-
Notifications
You must be signed in to change notification settings - Fork 8
馃懛 Add CICD for deployment to OpenShift #64
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
31 commits
Select commit
Hold shift + click to select a range
544512a
馃殌 Move deploy scripts to kustomize format
taagarwa-rh e5b70f4
馃懛 Add openshift deploy workflow
taagarwa-rh b4e95b3
馃懛 Add workflow for stage sync
taagarwa-rh fd4a30d
馃挌 Add MinIO deployment to deploy CI
taagarwa-rh abaec82
馃摑 Update documentation for new deployment setup
taagarwa-rh 4322d45
馃悰 Add missing key selection for google SA
taagarwa-rh d3bc57c
馃殌 Fix image tags and envvars using overlays
taagarwa-rh 901248d
馃敡 Update bumpversion config to point at new paths
taagarwa-rh 19c7f65
馃懛 Update build-push CI to push stage tag
taagarwa-rh d9a9cb5
馃悰 Do not notify or update intake in stage env
taagarwa-rh b40f1b7
馃挌 Fix issues in CI
taagarwa-rh 0ec7cf2
馃悰 Use secret.example.yaml for minio as well
taagarwa-rh 78e5a94
馃悰 Ignore minio secret
taagarwa-rh 014a23a
馃摑 Update docs for minio secret
taagarwa-rh fb37632
馃悰 Fix deployment paths
taagarwa-rh 3c07bef
馃摑 Fix yml -> yaml
taagarwa-rh e15b05f
馃悰 Run stage sync on merged branches targeting main
taagarwa-rh 45b5ca0
馃悰 Verify intake poller secret before applying
taagarwa-rh 09df672
馃悰 Remove secret files from kustomize
taagarwa-rh afe0dd0
馃悰 Update rollout strategy for minio
taagarwa-rh d485494
馃悰 Remove secret.yaml from minio kustomization
taagarwa-rh c87a854
馃摑 Remove reference to intake-poller-google-sa
taagarwa-rh 0228ec7
馃悰 Fix environment selection when merging to main
taagarwa-rh 4fd84fb
馃悰 Raise an error when ENVIRONMENT is not supported
taagarwa-rh 295669c
馃殮 Move is_stage_environment to utils.py
taagarwa-rh 6b30965
馃摑 Add ENVIRONMENT to .env.example
taagarwa-rh 3bd993c
馃摑 Update README
taagarwa-rh 6a6ae10
馃挌 Keep nebius and intake poller optional in CI
taagarwa-rh 126026a
馃悰 Update github CI deploy
taagarwa-rh cc67e87
馃悰 Fix ENVIRONMENT patching in deploy
taagarwa-rh 8e27a4e
馃悰 Fix stage rollouts from CI
taagarwa-rh File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,6 +4,7 @@ on: | |
| push: | ||
| branches: | ||
| - main | ||
| - stage | ||
| - 'CICD*' | ||
| tags: | ||
| - 'v*' | ||
|
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,76 @@ | ||
| name: Deploy to OpenShift | ||
|
|
||
| on: | ||
| workflow_run: | ||
| workflows: | ||
| - Build and Push Container Image | ||
| types: | ||
| - completed | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| deploy: | ||
| if: >- | ||
| github.event.workflow_run.conclusion == 'success' && | ||
| (github.event.workflow_run.head_branch == 'main' || | ||
| github.event.workflow_run.head_branch == 'stage' || | ||
| startsWith(github.event.workflow_run.head_branch, 'v')) | ||
| runs-on: ubuntu-latest | ||
| environment: ${{ (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) && 'production' || 'stage' }} | ||
| env: | ||
| OVERLAY: ${{ (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) && 'prod' || 'stage' }} | ||
| NAMESPACE: ${{ (github.event.workflow_run.head_branch == 'main' || startsWith(github.event.workflow_run.head_branch, 'v')) && vars.PROD_NAMESPACE || vars.STAGE_NAMESPACE }} | ||
| OPENSHIFT_SERVER: ${{ secrets.OPENSHIFT_SERVER }} | ||
| OPENSHIFT_TOKEN: ${{ secrets.OPENSHIFT_TOKEN }} | ||
|
|
||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 | ||
| with: | ||
| ref: ${{ github.event.workflow_run.head_sha }} | ||
|
|
||
| - name: Log in to OpenShift | ||
| uses: redhat-actions/oc-login@v1 | ||
| with: | ||
| openshift_server_url: ${{ env.OPENSHIFT_SERVER }} | ||
| openshift_token: ${{ env.OPENSHIFT_TOKEN }} | ||
| namespace: ${{ env.NAMESPACE }} | ||
|
|
||
| - name: Verify application Secrets | ||
| shell: bash | ||
| run: | | ||
| set -euo pipefail | ||
|
|
||
| test -n "$NAMESPACE" | ||
| for secret in harbor-minio job-queue-secret; do | ||
| oc -n "$NAMESPACE" get secret "$secret" >/dev/null | ||
| done | ||
| if oc -n "$NAMESPACE" get secret intake-poller-secret >/dev/null 2>&1; then | ||
| for key in ALLOW_INSECURE_QUEUE_HTTP SMTP_HOST SMTP_PORT SMTP_STARTTLS; do | ||
| test -n "$(oc -n "$NAMESPACE" get secret intake-poller-secret -o "jsonpath={.data.$key}")" | ||
| done | ||
| fi | ||
|
|
||
| - name: Apply MinIO | ||
| run: oc apply -k deploy/minio/overlays/$OVERLAY -n "$NAMESPACE" | ||
|
|
||
| - name: Wait for MinIO rollout | ||
| run: oc rollout status deployment/harbor-minio -n "$NAMESPACE" --timeout=10m | ||
|
|
||
| - name: Apply job queue | ||
| run: oc apply -k deploy/job-queue/overlays/$OVERLAY -n "$NAMESPACE" | ||
|
|
||
| - name: Restart stage job queue | ||
| if: env.OVERLAY == 'stage' | ||
| run: oc rollout restart deployment/job-queue -n "$NAMESPACE" | ||
|
|
||
| - name: Wait for job queue rollout | ||
| run: oc rollout status deployment/job-queue -n "$NAMESPACE" --timeout=10m | ||
|
|
||
| - name: Apply intake poller | ||
| run: | | ||
| if oc -n "$NAMESPACE" get secret intake-poller-secret >/dev/null 2>&1; then | ||
| oc apply -k deploy/intake-poller/overlays/$OVERLAY -n "$NAMESPACE" | ||
| fi |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,34 @@ | ||
| name: Sync stage with main | ||
|
|
||
| on: | ||
| pull_request_target: | ||
| branches: | ||
| - main | ||
| types: | ||
| - closed | ||
|
|
||
| permissions: | ||
| contents: write | ||
|
|
||
| concurrency: | ||
| group: sync-stage | ||
| cancel-in-progress: false | ||
|
|
||
| jobs: | ||
| sync: | ||
| if: github.event.pull_request.merged == true | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Check out stage | ||
| uses: actions/checkout@v4 | ||
| with: | ||
| repository: ${{ github.repository }} | ||
| ref: refs/heads/stage | ||
| fetch-depth: 0 | ||
|
|
||
| - name: Merge main into stage | ||
| run: | | ||
| git config user.name "github-actions[bot]" | ||
| git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | ||
| git merge origin/main --no-edit | ||
| git push origin HEAD:stage | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.