From ee7f5dadf0dc6967e303396835493f2938acda4e Mon Sep 17 00:00:00 2001 From: incubator4 Date: Wed, 3 Jan 2024 22:48:21 +0800 Subject: [PATCH] feat: deploy to gcp --- .github/workflows/docker-build-push.yml | 126 +++++++--------------- deploy/dev/deploy.yaml | 2 +- deploy/dev/kustomization.yaml | 8 ++ deploy/dev/route.yaml | 6 +- deploy/dev/{secrets.yaml => secret.yaml} | 6 +- deploy/prod/deploy.yaml | 2 +- deploy/prod/kustomization.yaml | 9 ++ deploy/prod/pvc.yaml | 12 +++ deploy/prod/route.yaml | 6 +- deploy/prod/{secrets.yaml => secret.yaml} | 6 +- 10 files changed, 87 insertions(+), 96 deletions(-) create mode 100644 deploy/dev/kustomization.yaml rename deploy/dev/{secrets.yaml => secret.yaml} (51%) create mode 100644 deploy/prod/kustomization.yaml create mode 100644 deploy/prod/pvc.yaml rename deploy/prod/{secrets.yaml => secret.yaml} (51%) diff --git a/.github/workflows/docker-build-push.yml b/.github/workflows/docker-build-push.yml index d1e81e9..07c8bcf 100644 --- a/.github/workflows/docker-build-push.yml +++ b/.github/workflows/docker-build-push.yml @@ -1,94 +1,48 @@ -name: Docker Build - +name: Build and Deploy on: push: branches: - - "dev" - - "main" - -env: - IMAGE_NAME: rss3/xchar - REGION_ID: us-east-1 - DEV_ACK_CLUSTER_ID: cd1d0ffc40b5242b39ddda1864e71e30d - PROD_ACK_CLUSTER_ID: cfc647c22fd6848b5a602ad4d7470632b - + - dev + - main + tags: + - v* jobs: build: - runs-on: ubuntu-latest - outputs: - version: ${{ steps.meta.outputs.version }} - steps: - - name: Checkout - uses: actions/checkout@v3 - - name: docker meta - id: meta - uses: docker/metadata-action@v4 - with: - images: ${{ env.IMAGE_NAME }} - tags: | - type=sha - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v2 - - name: Login to DockerHub - if: github.event_name != 'pull_request' - uses: docker/login-action@v2 - with: - username: ${{ secrets.DOCKERHUB_USERNAME }} - password: ${{ secrets.DOCKERHUB_TOKEN }} - - name: Build and push - uses: docker/build-push-action@v3 - with: - context: . - file: Dockerfile - push: ${{ github.event_name != 'pull_request' }} - tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} - + uses: NaturalSelectionLabs/Daedalus/.github/workflows/docker-tpl.yaml@main + with: + images: flosspicks/xchar + context: . + dockerfile: ./Dockerfile + secrets: + DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }} + DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} deploy-dev: - runs-on: ubuntu-latest - needs: [build] - steps: - - name: Checkout - uses: actions/checkout@v3 - - name: Set K8s context - uses: aliyun/ack-set-context@v1 - with: - access-key-id: "${{ secrets.ACCESS_KEY_ID }}" - access-key-secret: "${{ secrets.ACCESS_KEY_SECRET }}" - cluster-id: "${{ env.DEV_ACK_CLUSTER_ID }}" - - name: Install Tools - run: | - wget https://github.com/mikefarah/yq/releases/download/v4.25.1/yq_linux_amd64.tar.gz -O - | tar xz && mv yq_linux_amd64 /usr/local/bin/yq - curl -LO https://storage.googleapis.com/kubernetes-release/release/v1.22.10/bin/linux/amd64/kubectl && chmod +x kubectl && mv kubectl /usr/local/bin/kubectl - - uses: sljeff/secrets2env@main - with: - secrets-json: ${{ toJson(secrets) }} - - env: - IMAGE_TAG_RELEASE: ${{ env.IMAGE_NAME }}:${{ needs.build.outputs.version }} - run: | - sh apply.sh deploy/dev/* - + if: github.ref == 'refs/heads/dev' + uses: NaturalSelectionLabs/Daedalus/.github/workflows/deploy-v3-tpl.yaml@main + needs: + - build + with: + images: flosspicks/xchar + tag: sha-${{ github.sha }} + cluster: dev + namespace: crossbell + releaseName: xchar + revision: develop + dir: deploy/dev + secrets: + GOOGLE_CREDENTIALS: ${{ secrets.GOOGLE_CREDENTIALS }} deploy-prod: if: github.ref == 'refs/heads/main' - runs-on: ubuntu-latest - needs: [build, deploy-dev] - steps: - - name: Checkout - uses: actions/checkout@v3 - - name: Set K8s context - uses: aliyun/ack-set-context@v1 - with: - access-key-id: "${{ secrets.ACCESS_KEY_ID }}" - access-key-secret: "${{ secrets.ACCESS_KEY_SECRET }}" - cluster-id: "${{ env.PROD_ACK_CLUSTER_ID }}" - - name: Install Tools - run: | - wget https://github.com/mikefarah/yq/releases/download/v4.25.1/yq_linux_amd64.tar.gz -O - | tar xz && mv yq_linux_amd64 /usr/local/bin/yq - curl -LO https://storage.googleapis.com/kubernetes-release/release/v1.22.10/bin/linux/amd64/kubectl && chmod +x kubectl && mv kubectl /usr/local/bin/kubectl - - uses: sljeff/secrets2env@main - with: - secrets-json: ${{ toJson(secrets) }} - - env: - IMAGE_TAG_RELEASE: ${{ env.IMAGE_NAME }}:${{ needs.build.outputs.version }} - run: | - sh apply.sh deploy/prod/* + uses: NaturalSelectionLabs/Daedalus/.github/workflows/deploy-v3-tpl.yaml@main + needs: + - build + with: + images: flosspicks/xchar + tag: sha-${{ github.sha }} + cluster: prod + namespace: crossbell + releaseName: xchar + revision: main + dir: deploy/prod + secrets: + GOOGLE_CREDENTIALS: ${{ secrets.GOOGLE_CREDENTIALS }} diff --git a/deploy/dev/deploy.yaml b/deploy/dev/deploy.yaml index 6424dac..e5becd9 100644 --- a/deploy/dev/deploy.yaml +++ b/deploy/dev/deploy.yaml @@ -23,7 +23,7 @@ spec: tier: api spec: containers: - - image: $IMAGE_TAG_RELEASE + - image: flosspicks/xchar imagePullPolicy: Always name: xchar envFrom: diff --git a/deploy/dev/kustomization.yaml b/deploy/dev/kustomization.yaml new file mode 100644 index 0000000..7d7e6b5 --- /dev/null +++ b/deploy/dev/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - deploy.yaml + - svc.yaml + - route.yaml + - secret.yaml diff --git a/deploy/dev/route.yaml b/deploy/dev/route.yaml index 2e4b964..3191bf1 100644 --- a/deploy/dev/route.yaml +++ b/deploy/dev/route.yaml @@ -3,12 +3,14 @@ kind: IngressRoute metadata: name: xchar namespace: crossbell + annotations: + avp.kubernetes.io/path: "kv/data/crossbell/xchar" spec: entryPoints: - - web + - websecure routes: - kind: Rule - match: "Host(`$XCHAR_DOMAIN_DEV`)" + match: Host(``) services: - name: xchar port: 3000 diff --git a/deploy/dev/secrets.yaml b/deploy/dev/secret.yaml similarity index 51% rename from deploy/dev/secrets.yaml rename to deploy/dev/secret.yaml index a79f618..36df158 100644 --- a/deploy/dev/secrets.yaml +++ b/deploy/dev/secret.yaml @@ -1,8 +1,10 @@ apiVersion: v1 -stringData: - REDIS_URL: $REDIS_URL_DEV kind: Secret metadata: name: xchar namespace: crossbell + annotations: + avp.kubernetes.io/path: "kv/data/crossbell/xchar" type: Opaque +stringData: + REDIS_URL: "" diff --git a/deploy/prod/deploy.yaml b/deploy/prod/deploy.yaml index 9fcf216..3ddda50 100644 --- a/deploy/prod/deploy.yaml +++ b/deploy/prod/deploy.yaml @@ -23,7 +23,7 @@ spec: tier: api spec: containers: - - image: $IMAGE_TAG_RELEASE + - image: flosspicks/xchar imagePullPolicy: Always name: xchar envFrom: diff --git a/deploy/prod/kustomization.yaml b/deploy/prod/kustomization.yaml new file mode 100644 index 0000000..58376ce --- /dev/null +++ b/deploy/prod/kustomization.yaml @@ -0,0 +1,9 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - deploy.yaml + - svc.yaml + - route.yaml + - secret.yaml + - pvc.yaml diff --git a/deploy/prod/pvc.yaml b/deploy/prod/pvc.yaml new file mode 100644 index 0000000..7d66c25 --- /dev/null +++ b/deploy/prod/pvc.yaml @@ -0,0 +1,12 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: xchar-image + namespace: crossbell +spec: + accessModes: + - ReadWriteMany + resources: + requests: + storage: 80Gi + storageClassName: standard-rwm diff --git a/deploy/prod/route.yaml b/deploy/prod/route.yaml index 2c3935c..3191bf1 100644 --- a/deploy/prod/route.yaml +++ b/deploy/prod/route.yaml @@ -3,12 +3,14 @@ kind: IngressRoute metadata: name: xchar namespace: crossbell + annotations: + avp.kubernetes.io/path: "kv/data/crossbell/xchar" spec: entryPoints: - - web + - websecure routes: - kind: Rule - match: "Host(`$XCHAR_DOMAIN`)" + match: Host(``) services: - name: xchar port: 3000 diff --git a/deploy/prod/secrets.yaml b/deploy/prod/secret.yaml similarity index 51% rename from deploy/prod/secrets.yaml rename to deploy/prod/secret.yaml index 7f43cfb..36df158 100644 --- a/deploy/prod/secrets.yaml +++ b/deploy/prod/secret.yaml @@ -1,8 +1,10 @@ apiVersion: v1 -stringData: - REDIS_URL: $REDIS_URL kind: Secret metadata: name: xchar namespace: crossbell + annotations: + avp.kubernetes.io/path: "kv/data/crossbell/xchar" type: Opaque +stringData: + REDIS_URL: ""