Skip to content

Commit

Permalink
Add new prod
Browse files Browse the repository at this point in the history
  • Loading branch information
Simon KP committed May 15, 2024
1 parent b58ecea commit 489541d
Show file tree
Hide file tree
Showing 5 changed files with 320 additions and 1 deletion.
85 changes: 85 additions & 0 deletions .github/workflows/angular-new-prod.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
name: Build Prod Angular - Frontend

on:
push:
branches: [ develop ]
paths:
- "frontend/**"
- ".github/workflows/angular-new-prod.yml"

jobs:
build:
runs-on: ubuntu-latest
env:
REGION: eu-central-1
CLUSTER_NAME: maker-prod
SERVICE_NAME: mips-frontend
AWS_ECR_NAME: mips-frontend-prod
ENVIRONMENT_TAG: prod
HELM_FILE: helm/prod/frontend.yaml

steps:
- uses: actions/checkout@v3

- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.PROD_AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.PROD_AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ env.REGION }}

- name: Login to AWS ECR
id: login-ecr
uses: aws-actions/amazon-ecr-login@v2

- name: Extract commit hash
id: vars
if: ${{ !contains(github.event.head_commit.message , '[skip build]') }}
shell: bash
run: |
echo "::set-output name=sha_short::$(git rev-parse --short HEAD)"
- name: Build, tag, and push image to ECR
id: build-image
if: ${{ !contains(github.event.head_commit.message , '[skip build]') }}
working-directory: frontend
env:
SHA_TAG: ${{ steps.vars.outputs.sha_short }}
LATEST_TAG: latest
ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }}
run: |
# Build Docker containers and push them to ECR ${{ env.AWS_ECR_NAME }}
docker pull $ECR_REGISTRY/$AWS_ECR_NAME:$LATEST_TAG || true
docker build -t $AWS_ECR_NAME \
-t $ECR_REGISTRY/$AWS_ECR_NAME:$SHA_TAG \
-t $ECR_REGISTRY/$AWS_ECR_NAME:$LATEST_TAG \
-t $ECR_REGISTRY/$AWS_ECR_NAME:$ENVIRONMENT_TAG \
-f Dockerfile \
.
docker push $ECR_REGISTRY/$AWS_ECR_NAME --all-tags
- name: Replace variables in the Helm values file
id: replace-vars
if: ${{ !contains(github.event.head_commit.message , '[skip deploy]') }}
env:
ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }}
run: |
sed -i 's/${ECR_REGISTRY}/'$ECR_REGISTRY/ $HELM_FILE
sed -i 's/${USERS_LIST}/'$USERS_LIST/ $HELM_FILE
- name: Deploying Service to Kubernetes with Helm
id: deploy
if: ${{ !contains(github.event.head_commit.message , '[skip deploy]') }}
uses: bitovi/[email protected]
with:
values: image.repository=${{ steps.login-ecr.outputs.registry }}/${{ env.AWS_ECR_NAME }},image.tag=${{ steps.vars.outputs.sha_short }}
cluster-name: ${{ env.CLUSTER_NAME }}
config-files: ${{ env.HELM_FILE }}
chart-path: techops-services/common
namespace: mips
timeout: 5m0s
name: ${{ env.SERVICE_NAME }}
chart-repository: https://techops-services.github.io/helm-charts
version: 0.0.31
atomic: true
104 changes: 104 additions & 0 deletions .github/workflows/node.js-new-prod.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,104 @@
name: Node.js Prod CI - Backend

on:
push:
branches: [ develop ]
paths:
- "backend/**"
- ".github/workflows/node.js-new-prod.yml"

jobs:
build-deploy:
runs-on: ubuntu-latest
env:
REGION: eu-central-1
CLUSTER_NAME: maker-prod
SERVICE_NAME: mips-backend
AWS_ECR_NAME: mips-backend-prod
ENVIRONMENT_TAG: prod
HELM_FILE: helm/prod/backend.yaml

steps:
- name: Checkout
uses: actions/checkout@v3

- name: Running the Test Suit
env:
REQUEST_GITHUB_URL_API_ENDPOINT: ${{ secrets.REQUEST_GITHUB_URL_API_ENDPOINT }}
GIT_ACCESS_API_TOKEN: ${{ secrets.GIT_ACCESS_API_TOKEN }}
MIP_GITHUB_REPOSITORY: ${{ secrets.MIP_GITHUB_REPOSITORY_DEV }}
MIP_GITHUB_REPOSITORY_OWNER: ${{ secrets.MIP_GITHUB_REPOSITORY_OWNER_DEV }}
run: |
cp '.env example' .env
npm install
npm run pre-start
npm test
working-directory: backend

- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.PROD_AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.PROD_AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ env.REGION }}

