Skip to content

Commit 5c39524

Browse files
committed
Migrate to Kamal for deployments
1 parent 2ff25c9 commit 5c39524

13 files changed

Lines changed: 525 additions & 130 deletions
Lines changed: 97 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,97 @@
1+
name: Build Container
2+
permissions:
3+
packages: write
4+
contents: write
5+
on:
6+
workflow_run:
7+
workflows: ["Build"]
8+
types:
9+
- completed
10+
branches:
11+
- main
12+
- master
13+
workflow_dispatch:
14+
15+
env:
16+
DOCKER_BUILDKIT: 1
17+
KAMAL_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
18+
KAMAL_REGISTRY_USERNAME: ${{ github.actor }}
19+
20+
jobs:
21+
build-container:
22+
runs-on: ubuntu-latest
23+
if: ${{ github.event.workflow_run.conclusion == 'success' }}
24+
steps:
25+
- name: Checkout code
26+
uses: actions/checkout@v3
27+
28+
- name: Set up environment variables
29+
run: |
30+
echo "image_repository_name=$(echo ${{ github.repository }} | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV
31+
echo "repository_name=$(echo ${{ github.repository }} | cut -d '/' -f 2)" >> $GITHUB_ENV
32+
echo "repository_name_lower=$(echo ${{ github.repository }} | cut -d '/' -f 2 | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV
33+
echo "org_name=$(echo ${{ github.repository }} | cut -d '/' -f 1)" >> $GITHUB_ENV
34+
if [ -n "${{ secrets.APPSETTINGS_PATCH }}" ]; then
35+
echo "HAS_APPSETTINGS_PATCH=true" >> $GITHUB_ENV
36+
else
37+
echo "HAS_APPSETTINGS_PATCH=false" >> $GITHUB_ENV
38+
fi
39+
if [ -n "${{ secrets.KAMAL_DEPLOY_IP }}" ]; then
40+
echo "HAS_DEPLOY_ACTION=true" >> $GITHUB_ENV
41+
else
42+
echo "HAS_DEPLOY_ACTION=false" >> $GITHUB_ENV
43+
fi
44+
45+
# This step is for the deployment of the templates only, safe to delete
46+
- name: Modify csproj for template deploy
47+
if: env.HAS_DEPLOY_ACTION == 'true'
48+
run: |
49+
sed -i 's#<ContainerLabel Include="service" Value="talent-blazor" />#<ContainerLabel Include="service" Value="${{ env.repository_name_lower }}" />#g' TalentBlazor/TalentBlazor.csproj
50+
51+
- name: Check for Client directory and package.json
52+
id: check_client
53+
run: |
54+
if [ -d "TalentBlazor.Client" ] && [ -f "TalentBlazor.Client/package.json" ]; then
55+
echo "client_exists=true" >> $GITHUB_OUTPUT
56+
else
57+
echo "client_exists=false" >> $GITHUB_OUTPUT
58+
fi
59+
60+
- name: Setup Node.js
61+
if: steps.check_client.outputs.client_exists == 'true'
62+
uses: actions/setup-node@v3
63+
with:
64+
node-version: 22
65+
66+
- name: Install npm dependencies
67+
if: steps.check_client.outputs.client_exists == 'true'
68+
working-directory: ./TalentBlazor.Client
69+
run: npm install
70+
71+
- name: Install x tool
72+
run: dotnet tool install -g x
73+
74+
- name: Apply Production AppSettings
75+
if: env.HAS_APPSETTINGS_PATCH == 'true'
76+
working-directory: ./TalentBlazor
77+
run: |
78+
cat <<EOF >> appsettings.json.patch
79+
${{ secrets.APPSETTINGS_PATCH }}
80+
EOF
81+
x patch appsettings.json.patch
82+
83+
- name: Login to GitHub Container Registry
84+
uses: docker/login-action@v3
85+
with:
86+
registry: ghcr.io
87+
username: ${{ env.KAMAL_REGISTRY_USERNAME }}
88+
password: ${{ env.KAMAL_REGISTRY_PASSWORD }}
89+
90+
- name: Setup .NET
91+
uses: actions/setup-dotnet@v3
92+
with:
93+
dotnet-version: '8.0'
94+
95+
- name: Build and push Docker image
96+
run: |
97+
dotnet publish --os linux --arch x64 -c Release -p:ContainerRepository=${{ env.image_repository_name }} -p:ContainerRegistry=ghcr.io -p:ContainerImageTags=latest -p:ContainerPort=80

.github/workflows/release.yml

Lines changed: 83 additions & 130 deletions
Original file line numberDiff line numberDiff line change
@@ -3,153 +3,106 @@ permissions:
33
packages: write
44
contents: write
55
on:
6-
# Triggered on new GitHub Release
7-
release:
8-
types: [published]
9-
# Triggered on every successful Build action
106
workflow_run:
11-
workflows: ["Build"]
12-
branches: [main,master]
7+
workflows: ["Build Container"]
138
types:
149
- completed
15-
# Manual trigger for rollback to specific release or redeploy latest
10+
branches:
11+
- main
12+
- master
1613
workflow_dispatch:
17-
inputs:
18-
version:
19-
default: latest
20-
description: Tag you want to release.
21-
required: true
14+
15+
env:
16+
DOCKER_BUILDKIT: 1
17+
KAMAL_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
18+
KAMAL_REGISTRY_USERNAME: ${{ github.actor }}
2219

