Repository navigation
105 lines (98 loc) · 4.29 KB
/
Copy pathdeploy-dev2.yml
File metadata and controls
105 lines (98 loc) · 4.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
# Ship every merge to dev2, where outreachgraph.com runs since it left Railway (which
# deployed on merge by itself). The box pulls the merged commit, rebuilds the
# image(s) from this repo and restarts the compose stack under
# /home/anthony/www/outreachgraph.com. Generated by cli-tools/dev2/dev2-site scaffold.
name: Deploy to dev2
on:
push:
branches: [main]
workflow_dispatch:
inputs:
ref:
description: Git ref to deploy (defaults to the pushed commit)
required: false
type: string
concurrency:
group: deploy-dev2
cancel-in-progress: false
jobs:
deploy:
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
# ${{ }} values go through env, never straight into a run: body.
- name: Resolve target revision
id: rev
env:
REF: ${{ inputs.ref || github.sha }}
run: echo "sha=$REF" >> "$GITHUB_OUTPUT"
- name: Set up ssh
env:
SSH_KEY: ${{ secrets.DEV2_SSH_KEY }}
KNOWN_HOSTS: ${{ secrets.DEV2_KNOWN_HOSTS }}
run: |
install -d -m 700 ~/.ssh
printf '%s\n' "$SSH_KEY" > ~/.ssh/id_ed25519
chmod 600 ~/.ssh/id_ed25519
printf '%s\n' "$KNOWN_HOSTS" > ~/.ssh/known_hosts
chmod 644 ~/.ssh/known_hosts
# app.env on the box is the runtime's only env and nothing else writes it, so a
# secret a new feature needs ships as a repo secret and lands here, reviewable
# and repeatable, instead of somebody editing dev2 by hand. Additive: an unset
# secret is skipped, an unchanged value writes nothing, and a change keeps a
# numbered backup of app.env first. Values travel on stdin, never in argv.
- name: Sync secrets into app.env
env:
DEV2_USER: ${{ secrets.DEV2_USER }}
DEV2_HOST: ${{ secrets.DEV2_HOST }}
VALUESERP_API_KEY: ${{ secrets.VALUESERP_API_KEY }}
CHOVY_CAMPAIGN_SECRET: ${{ secrets.CHOVY_CAMPAIGN_SECRET }}
PDL_API_KEY: ${{ secrets.PDL_API_KEY }}
SERPER_API_KEY: ${{ secrets.SERPER_API_KEY }}
HUNTER_API_KEY: ${{ secrets.HUNTER_API_KEY }}
CONTACTOUT_API_KEY: ${{ secrets.CONTACTOUT_API_KEY }}
run: |
lines=""
for key in VALUESERP_API_KEY CHOVY_CAMPAIGN_SECRET PDL_API_KEY SERPER_API_KEY HUNTER_API_KEY CONTACTOUT_API_KEY; do
value=$(printenv "$key" || true)
[ -n "$value" ] && lines="$lines$key=$value"$'\n'
done
if [ -z "$lines" ]; then echo "no secrets to sync"; exit 0; fi
printf '%s' "$lines" | ssh -o BatchMode=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=20 "$DEV2_USER@$DEV2_HOST" '
set -eu
env_file=/home/anthony/www/outreachgraph.com/app.env
tmp=$(mktemp); cp "$env_file" "$tmp"; changed=""
while IFS= read -r line; do
[ -n "$line" ] || continue
key=${line%%=*}
if grep -qxF -- "$line" "$tmp"; then continue; fi
grep -v "^$key=" "$tmp" > "$tmp.next" || true
printf "%s\n" "$line" >> "$tmp.next"
mv "$tmp.next" "$tmp"; changed="$changed $key"
done
if [ -n "$changed" ]; then
n=1; while [ -e "$env_file.bak-$(printf %03d $n)" ]; do n=$((n+1)); done
cp -p "$env_file" "$env_file.bak-$(printf %03d $n)"
cat "$tmp" > "$env_file"; chmod 600 "$env_file"
echo "app.env updated:$changed"
else
echo "app.env already current"
fi
rm -f "$tmp"
'
- name: Deploy
env:
DEV2_USER: ${{ secrets.DEV2_USER }}
DEV2_HOST: ${{ secrets.DEV2_HOST }}
SHA: ${{ steps.rev.outputs.sha }}
run: |
ssh -o BatchMode=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=20 "$DEV2_USER@$DEV2_HOST" \
/home/anthony/www/outreachgraph.com/deploy-app.sh "$SHA"
- name: Verify the site answers
run: |
for i in $(seq 1 10); do
code=$(curl -s -o /dev/null -w '%{http_code}' "https://outreachgraph.com/health/live" || true)
case "$code" in 2*|3*|401|403) echo "outreachgraph.com $code"; exit 0;; esac
echo "attempt $i: $code"; sleep 10
done
echo "outreachgraph.com never answered"; exit 1