- name: Login to AWS ECR
id: login-ecr
uses: aws-actions/amazon-ecr-login@v2

- name: Extract commit hash
id: vars
if: ${{ !contains(github.event.head_commit.message , '[skip build]') }}
shell: bash
run: |
echo "::set-output name=sha_short::$(git rev-parse --short HEAD)"
- name: Build, tag, and push image to ECR
id: build-image
if: ${{ !contains(github.event.head_commit.message , '[skip build]') }}
working-directory: backend
env:
SHA_TAG: ${{ steps.vars.outputs.sha_short }}
LATEST_TAG: latest
ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }}
REQUEST_GITHUB_URL_API_ENDPOINT: ${{ secrets.REQUEST_GITHUB_URL_API_ENDPOINT }}
GIT_ACCESS_API_TOKEN: ${{ secrets.GIT_ACCESS_API_TOKEN }}
MIP_GITHUB_REPOSITORY: ${{ secrets.MIP_GITHUB_REPOSITORY_DEV }}
MIP_GITHUB_REPOSITORY_OWNER: ${{ secrets.MIP_GITHUB_REPOSITORY_OWNER_DEV }}
run: |
# Build Docker containers and push them to ECR ${{ env.AWS_ECR_NAME }}
docker pull $ECR_REGISTRY/$AWS_ECR_NAME:$LATEST_TAG || true
docker build -t $AWS_ECR_NAME \
-t $ECR_REGISTRY/$AWS_ECR_NAME:$SHA_TAG \
-t $ECR_REGISTRY/$AWS_ECR_NAME:$LATEST_TAG \
-t $ECR_REGISTRY/$AWS_ECR_NAME:$ENVIRONMENT_TAG \
--build-arg REQUEST_GITHUB_URL_API_ENDPOINT=$REQUEST_GITHUB_URL_API_ENDPOINT \
--build-arg GIT_ACCESS_API_TOKEN=$GIT_ACCESS_API_TOKEN \
-f Dockerfile \
.
docker push $ECR_REGISTRY/$AWS_ECR_NAME --all-tags
- name: Replace variables in the Helm values file
id: replace-vars
if: ${{ !contains(github.event.head_commit.message , '[skip deploy]') }}
env:
ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }}
run: |
sed -i 's/${ECR_REGISTRY}/'$ECR_REGISTRY/ $HELM_FILE
- name: Deploying Service to Kubernetes with Helm
id: deploy
if: ${{ !contains(github.event.head_commit.message , '[skip deploy]') }}
uses: bitovi/[email protected]
with:
values: image.repository=${{ steps.login-ecr.outputs.registry }}/${{ env.AWS_ECR_NAME }},image.tag=${{ steps.vars.outputs.sha_short }}
cluster-name: ${{ env.CLUSTER_NAME }}
config-files: ${{ env.HELM_FILE }}
chart-path: techops-services/common
namespace: mips
timeout: 5m0s
name: ${{ env.SERVICE_NAME }}
chart-repository: https://techops-services.github.io/helm-charts
version: 0.0.31
atomic: true
2 changes: 1 addition & 1 deletion frontend/src/environments/environment.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
export const environment = {
production: false,
// apiUrl: 'http://backend:3000',
apiUrl: "https://mips-api-staging.makerdao.com",
apiUrl: "https://mips-api.makerdao.com",
repoUrl: 'https://github.com/makerdao/mips/blob/master',
feedBackFormUrl: 'https://formspree.io/f/xzbyjjnb',
githubURL: 'https://github.com/',
Expand Down
67 changes: 67 additions & 0 deletions helm/prod/backend.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
replicaCount: 1
service:
enabled: true
name: mips-backend
port: 3000
type: ClusterIP
containerPort: 3000
tls:
enabled: true
issuerName: letsencrypt

image:
repository: ${ECR_REGISTRY}/mips-backend-prod
pullPolicy: Always
tag: latest

serviceAccount:
create: false

ingress:
enabled: true
hosts:
- mips-api-prod.makerdao.com
annotations:
external-dns.alpha.kubernetes.io/cloudflare-proxied: "false"

httpBasicAuth:
enabled: false

# If enabled will create Traefik Middleware and apply to Ingress
# to redirect http to https and www to non-www
httpWwwRedirect:
enabled: false

podAnnotations:
reloader.stakater.com/auto: "true"

resources:
limits:
cpu: 1
memory: 1Gi
requests:
cpu: 250m
memory: 256Mi

env:
NODE_ENV:
type: kv
value: production
WEBHOOKS_SECRET_TOKEN:
type: parameterStore
name: webhooks-secret-token
parameter_name: /eks/maker-prod/mips-backend/webhooks-secret-token

externalSecrets:
clusterSecretStoreName: maker-prod

livenessProbe:
initialDelaySeconds: 5
periodSeconds: 30
tcpSocket:
port: 3000
readinessProbe:
initialDelaySeconds: 5
periodSeconds: 30
tcpSocket:
port: 3000
63 changes: 63 additions & 0 deletions helm/prod/frontend.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
replicaCount: 1
service:
enabled: true
name: mips-frontend
port: 8000
type: ClusterIP
containerPort: 80
tls:
enabled: true
issuerName: letsencrypt

image:
repository: ${ECR_REGISTRY}/mips-frontend-prod
pullPolicy: Always
tag: latest

serviceAccount:
create: false

ingress:
enabled: true
hosts:
- mips-prod.makerdao.com
annotations:
external-dns.alpha.kubernetes.io/cloudflare-proxied: "false"

httpBasicAuth:
enabled: false

# If enabled will create Traefik Middleware and apply to Ingress
# to redirect http to https and www to non-www
httpWwwRedirect:
enabled: false

podAnnotations:
reloader.stakater.com/auto: "true"

resources:
limits:
cpu: 1
memory: 1Gi
requests:
cpu: 250m
memory: 256Mi

env:
NODE_ENV:
type: kv
value: production

externalSecrets:
clusterSecretStoreName: maker-prod

livenessProbe:
initialDelaySeconds: 5
periodSeconds: 30
tcpSocket:
port: 80
readinessProbe:
initialDelaySeconds: 5
periodSeconds: 30
tcpSocket:
port: 80

0 comments on commit 489541d

Please sign in to comment.