2320
jobs:
24-
push_to_registry:
25-
runs-on: ubuntu-22.04
26-
if: ${{ github.event.workflow_run.conclusion != 'failure' }}
21+
release:
22+
runs-on: ubuntu-latest
23+
if: ${{ github.event.workflow_run.conclusion == 'success' }}
2724
steps:
28-
# Checkout latest or specific tag
29-
- name: checkout
30-
if: ${{ github.event.inputs.version == '' || github.event.inputs.version == 'latest' }}
31-
uses: actions/checkout@v3
32-
- name: checkout tag
33-
if: ${{ github.event.inputs.version != '' && github.event.inputs.version != 'latest' }}
25+
- name: Checkout code
3426
uses: actions/checkout@v3
35-
with:
36-
ref: refs/tags/${{ github.event.inputs.version }}
37-
38-
# Assign environment variables used in subsequent steps
39-
- name: Env variable assignment
40-
run: echo "image_repository_name=$(echo ${{ github.repository }} | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV
41-
# TAG_NAME defaults to 'latest' if not a release or manual deployment
42-
- name: Assign version
27+
28+
- name: Set up environment variables
4329
run: |
44-
echo "TAG_NAME=latest" >> $GITHUB_ENV
45-
if [ "${{ github.event.release.tag_name }}" != "" ]; then
46-
echo "TAG_NAME=${{ github.event.release.tag_name }}" >> $GITHUB_ENV
47-
fi;
48-
if [ "${{ github.event.inputs.version }}" != "" ]; then
49-
echo "TAG_NAME=${{ github.event.inputs.version }}" >> $GITHUB_ENV
50-
fi;
51-
30+
echo "image_repository_name=$(echo ${{ github.repository }} | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV
31+
echo "repository_name=$(echo ${{ github.repository }} | cut -d '/' -f 2)" >> $GITHUB_ENV
32+
echo "repository_name_lower=$(echo ${{ github.repository }} | cut -d '/' -f 2 | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV
33+
echo "org_name=$(echo ${{ github.repository }} | cut -d '/' -f 1)" >> $GITHUB_ENV
34+
if find . -maxdepth 2 -type f -name "Configure.Db.Migrations.cs" | grep -q .; then
35+
echo "HAS_MIGRATIONS=true" >> $GITHUB_ENV
36+
else
37+
echo "HAS_MIGRATIONS=false" >> $GITHUB_ENV
38+
fi
39+
if [ -n "${{ secrets.KAMAL_DEPLOY_IP }}" ]; then
40+
echo "HAS_DEPLOY_ACTION=true" >> $GITHUB_ENV
41+
else
42+
echo "HAS_DEPLOY_ACTION=false" >> $GITHUB_ENV
43+
fi
44+
45+
# This step is for the deployment of the templates only, safe to delete
46+
- name: Modify deploy.yml
47+
if: env.HAS_DEPLOY_ACTION == 'true'
48+
run: |
49+
sed -i "s/service: talent-blazor/service: ${{ env.repository_name_lower }}/g" config/deploy.yml
50+
sed -i "s#image: my-user/talentblazor#image: ${{ env.image_repository_name }}#g" config/deploy.yml
51+
sed -i "s/- 192.168.0.1/- ${{ secrets.KAMAL_DEPLOY_IP }}/g" config/deploy.yml
52+
sed -i "s/host: talent-blazor.example.com/host: ${{ secrets.KAMAL_DEPLOY_HOST }}/g" config/deploy.yml
53+
sed -i "s/TalentBlazor/${{ env.repository_name }}/g" config/deploy.yml
54+
5255
- name: Login to GitHub Container Registry
53-
uses: docker/login-action@v2
56+
uses: docker/login-action@v3
5457
with:
5558
registry: ghcr.io
56-
username: ${{ github.actor }}
57-
password: ${{ secrets.GITHUB_TOKEN }}
58-
59-
60-
- name: setup .net core
61-
uses: actions/setup-dotnet@v3
59+
username: ${{ env.KAMAL_REGISTRY_USERNAME }}
60+
password: ${{ env.KAMAL_REGISTRY_PASSWORD }}
61+
62+
- name: Set up SSH key
63+
uses: webfactory/ssh-agent@v0.9.0
6264
with:
63-
dotnet-version: '8.0'
64-
65-
# Build and push new docker image, skip for manual redeploy other than 'latest'
66-
- name: Build and push Docker image
67-
run: |
68-
dotnet publish --os linux --arch x64 -c Release -p:ContainerRepository=${{ env.image_repository_name }} -p:ContainerRegistry=ghcr.io -p:ContainerImageTags=${{ env.TAG_NAME }} -p:ContainerPort=80
65+
ssh-private-key: ${{ secrets.SSH_PRIVATE_KEY }}
6966

