diff --git a/.gitea/workflows/build.yml b/.gitea/workflows/build.yml deleted file mode 100644 index c619e8b4..00000000 --- a/.gitea/workflows/build.yml +++ /dev/null @@ -1,69 +0,0 @@ -name: Build and Push Docker Image - -on: - push: - branches: [main] - -jobs: - build: - runs-on: ubuntu-latest - - container: - options: --cap-add=NET_ADMIN --device=/dev/net/tun - - steps: - - name: Tailscale - uses: tailscale/github-action@v4 - with: - authkey: ${{ secrets.TAILSCALE_AUTHKEY }} - ping: rose-library,gitea,tle-meanjin-one-deploy-trigger - version: latest - - - name: Checkout - uses: actions/checkout@v4 - with: - submodules: true # Pulls in the mission files - - - name: Docker Login - uses: docker/login-action@v4 - with: - registry: gitea.allosaurus-chromatic.ts.net - username: ${{ secrets.REGISTRY_USER }} - password: ${{ secrets.REGISTRY_PASSWORD }} - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v4 - - - name: Build and Push - uses: docker/build-push-action@v7 - with: - push: true - tags: gitea.allosaurus-chromatic.ts.net/tlecommunity/server:latest - provenance: false - platforms: linux/amd64 - cache-from: type=registry,ref=gitea.allosaurus-chromatic.ts.net/tlecommunity/server:buildcache - cache-to: type=registry,ref=gitea.allosaurus-chromatic.ts.net/tlecommunity/server:buildcache,mode=max - - - name: Trigger Deploy - env: - DEPLOY_WEBHOOK_SECRET: ${{ secrets.DEPLOY_WEBHOOK_SECRET }} - run: | - set -euo pipefail - - payload=$(jq -nc \ - --arg actor "${GITHUB_ACTOR:-unknown}" \ - --arg ref "${GITHUB_REF:-unknown}" \ - --arg commit "${GITHUB_SHA:-unknown}" \ - --arg ci_run_url "${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/actions/runs/${GITHUB_RUN_ID}" \ - '{actor: $actor, ref: $ref, commit: $commit, ci_run_url: $ci_run_url}') - - sig=$(printf '%s' "$payload" \ - | openssl dgst -sha256 -hmac "$DEPLOY_WEBHOOK_SECRET" \ - | sed 's/^.* //') - - curl -fsS --retry 3 --retry-delay 5 --retry-connrefused \ - -X POST \ - -H 'Content-Type: application/json' \ - -H "X-Hub-Signature-256: sha256=${sig}" \ - --data "$payload" \ - https://tle-meanjin-one-deploy-trigger.allosaurus-chromatic.ts.net/hooks/deploy diff --git a/.tangled/workflows/build.yml b/.tangled/workflows/build.yml new file mode 100644 index 00000000..8e87ecc7 --- /dev/null +++ b/.tangled/workflows/build.yml @@ -0,0 +1,50 @@ +name: Build and Push Docker Image + +when: + - event: ['push'] + branch: ['main'] + +clone: + submodules: true # Pulls in the mission files + +engine: 'nixery' + +dependencies: + nixpkgs: + - docker + - docker-buildx + +steps: + - name: Docker Build & Push + command: | + set -euo pipefail + + echo "$REGISTRY_TOKEN" | docker login atcr.io -u "tlecommunity.com" --password-stdin + docker build \ + -t "atcr.io/tlecommunity.com/server:latest" \ + --cache-from "type=registry,ref=atcr.io/tlecommunity.com/server:buildcache" \ + --cache-to "type=registry,ref=atcr.io/tlecommunity.com/server:buildcache,mode=max" \ + . + docker push "atcr.io/tlecommunity.com/server:latest" + + - name: Deploy Webhook + command: | + set -euo pipefail + + payload=$(jq -nc \ + --arg actor "${GITHUB_ACTOR:-unknown}" \ + --arg ref "${TANGLED_REF:-unknown}" \ + --arg commit "${TANGLED_SHA:-unknown}" \ + --arg ci_run_url "${TANGLED_REPOSITORY}/actions/runs/${TANGLED_PIPELINE_ID}" \ + '{actor: $actor, ref: $ref, commit: $commit, ci_run_url: $ci_run_url}') + + sig=$(printf '%s' "$payload" \ + | openssl dgst -sha256 -hmac "$DEPLOY_WEBHOOK_SECRET" \ + | sed 's/^.* //') + + curl -fsS --retry 3 --retry-delay 5 --retry-connrefused \ + -X POST \ + -H 'Content-Type: application/json' \ + -H "X-Hub-Signature-256: sha256=${sig}" \ + --data "$payload" \ + "$DEPLOY_WEBHOOK_ENDPOINT"