Something went wrong. Try again.
Monorepo for Tangled tangled.org
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123when: - event: push branch: sv-fe paths: - bobbin/** - crates/** - lexicons/** - Cargo.toml - Cargo.lock - rust-toolchain.toml - web/** - flake.nix - flake.lock - nix/pkgs/web-static-files.nix - .tangled/workflows/deploy-gcp-dev.yml
audience: //iam.googleapis.com/projects/264757501569/locations/global/workloadIdentityPools/tangled-ci/providers/spindle
engine: microvmimage: nixos
virtualisation: docker: true
dependencies: - google-cloud-sdk - docker-buildx
environment: GCP_PROJECT: exemplary-proxy-507408-d6 GCP_REGION: europe-north1 REGISTRY: europe-north1-docker.pkg.dev/exemplary-proxy-507408-d6/tangled WIF_PROVIDER: projects/264757501569/locations/global/workloadIdentityPools/tangled-ci/providers/spindle CI_SERVICE_ACCOUNT: ci-deployer-next@exemplary-proxy-507408-d6.iam.gserviceaccount.com IM_SERVICE_ACCOUNT: im-deployer-next@exemplary-proxy-507408-d6.iam.gserviceaccount.com DEPLOYMENT: tangled-dev BOBBIN_CACHE: europe-north1-docker.pkg.dev/exemplary-proxy-507408-d6/tangled/bobbin-cache:buildcache SVFE_CACHE: europe-north1-docker.pkg.dev/exemplary-proxy-507408-d6/tangled/svfe-cache:buildcache TF_VERSION: "=1.5.7" # buildx passes this to the builds, and rewrite-timestamp clamps the files in the # layers to it too, so rebuilding the same source gives the same digest SOURCE_DATE_EPOCH: "0" VITE_OAUTH_CLIENT_ID: https://next.tangled.org/oauth-client-metadata.json VITE_OAUTH_REDIRECT_URI: https://next.tangled.org/oauth/callback
steps: - name: authenticate to gcp command: | set -eu umask 077 printf '%s' "$TANGLED_ID_TOKEN" > "$HOME/.tangled-id-token" gcloud iam workload-identity-pools create-cred-config "$WIF_PROVIDER" \ --service-account="$CI_SERVICE_ACCOUNT" \ --credential-source-file="$HOME/.tangled-id-token" \ --output-file="$HOME/.gcp-wif.json" gcloud auth login --cred-file="$HOME/.gcp-wif.json" --quiet gcloud config set project "$GCP_PROJECT" --quiet gcloud auth print-access-token > "$HOME/.gcp-token" docker login --username=oauth2accesstoken \ --password="$(cat "$HOME/.gcp-token")" "$GCP_REGION-docker.pkg.dev"
# bobbin's Containerfile copies from the repo root, so the root is the context - name: build and push bobbin command: | set -eu tag="dev-${TANGLED_COMMIT_SHA:0:8}" docker-buildx build \ --file=bobbin/containerfiles/bobbin.Containerfile \ --build-arg BOBBIN_PROFILE=dev-deploy \ --tag="$REGISTRY/bobbin-next:$tag" \ --tag="$REGISTRY/bobbin-next:dev" \ --provenance=false \ --cache-from "type=registry,ref=$BOBBIN_CACHE" \ --cache-to "type=registry,ref=$BOBBIN_CACHE,mode=max" \ --output type=registry,rewrite-timestamp=true . echo "bobbin-next:$tag"
- name: build and push svfe command: | set -eu tag="dev-${TANGLED_COMMIT_SHA:0:8}"
out=$(nix build .#web-static-files --no-link --print-out-paths) mkdir -p web/static rm -rf web/static/fonts web/static/logos cp -fr "$out"/* web/static
docker-buildx build \ --file=web/Containerfile \ --build-arg VITE_OAUTH_CLIENT_ID="$VITE_OAUTH_CLIENT_ID" \ --build-arg VITE_OAUTH_REDIRECT_URI="$VITE_OAUTH_REDIRECT_URI" \ --build-arg APP_VERSION="$(git rev-parse HEAD:web)" \ --tag="$REGISTRY/svfe-next:$tag" \ --tag="$REGISTRY/svfe-next:dev" \ --provenance=false \ --cache-from "type=registry,ref=$SVFE_CACHE" \ --cache-to "type=registry,ref=$SVFE_CACHE,mode=max" \ --output type=registry,rewrite-timestamp=true web/ echo "svfe-next:$tag"
# reuse the last deployed blueprint here. # the image ref input is what rolls the services: terraform diffs the image # string, and a floating :dev tag looks unchanged, so pin the sha tag - name: deploy command: | set -eu export CLOUDSDK_AUTH_ACCESS_TOKEN="$(cat "$HOME/.gcp-token")" dep="projects/$GCP_PROJECT/locations/$GCP_REGION/deployments/$DEPLOYMENT"
src=$(gcloud infra-manager deployments describe "$dep" \ --format='value(terraformBlueprint.gcsSource)')
ref=":dev-${TANGLED_COMMIT_SHA:0:8}" printf 'env_name = "dev"\nimage_refs = { bobbin = "%s", svfe = "%s" }\n' "$ref" "$ref" > /tmp/im-inputs.env
gcloud infra-manager deployments apply "$dep" \ --service-account="projects/$GCP_PROJECT/serviceAccounts/$IM_SERVICE_ACCOUNT" \ --gcs-source="$src" \ --inputs-file=/tmp/im-inputs.env \ --tf-version-constraint="$TF_VERSION"
gcloud infra-manager deployments describe "$dep" --format='value(latestRevision)'