Runner AWS auth #42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build & Deploy | |
| on: | |
| push: | |
| branches: | |
| - main | |
| - images/ECR | |
| workflow_dispatch: | |
| jobs: | |
| build-backend: | |
| if: github.event_name == 'workflow_dispatch' || contains(join(github.event.commits.*.modified, ' '), 'backend/') | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Configure AWS credentials | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | |
| aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
| aws-region: eu-west-1 | |
| - name: Log in to Amazon ECR | |
| uses: aws-actions/amazon-ecr-login@v2 | |
| - name: Build backend image | |
| run: | | |
| docker build -t 620914207029.dkr.ecr.eu-west-1.amazonaws.com/movie_api:movie-api -f backend/Dockerfile ./backend | |
| - name: Push backend image | |
| run: | | |
| docker push 620914207029.dkr.ecr.eu-west-1.amazonaws.com/movie_api:movie-api | |
| build-frontend: | |
| if: github.event_name == 'workflow_dispatch' || contains(join(github.event.commits.*.modified, ' '), 'frontend/') | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Configure AWS credentials | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | |
| aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
| aws-region: eu-west-1 | |
| - name: Log in to Amazon ECR | |
| uses: aws-actions/amazon-ecr-login@v2 | |
| - name: Build frontend image | |
| run: | | |
| docker build -t 620914207029.dkr.ecr.eu-west-1.amazonaws.com/movie_api:frontend -f frontend/Dockerfile ./frontend | |
| - name: Push frontend image | |
| run: | | |
| docker push 620914207029.dkr.ecr.eu-west-1.amazonaws.com/movie_api:frontend | |
| build-gateway: | |
| if: github.event_name == 'workflow_dispatch' || contains(join(github.event.commits.*.modified, ' '), 'gateway/') | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Configure AWS credentials | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | |
| aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
| aws-region: eu-west-1 | |
| - name: Log in to Amazon ECR | |
| uses: aws-actions/amazon-ecr-login@v2 | |
| - name: Build gateway image | |
| run: | | |
| docker build -t 620914207029.dkr.ecr.eu-west-1.amazonaws.com/movie_api:gateway -f gateway/Dockerfile ./gateway | |
| - name: Push gateway image | |
| run: | | |
| docker push 620914207029.dkr.ecr.eu-west-1.amazonaws.com/movie_api:gateway | |
| deploy: | |
| needs: [build-backend, build-frontend, build-gateway] | |
| runs-on: ubuntu-latest | |
| if: always() # Ensures deploy runs even if no images were built | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Set up SSH key | |
| uses: kielabokkie/ssh-key-and-known-hosts-action@v1 | |
| with: | |
| ssh-private-key: ${{ secrets.EC2_SSH_KEY }} | |
| ssh-host: ${{ vars.SSH_PROXY_HOST }} | |
| - name: Add SSH config | |
| run: | | |
| printf "Host ec2-docker\nHostName %s\nUser ubuntu\nIdentityFile ~/.ssh/id_rsa\nStrictHostKeyChecking no\nProxyCommand ssh -W %%h:%%p -q pure@xanderbit.cgitverse.com\n" "${{ secrets.EC2_HOST }}" > ~/.ssh/config | |
| chmod 600 ~/.ssh/config | |
| - name: Create .env file | |
| run: | | |
| echo "DB_HOST=${{ secrets.DB_HOST }}" >> .env | |
| echo "DB_PORT=${{ secrets.DB_PORT }}" >> .env | |
| echo "DB_NAME=${{ secrets.DB_NAME }}" >> .env | |
| echo "DB_USER=${{ secrets.DB_USER }}" >> .env | |
| echo "DB_PASSWORD=${{ secrets.DB_PASSWORD }}" >> .env | |
| echo "REDIS_HOST=${{ secrets.REDIS_HOST }}" >> .env | |
| echo "REDIS_PORT=${{ secrets.REDIS_PORT }}" >> .env | |
| echo "DATA_SOURCE_NAME=${{ secrets.DATA_SOURCE_NAME }}" >> .env | |
| - name: Configure AWS credentials | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | |
| aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
| aws-region: eu-west-1 | |
| - name: Log in to Amazon ECR | |
| id: login-ecr | |
| uses: aws-actions/amazon-ecr-login@v2 | |
| - name: Install Ansible | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y ansible | |
| - name: Upgrade Ansible | |
| run: | | |
| pip install --upgrade ansible | |
| - name: Run Ansible Playbook | |
| run: | | |
| ansible-playbook ansible/deploy.yml \ | |
| -i ansible/inventory.ini |