config: update new config #23
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Deploy to production | |
on: | |
push: | |
branches: [production] | |
# 2 | |
env: | |
REGISTRY: "registry.digitalocean.com/tulanh" | |
IMAGE_NAME: "service-api" | |
# 3 | |
jobs: | |
build_and_push: | |
runs-on: ubuntu-latest | |
defaults: | |
run: | |
working-directory: . | |
steps: | |
- name: Checkout the repo | |
uses: actions/checkout@v2 | |
- name: "Create env file" | |
run: | | |
touch .env | |
echo DB_SOURCE=${{ secrets.DB_SOURCE }} >> app.env | |
echo HTTP_SERVER_ADDRESS=${{ secrets.HTTP_SERVER_ADDRESS }} >> app.env | |
echo TOKEN_SYMMETRIC_KEY=${{ secrets.TOKEN_SYMMETRIC_KEY }} >> app.env | |
echo ACCESS_TOKEN_DURATION=${{ secrets.ACCESS_TOKEN_DURATION }} >> app.env | |
cat app.env | |
- name: Build container image | |
run: docker build -t $(echo $REGISTRY)/$(echo $IMAGE_NAME):$(echo $GITHUB_SHA | head -c7) . | |
- name: Install doctl | |
uses: digitalocean/action-doctl@v2 | |
with: | |
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }} | |
- name: Log in to DigitalOcean Container Registry with short-lived credentials | |
run: doctl registry login --expiry-seconds 600 | |
- name: Remove all old images | |
run: if [ ! -z "$(doctl registry repository list | grep "$(echo $IMAGE_NAME)")" ]; then doctl registry repository delete-manifest $(echo $IMAGE_NAME) $(doctl registry repository list-tags $(echo $IMAGE_NAME) | grep -o "sha.*") --force; else echo "No repository"; fi | |
- name: Push image to DigitalOcean Container Registry | |
run: docker push $(echo $REGISTRY)/$(echo $IMAGE_NAME):$(echo $GITHUB_SHA | head -c7) | |
deploy: | |
runs-on: ubuntu-latest | |
defaults: | |
run: | |
working-directory: . | |
needs: build_and_push | |
steps: | |
- name: Deploy to Digital Ocean droplet via SSH action | |
uses: appleboy/[email protected] | |
with: | |
host: ${{ secrets.HOST }} | |
username: ${{ secrets.USERNAME }} | |
key: ${{ secrets.SSHKEY }} | |
envs: IMAGE_NAME,REGISTRY,{{ secrets.DIGITALOCEAN_ACCESS_TOKEN }},GITHUB_SHA | |
script: | | |
# Login to registry | |
docker login -u ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }} -p ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }} registry.digitalocean.com | |
# Stop running container | |
docker stop $(echo $IMAGE_NAME) | |
# Remove old container | |
docker rm $(echo $IMAGE_NAME) | |
# Run a new container from a new image | |
docker run -d \ | |
--restart always \ | |
-p 8080:8080 \ | |
--name $(echo $IMAGE_NAME) \ | |
$(echo $REGISTRY)/$(echo $IMAGE_NAME):$(echo $GITHUB_SHA | head -c7) |