ajustes novos
This commit is contained in:
parent
6128e166a8
commit
6c8c43e0e6
1 changed files with 22 additions and 52 deletions
|
|
@ -9,58 +9,43 @@ on:
|
||||||
env:
|
env:
|
||||||
REGISTRY: pipe.gohorsejobs.com
|
REGISTRY: pipe.gohorsejobs.com
|
||||||
IMAGE_NAMESPACE: bohessefm
|
IMAGE_NAMESPACE: bohessefm
|
||||||
DOCKER_MTU: 1200
|
# O DOCKER_HOST aponta para o seu container sidecar 'docker' no mesmo pod
|
||||||
|
DOCKER_HOST: tcp://localhost:2375
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build-and-push:
|
build-and-push:
|
||||||
|
# As labels aqui batem com o que você registrou no seu Deployment
|
||||||
runs-on:
|
runs-on:
|
||||||
- self-hosted
|
|
||||||
- ubuntu-latest
|
- ubuntu-latest
|
||||||
container:
|
defaults:
|
||||||
image: docker:24.0.7-dind
|
run:
|
||||||
options: --privileged
|
shell: sh
|
||||||
env:
|
|
||||||
# Forçamos o uso do localhost para evitar erros de DNS/Lookup
|
|
||||||
DOCKER_HOST: tcp://localhost:2375
|
|
||||||
DOCKER_TLS_CERTDIR: ""
|
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Prepare Environment (MTU & Git & Docker Daemon)
|
# 1. Agora o Checkout funciona direto porque a imagem 'node:20-bookworm' tem Node!
|
||||||
run: |
|
|
||||||
# 1. Ajuste de Rede
|
|
||||||
ip link set dev eth0 mtu ${{ env.DOCKER_MTU }} || true
|
|
||||||
apk add --no-cache git
|
|
||||||
|
|
||||||
# 2. Inicia o Docker Daemon em background dentro do próprio container
|
|
||||||
# Isso garante que 'localhost:2375' funcione sem depender de DNS externo
|
|
||||||
nohup dockerd --host=tcp://localhost:2375 --host=unix:///var/run/docker.sock --mtu=${{ env.DOCKER_MTU }} &
|
|
||||||
|
|
||||||
# 3. Espera o Docker subir (retry loop)
|
|
||||||
timeout 30s sh -c 'until docker info >/dev/null 2>&1; do echo "Aguardando Docker..."; sleep 2; done'
|
|
||||||
|
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
run: |
|
uses: actions/checkout@v4
|
||||||
git config --global core.compression 0
|
|
||||||
git clone --depth 1 --branch dev https://${{ secrets.FORGEJO_TOKEN }}@pipe.gohorsejobs.com/${{ github.repository }}.git .
|
|
||||||
|
|
||||||
- name: Docker Login (Forgejo)
|
# 2. Garante que o Daemon do sidecar já acordou
|
||||||
|
- name: Wait for Docker
|
||||||
|
run: |
|
||||||
|
until docker info >/dev/null 2>&1; do echo "Aguardando Docker..."; sleep 1; done
|
||||||
|
|
||||||
|
- name: Docker login
|
||||||
run: |
|
run: |
|
||||||
# Autenticação usando o Token do Forgejo
|
|
||||||
echo "${{ secrets.FORGEJO_TOKEN }}" | docker login ${{ env.REGISTRY }} \
|
echo "${{ secrets.FORGEJO_TOKEN }}" | docker login ${{ env.REGISTRY }} \
|
||||||
-u ${{ env.IMAGE_NAMESPACE }} --password-stdin
|
-u ${{ env.IMAGE_NAMESPACE }} --password-stdin
|
||||||
|
|
||||||
- name: Build & Push Backend
|
- name: Build & Push Backend
|
||||||
run: |
|
run: |
|
||||||
docker build --build-arg DOCKER_MTU=${{ env.DOCKER_MTU }} \
|
docker build -t ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:${{ github.sha }} \
|
||||||
-t ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:${{ github.sha }} \
|
|
||||||
-t ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:latest ./backend
|
-t ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:latest ./backend
|
||||||
docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:${{ github.sha }}
|
docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:${{ github.sha }}
|
||||||
docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:latest
|
docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:latest
|
||||||
|
|
||||||
- name: Build & Push Backoffice
|
- name: Build & Push Backoffice
|
||||||
run: |
|
run: |
|
||||||
docker build --build-arg DOCKER_MTU=${{ env.DOCKER_MTU }} \
|
docker build -t ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:${{ github.sha }} \
|
||||||
-t ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:${{ github.sha }} \
|
|
||||||
-t ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:latest ./backoffice
|
-t ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:latest ./backoffice
|
||||||
docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:${{ github.sha }}
|
docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:${{ github.sha }}
|
||||||
docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:latest
|
docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:latest
|
||||||
|
|
@ -68,30 +53,16 @@ jobs:
|
||||||
deploy-to-k3s:
|
deploy-to-k3s:
|
||||||
needs: build-and-push
|
needs: build-and-push
|
||||||
runs-on:
|
runs-on:
|
||||||
- self-hosted
|
|
||||||
- ubuntu-latest
|
- ubuntu-latest
|
||||||
container:
|
|
||||||
image: alpine/k8s:1.30.0
|
|
||||||
steps:
|
steps:
|
||||||
- name: Fix Network & Install Git
|
|
||||||
run: |
|
|
||||||
ip link set dev eth0 mtu ${{ env.DOCKER_MTU }} || true
|
|
||||||
apk add --no-cache git
|
|
||||||
|
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
run: |
|
uses: actions/checkout@v4
|
||||||
git clone --depth 1 --branch dev https://${{ secrets.FORGEJO_TOKEN }}@pipe.gohorsejobs.com/${{ github.repository }}.git .
