Merge https://github.com/cisagov/skeleton-packer into lineage/skeleton #96
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--- | ||
name: prerelease | ||
on: | ||
release: | ||
types: [prereleased] | ||
env: | ||
AWS_DEFAULT_REGION: us-east-1 | ||
CURL_CACHE_DIR: ~/.cache/curl | ||
PIP_CACHE_DIR: ~/.cache/pip | ||
RUN_TMATE: ${{ secrets.RUN_TMATE }} | ||
jobs: | ||
diagnostics: | ||
name: Run diagnostics | ||
runs-on: ubuntu-latest | ||
steps: | ||
# Note that a duplicate of this step must be added at the top of | ||
# each job. | ||
- id: harden-runner | ||
name: Harden the runner | ||
uses: step-security/harden-runner@v2 | ||
with: | ||
egress-policy: audit | ||
- id: github-status | ||
name: Check GitHub status | ||
uses: crazy-max/ghaction-github-status@v4 | ||
- id: dump-context | ||
name: Dump context | ||
uses: crazy-max/ghaction-dump-context@v2 | ||
prerelease: | ||
needs: | ||
- diagnostics | ||
runs-on: ubuntu-latest | ||
strategy: | ||
fail-fast: false | ||
matrix: | ||
architecture: | ||
- arm64 | ||
- x86_64 | ||
steps: | ||
- id: harden-runner | ||
name: Harden the runner | ||
uses: step-security/harden-runner@v2 | ||
with: | ||
egress-policy: audit | ||
- id: setup-env | ||
uses: cisagov/setup-env-github-action@develop | ||
- uses: actions/checkout@v4 | ||
- id: setup-python | ||
uses: actions/setup-python@v5 | ||
with: | ||
python-version: ${{ steps.setup-env.outputs.python-version }} | ||
- uses: actions/cache@v3 | ||
env: | ||
BASE_CACHE_KEY: "${{ github.job }}-${{ runner.os }}-\ | ||
py${{ steps.setup-python.outputs.python-version }}-\ | ||
packer${{ steps.setup-env.outputs.packer-version }}-\ | ||
tf-${{ steps.setup-env.outputs.terraform-version }}-" | ||
with: | ||
path: | | ||
${{ env.PIP_CACHE_DIR }} | ||
${{ env.CURL_CACHE_DIR }} | ||
key: "${{ env.BASE_CACHE_KEY }}\ | ||
${{ hashFiles('**/requirements.txt') }}" | ||
restore-keys: | | ||
${{ env.BASE_CACHE_KEY }} | ||
- name: Setup curl cache | ||
run: mkdir -p ${{ env.CURL_CACHE_DIR }} | ||
- name: Install Packer | ||
env: | ||
PACKER_VERSION: ${{ steps.setup-env.outputs.packer-version }} | ||
run: | | ||
PACKER_ZIP="packer_${PACKER_VERSION}_linux_amd64.zip" | ||
curl --output ${{ env.CURL_CACHE_DIR }}/"${PACKER_ZIP}" \ | ||
--time-cond ${{ env.CURL_CACHE_DIR }}/"${PACKER_ZIP}" \ | ||
--location \ | ||
"https://releases.hashicorp.com/packer/${PACKER_VERSION}/${PACKER_ZIP}" | ||
sudo unzip -d /opt/packer \ | ||
${{ env.CURL_CACHE_DIR }}/"${PACKER_ZIP}" | ||
sudo mv /usr/local/bin/packer /usr/local/bin/packer-default | ||
sudo ln -s /opt/packer/packer /usr/local/bin/packer | ||
- uses: hashicorp/setup-terraform@v3 | ||
with: | ||
terraform_version: ${{ steps.setup-env.outputs.terraform-version }} | ||
- name: Install dependencies | ||
run: | | ||
python -m pip install --upgrade pip | ||
pip install --upgrade \ | ||
--requirement requirements.txt | ||
- name: Install ansible roles | ||
run: ansible-galaxy install --force --role-file src/requirements.yml | ||
- name: Assume AWS build role | ||
uses: aws-actions/configure-aws-credentials@v4 | ||
with: | ||
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | ||
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | ||
aws-region: ${{ env.AWS_DEFAULT_REGION }} | ||
role-to-assume: ${{ secrets.BUILD_ROLE_TO_ASSUME_STAGING }} | ||
role-duration-seconds: 3600 | ||
# When called by Packer, Ansible will find /usr/bin/python3 and | ||
# use it; therefore, we must ensure that /usr/bin/python3 points | ||
# to the version of Python that we installed in the | ||
# actions/setup-python step above. This can hose other tasks | ||
# that are expecting to find the system Python at that location, | ||
# though, so we undo this change after running Packer. | ||
- name: Create a /usr/bin/python3 symlink to the installed python | ||
run: | | ||
sudo mv /usr/bin/python3 /usr/bin/python3-default | ||
sudo ln -s ${{ env.pythonLocation }}/bin/python3 \ | ||
/usr/bin/python3 | ||
- name: Install Packer plugins | ||
run: packer init src | ||
- name: Create machine image | ||
run: | | ||
<<<<<<< HEAD | ||
packer build -timestamp-ui \ | ||
-var build_bucket=${{ secrets.THIRD_PARTY_BUCKET_STAGING }} \ | ||
======= | ||
packer build -only amazon-ebs.${{ matrix.architecture }} \ | ||
-timestamp-ui \ | ||
>>>>>>> d44181d2b276aa78c43b8b8a038b6c7a2d1fa52c | ||
-var is_prerelease=${{ github.event.release.prerelease }} \ | ||
-var release_tag=${{ github.event.release.tag_name }} \ | ||
-var release_url=${{ github.event.release.html_url }} \ | ||
src/packer.pkr.hcl | ||
- name: Remove /usr/bin/python3 symlink to the installed python | ||
run: | | ||
sudo mv /usr/bin/python3-default /usr/bin/python3 | ||
- name: Setup tmate debug session | ||
uses: mxschmitt/action-tmate@v3 | ||
if: env.RUN_TMATE |