fix: images #42
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: CD | |
on: | |
push: | |
branches: | |
- prod | |
jobs: | |
cd-build: | |
runs-on: ubuntu-20.04 | |
steps: | |
- name: checkout | |
uses: actions/checkout@v3 | |
- name: Set up Node.js | |
uses: actions/setup-node@v3 | |
with: | |
node-version: 20 | |
- name: install pnpm | |
run: npm i -g pnpm | |
- name: Caching dependencies | |
id: cache | |
uses: actions/cache@v3 | |
with: | |
path: "**/node_modules" | |
key: ${{runner.os}}-node-${{ hashFiles('**/pnpm-lock.json')}} | |
restore-keys: | | |
${{ runner.os }}-node- | |
${{ runner.os }} | |
- name: Install package | |
if: steps.cache.outputs.cache-hit != 'true' | |
run: pnpm i --no-frozen-lockfile | |
- name: env set | |
run: | | |
touch .env | |
echo POSTGRESQL_DB=${{secrets.POSTGRESQL_DB}} >> .env | |
echo PORT=${{secrets.PORT}} >> .env | |
echo ORIGIN=${{secrets.ORIGIN}} >> .env | |
echo TESTING_TOKEN=${{secrets.TESTING_TOKEN}} >> .env | |
echo TESTING_PASSWORD=${{secrets.TESTING_PASSWORD}} >> .env | |
- name: prisma set | |
run: npx prisma generate --schema=src/prisma/schema.prisma | |
- name: docker | |
run: docker build --cache-from ${{ secrets.DOCKERHUB_USERNAME }}/admin-server:latest -t ${{ secrets.DOCKERHUB_USERNAME }}/admin-server:latest -f ./dockerfile ./ | |
- name: Login to Docker Hub | |
uses: docker/login-action@v1 | |
with: | |
username: ${{secrets.DOCKERHUB_USERNAME}} | |
password: ${{secrets.DOCKERHUB_PASSWORD}} | |
- name: push to Docker Hub | |
run: docker push ${{secrets.DOCKERHUB_USERNAME}}/admin-server:latest | |
- name: Get GitHub Actions IP | |
id: ip | |
uses: haythem/[email protected] | |
- name: configuring | |
uses: aws-actions/configure-aws-credentials@v4 | |
with: | |
aws-region: ${{ secrets.AWS_REGION }} | |
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY }} | |
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
- name: Add Github Actions IP to Security group | |
env: | |
AWS_DEFAULT_REGION: ${{ secrets.AWS_REGION }} | |
run: | | |
aws ec2 authorize-security-group-ingress \ | |
--group-id ${{ secrets.AWS_EC2_SG_ID }} \ | |
--protocol tcp --port 22 \ | |
--cidr ${{ steps.ip.outputs.ipv4 }}/32 \ | |
- name: EC2 Production Server Deploy | |
uses: appleboy/ssh-action@master | |
with: | |
host: ${{ secrets.PROD_AWS_HOST }} | |
port: ${{ secrets.AWS_PORT }} | |
username: ${{ secrets.PROD_AWS_USERNAME }} | |
key: ${{ secrets.PROD_AWS_SSH_KEY }} | |
script: | | |
sudo groupadd docker | |
sudo usermod -aG docker $USER | |
echo "${{ secrets.DOCKERHUB_PASSWORD }}" | docker login -u ${{ secrets.DOCKERHUB_USERNAME }} --password-stdin | |
sudo docker stop $(sudo docker ps -q --filter "ancestor=${{ secrets.DOCKERHUB_USERNAME }}/${{ secrets.DOCKERHUB_PASSWORD }}") | |
sudo docker rm -f $(sudo docker ps -a -f status=exited -q) | |
sudo docker pull ${{ secrets.DOCKERHUB_USERNAME }}/admin-server:latest | |
sudo docker run -d -p ${{ secrets.PORT }}:${{ secrets.PORT }} ${{ secrets.DOCKERHUB_USERNAME }}/admin-server:latest | |
sudo docker image prune -f | |
- name: Remove Github Actions IP From Security Group | |
run: | | |
aws ec2 revoke-security-group-ingress \ | |
--group-id ${{ secrets.AWS_EC2_SG_ID }} \ | |
--protocol tcp --port 22 \ | |
--cidr ${{ steps.ip.outputs.ipv4 }}/32 |