|
|
||||||
|
|
||||||
- name: Apply to K3s
|
- name: Deploy to K3s
|
||||||
run: |
|
run: |
|
||||||
mkdir -p $HOME/.kube
|
# O kubectl já funciona porque o ServiceAccount 'forgejo-deployer' é admin
|
||||||
echo "${{ secrets.KUBECONFIG }}" > $HOME/.kube/config
|
|
||||||
chmod 600 $HOME/.kube/config
|
|
||||||
export KUBECONFIG=$HOME/.kube/config
|
|
||||||
|
|
||||||
kubectl create namespace gohorsejobsdev --dry-run=client -o yaml | kubectl apply -f -
|
kubectl create namespace gohorsejobsdev --dry-run=client -o yaml | kubectl apply -f -
|
||||||
|
|
||||||
# Garante que o secret de pull de imagem no K3s use o Registry correto
|
|
||||||
kubectl -n gohorsejobsdev create secret docker-registry forgejo-registry \
|
kubectl -n gohorsejobsdev create secret docker-registry forgejo-registry \
|
||||||
--docker-server=${{ env.REGISTRY }} \
|
--docker-server=${{ env.REGISTRY }} \
|
||||||
--docker-username=${{ env.IMAGE_NAMESPACE }} \
|
--docker-username=${{ env.IMAGE_NAMESPACE }} \
|
||||||
|
|
@ -99,7 +70,6 @@ jobs:
|
||||||
--dry-run=client -o yaml | kubectl apply -f -
|
--dry-run=client -o yaml | kubectl apply -f -
|
||||||
|
|
||||||
kubectl -n gohorsejobsdev create secret generic backend-secrets \
|
kubectl -n gohorsejobsdev create secret generic backend-secrets \
|
||||||
--from-literal=MTU="${{ env.DOCKER_MTU }}" \
|
|
||||||
--from-literal=JWT_SECRET="${{ vars.JWT_SECRET }}" \
|
--from-literal=JWT_SECRET="${{ vars.JWT_SECRET }}" \
|
||||||
--from-literal=AMQP_URL="${{ vars.AMQP_URL }}" \
|
--from-literal=AMQP_URL="${{ vars.AMQP_URL }}" \
|
||||||
--from-literal=DATABASE_URL="${{ vars.DATABASE_URL }}" \
|
--from-literal=DATABASE_URL="${{ vars.DATABASE_URL }}" \
|
||||||
|
|
@ -109,8 +79,8 @@ jobs:
|
||||||
|
|
||||||
kubectl -n gohorsejobsdev set image deployment/gohorse-backend-dev \
|
kubectl -n gohorsejobsdev set image deployment/gohorse-backend-dev \
|
||||||
backend=${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:${{ github.sha }}
|
backend=${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/gohorsejobs:${{ github.sha }}
|
||||||
|
|
||||||
kubectl -n gohorsejobsdev set image deployment/gohorse-backoffice-dev \
|
kubectl -n gohorsejobsdev set image deployment/gohorse-backoffice-dev \
|
||||||
backoffice=${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:${{ github.sha }}
|
backoffice=${{ env.REGISTRY }}/${{ env.IMAGE_NAMESPACE }}/backoffice:${{ github.sha }}
|
||||||
|
|
||||||
kubectl -n gohorsejobsdev rollout status deployment/gohorse-backend-dev --timeout=120s
|
kubectl -n gohorsejobsdev rollout status deployment/gohorse-backend-dev --timeout=60s
|
||||||
kubectl -n gohorsejobsdev rollout status deployment/gohorse-backoffice-dev --timeout=120s
|
|
||||||
Loading…
Reference in a new issue