/video_editors/": "video-editors",
"apps/graphic_designers/": "graphic-designers",
"apps/social_media_managers/": "social-media-managers",
"apps/fitness_trainers/": "fitness-trainers",
"apps/catering_services/": "catering-services",
"apps/ugc_content_creators/": "ugc-content-creators",
"apps/cron/": "cron",
}
services = []
seen = set()
for raw in sys.stdin:
line = raw.strip()
for prefix, service in mapping.items():
if line.startswith(prefix) and service not in seen:
seen.add(service)
services.append(service)
break
print(json.dumps(services))
')"
echo "services=$SERVICES_JSON" >> "$GITHUB_OUTPUT"
build-deploy:
needs: detect-changes
if: needs.detect-changes.outputs.services != '[]'
runs-on: ubuntu-latest
strategy:
fail-fast: false
max-parallel: 1
matrix:
service: ${{ fromJSON(needs.detect-changes.outputs.services) }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to GHCR
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ secrets.GHCR_USERNAME }}
password: ${{ secrets.DEPLOY_GITHUB_TOKEN }}
- name: Build and push image
id: build
uses: docker/build-push-action@v6
with:
context: .
file: Dockerfile.simple
push: true
platforms: linux/amd64
build-args: |
SERVICE_NAME=${{ matrix.service }}
tags: ghcr.io/traceworks2023/nxtgauge-rust-${{ matrix.service }}:${{ github.sha }}
- name: Configure kubeconfig
run: |
set -euo pipefail
mkdir -p ~/.kube
printf '%s' '${{ secrets.KUBE_CONFIG_DATA }}' | base64 -d > ~/.kube/config
chmod 600 ~/.kube/config
- name: Install kubectl
uses: azure/setup-kubectl@v4
- name: Deploy to Kubernetes
env:
GHCR_USERNAME: ${{ secrets.GHCR_USERNAME }}
GHCR_TOKEN: ${{ secrets.DEPLOY_GITHUB_TOKEN }}
run: |
set -euo pipefail
deployment="nxtgauge-rust-${{ matrix.service }}"
container="${{ matrix.service }}"
image_ref="ghcr.io/traceworks2023/nxtgauge-rust-${{ matrix.service }}@${{ steps.build.outputs.digest }}"
kubectl -n "$K8S_NAMESPACE" create secret docker-registry ghcr-regcred --docker-server=ghcr.io --docker-username="$GHCR_USERNAME" --docker-password="$GHCR_TOKEN" --dry-run=client -o yaml | kubectl apply -f -
kubectl -n "$K8S_NAMESPACE" patch deployment "$deployment" --type merge -p '{"spec":{"template":{"spec":{"imagePullSecrets":[{"name":"ghcr-regcred"}]}}}}'
kubectl -n "$K8S_NAMESPACE" set image deployment/"$deployment" "$container"="$image_ref"
kubectl -n "$K8S_NAMESPACE" rollout status deployment/"$deployment" --timeout=15m
- name: Sync GitOps release
env:
GITOPS_TOKEN: ${{ secrets.DEPLOY_GITHUB_TOKEN }}
run: |
set -euo pipefail
git clone "https://${{ secrets.GHCR_USERNAME }}:${GITOPS_TOKEN}@github.com/${GITOPS_REPO}.git" /tmp/nxtgauge-gitops
cd /tmp/nxtgauge-gitops
./scripts/set-backend-rust-release.sh "${{ matrix.service }}" "${{ steps.build.outputs.digest }}"
if git diff --quiet; then
echo "GitOps repo already up to date."
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git add apps/nxtgauge-backend-rust/overlays/prod/backend-release-state.tsv apps/nxtgauge-backend-rust/overlays/prod/release-patches.yaml apps/nxtgauge-backend-rust/overlays/prod/disabled-deployments.yaml
git commit -m "chore(gitops): deploy backend ${{ matrix.service }}@${{ github.sha }}"
git pull --rebase origin main
git push origin HEAD:main