email article #71
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Build and deploy blog | |
on: | |
push: | |
branches: | |
- master | |
paths: | |
- 'astro-website/**' | |
env: | |
REGISTRY: ghcr.io | |
IMAGE_NAME: ${{ github.repository }} | |
jobs: | |
build-and-push-image: | |
runs-on: ubuntu-latest | |
permissions: | |
contents: read | |
packages: write | |
steps: | |
- run: echo "🎉 The job was automatically triggered by a ${{ github.event_name }} event." | |
- name: Checkout repository | |
uses: actions/checkout@v3 | |
with: | |
# These two options seems important for when an action needs to push commits back into | |
# the repo | |
persist-credentials: false # otherwise, the token used is the GITHUB_TOKEN, instead of your personal access token. | |
fetch-depth: 0 # otherwise, there would be errors pushing refs to the destination repository. | |
- name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@v1 | |
- name: Cache Docker layers | |
uses: actions/cache@v2 | |
with: | |
path: /tmp/.buildx-cache | |
key: ${{ runner.os }}-buildx-${{ github.sha }} | |
restore-keys: | | |
${{ runner.os }}-buildx- | |
- name: Log in to the Container registry | |
uses: docker/login-action@f054a8b539a109f9f41c372932f1ae047eff08c9 | |
with: | |
registry: ${{ env.REGISTRY }} | |
username: ${{ github.actor }} | |
password: ${{ secrets.GITHUB_TOKEN }} | |
- name: Extract metadata (tags, labels) for Docker | |
id: meta | |
uses: docker/metadata-action@98669ae865ea3cffbcbaa878cf57c20bbf1c6c38 | |
with: | |
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} | |
# https://github.com/docker/metadata-action#typesha | |
tags: | | |
type=sha,priority=100,format=short,prefix=sha- | |
type=raw,priority=200,prefix=sha-,value=${{ github.sha }} | |
- name: Build and push Docker image | |
uses: docker/build-push-action@ad44023a93711e3deb337508980b4b5e9bcdc5dc | |
with: | |
context: . | |
push: true | |
tags: ${{ steps.meta.outputs.tags }} | |
labels: ${{ steps.meta.outputs.labels }} | |
cache-from: type=gha | |
cache-to: type=gha,mode=max | |
- name: update image tags in k8s manifests | |
uses: fjogeleit/[email protected] | |
with: | |
valueFile: 'k8s/deployment.yaml' | |
propertyPath: 'spec.template.spec.containers[0].image' | |
value: ghcr.io/robalb/my-website:sha-${{ github.sha }} | |
updateFile: true | |
commitChange: false | |
- name: update image tags in compose-prod | |
uses: fjogeleit/[email protected] | |
with: | |
valueFile: 'compose-prod/blog-halb/docker-compose.yml' | |
propertyPath: "services['blog-halb'].image" | |
value: ghcr.io/robalb/my-website:sha-${{ github.sha }} | |
updateFile: true | |
commitChange: false | |
- name: Commit changes | |
run: | | |
git config --local user.email "41898282+github-actions[bot]@users.noreply.github.com" | |
git config --local user.name "github-actions[bot]" | |
git commit -am "Updated image tags in the app manifests" | |
- name: Push changes | |
uses: ad-m/[email protected] | |
with: | |
github_token: ${{ secrets.PAC_TO_BYPASS_CURSE }} | |
branch: ${{ github.ref }} |