-
Notifications
You must be signed in to change notification settings - Fork 0
88 lines (77 loc) · 3.08 KB
/
cd.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
name: CD
on:
pull_request:
branches: [master] # Temporary trigger
workflow_run:
workflows: [CI]
branches: [master]
types:
- completed
env:
GO_VERSION: ^1.21.5
GHCR_REGISTRY: ghcr.io
GAR_REGISTRY: ${{ vars.GAR_LOCATION }}-docker.pkg.dev
GHCR_IMAGE_NAME: ${{ github.repository }}
GAR_IMAGE_NAME: ${{ vars.GOOGLE_PROJECT_ID }}/${{ secrets.GAR_REPOSITORY }}/${{ github.repository }}
TAG: sha-${{ github.sha }}
jobs:
deploy:
runs-on: ubuntu-latest
permissions:
contents: "read"
packages: "write"
id-token: "write"
steps:
- name: Check out code
uses: actions/checkout@v4
- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.GHCR_REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Log in to Google Cloud Platform
uses: "google-github-actions/auth@v2"
with:
project_id: "go-modproxy"
workload_identity_provider: ${{ secrets.GOOGLE_WORKLOAD_IDENTITY_PROVIDER_ID }}
service_account: "${{ secrets.GOOGLE_CLOUD_RUN_SERVICE_ACCOUNT }}"
- name: "Set up Google Cloud SDK"
uses: "google-github-actions/setup-gcloud@v2"
with:
version: ">= 461.0.0"
- name: "Get Google Artifacts Registry credentials"
run: |
gcloud auth configure-docker "${{ vars.GOOGLE_SERVICE_REGION }}-docker.pkg.dev" --quiet
- name: Pull image built by CI
env:
IMAGE: ${{ env.GHCR_REGISTRY }}/${{ env.GHCR_IMAGE_NAME }}:${{ env.TAG }}
run: docker pull ${{ env.IMAGE }}
- name: Tag image as latest for GHCR and specific for GAR
env:
IMAGE: ${{ env.GHCR_REGISTRY }}/${{ env.GHCR_IMAGE_NAME }}:${{ env.TAG }}
GHCR_IMAGE: ${{ env.GHCR_REGISTRY }}/${{ env.GHCR_IMAGE_NAME }}:latest
GAR_IMAGE: ${{ env.GAR_REGISTRY }}/${{ env.GAR_IMAGE_NAME }}:${{ env.TAG }}
run: |
docker tag ${{ env.IMAGE }} ${{ env.GHCR_IMAGE }}
docker tag ${{ env.IMAGE }} ${{ env.GAR_IMAGE }}
- name: Push images to GHCR and GAR
env:
GHCR_IMAGE: ${{ env.GHCR_REGISTRY }}/${{ env.GHCR_IMAGE_NAME }}:latest
GAR_IMAGE: ${{ env.GAR_REGISTRY }}/${{ env.GAR_IMAGE_NAME }}:${{ env.TAG }}
run: |
docker push ${{ env.GHCR_IMAGE }}
docker push ${{ env.GAR_IMAGE }}
- name: "Deploy to Cloud Run"
uses: "google-github-actions/deploy-cloudrun@v2"
with:
service: "${{ vars.GOOGLE_SERVICE_NAME }}"
image: "${{ env.GAR_IMAGE_NAME }}"
env_vars: |
HOST_PATTERN=${{ vars.HOST_PATTERN }}
HOST_REPLACEMENT=${{ vars.HOST_REPLACEMENT }}
PATH_PATTERN=${{ vars.PATH_PATTERN }}
PATH_REPLACEMENT=${{ vars.PATH_REPLACEMENT }}
region: "${{ vars.GOOGLE_SERVICE_REGION }}"
project_id: "${{ vars.GOOGLE_PROJECT_ID }}"
flags: "--service-account=${{ secrets.GOOGLE_CLOUD_RUN_SERVICE_ACCOUNT}}" # action does not expose this feature