70-
deploy_via_ssh:
71-
needs: push_to_registry
72-
runs-on: ubuntu-22.04
73-
if: ${{ github.event.workflow_run.conclusion != 'failure' }}
74-
steps:
75-
# Checkout latest or specific tag
76-
- name: checkout
77-
if: ${{ github.event.inputs.version == '' || github.event.inputs.version == 'latest' }}
78-
uses: actions/checkout@v3
79-
- name: checkout tag
80-
if: ${{ github.event.inputs.version != '' && github.event.inputs.version != 'latest' }}
81-
uses: actions/checkout@v3
67+
- name: Setup Ruby
68+
uses: ruby/setup-ruby@v1
8269
with:
83-
ref: refs/tags/${{ github.event.inputs.version }}
70+
ruby-version: 3.3.0
71+
bundler-cache: true
8472

85-
- name: repository name fix and env
73+
- name: Install Kamal
74+
run: gem install kamal -v 2.3.0
75+
76+
- name: Set up Docker Buildx
77+
uses: docker/setup-buildx-action@v3
78+
with:
79+
driver-opts: image=moby/buildkit:master
80+
81+
- name: Kamal bootstrap
82+
run: kamal server bootstrap
83+
84+
- name: Check if first run and execute kamal app boot if necessary
8685
run: |
87-
echo "image_repository_name=$(echo ${{ github.repository }} | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV
88-
echo "TAG_NAME=latest" >> $GITHUB_ENV
89-
if [ "${{ github.event.release.tag_name }}" != "" ]; then
90-
echo "TAG_NAME=${{ github.event.release.tag_name }}" >> $GITHUB_ENV
91-
fi;
92-
if [ "${{ github.event.inputs.version }}" != "" ]; then
93-
echo "TAG_NAME=${{ github.event.inputs.version }}" >> $GITHUB_ENV
94-
fi;
86+
FIRST_RUN_FILE=".${{ env.repository_name }}"
87+
if ! kamal server exec --no-interactive -q "test -f $FIRST_RUN_FILE"; then
88+
kamal server exec --no-interactive -q "touch $FIRST_RUN_FILE" || true
89+
kamal deploy -q -P --version latest || true
90+
else
91+
echo "Not first run, skipping kamal app boot"
92+
fi
9593
96-
- name: Create .env file
94+
- name: Ensure file permissions
9795
run: |
98-
echo "Generating .env file"
99-
100-
echo "# Autogenerated .env file" > .deploy/.env
101-
echo "HOST_DOMAIN=${{ secrets.DEPLOY_HOST }}" >> .deploy/.env
102-
echo "LETSENCRYPT_EMAIL=${{ secrets.LETSENCRYPT_EMAIL }}" >> .deploy/.env
103-
echo "APP_NAME=${{ github.event.repository.name }}" >> .deploy/.env
104-
echo "IMAGE_REPO=${{ env.image_repository_name }}" >> .deploy/.env
105-
echo "RELEASE_VERSION=${{ env.TAG_NAME }}" >> .deploy/.env
106-
107-
# Copy only the docker-compose.yml to remote server home folder
108-
- name: copy files to target server via scp
109-
uses: appleboy/scp-action@v0.1.3
110-
with:
111-
host: ${{ secrets.DEPLOY_HOST }}
112-
username: ${{ secrets.DEPLOY_USERNAME }}
113-
port: 22
114-
key: ${{ secrets.DEPLOY_KEY }}
115-
strip_components: 2
116-
source: "./.deploy/docker-compose.yml,./.deploy/.env"
117-
target: "~/.deploy/${{ github.event.repository.name }}/"
118-
119-
- name: Run remote db migrations
120-
uses: appleboy/ssh-action@v0.1.5
121-
env:
122-
APPTOKEN: ${{ secrets.GITHUB_TOKEN }}
123-
USERNAME: ${{ secrets.DEPLOY_USERNAME }}
124-
with:
125-
host: ${{ secrets.DEPLOY_HOST }}
126-
username: ${{ secrets.DEPLOY_USERNAME }}
127-
key: ${{ secrets.DEPLOY_KEY }}
128-
port: 22
129-
envs: APPTOKEN,USERNAME
130-
script: |
131-
set -e
132-
echo $APPTOKEN | docker login ghcr.io -u $USERNAME --password-stdin
133-
cd ~/.deploy/${{ github.event.repository.name }}
134-
docker compose pull
135-
export APP_ID=$(docker compose run --entrypoint "id -u" --rm app)
136-
docker compose run --entrypoint "chown $APP_ID:$APP_ID /app/App_Data" --user root --rm app
137-
docker compose up app-migration --exit-code-from app-migration
96+
kamal server exec --no-interactive "mkdir -p /opt/docker/${{ env.repository_name }}/App_Data && chown -R 1654:1654 /opt/docker/${{ env.repository_name }}"
13897
139-
# Deploy Docker image with your application using `docker compose up` remotely
140-
- name: remote docker-compose up via ssh
141-
uses: appleboy/ssh-action@v0.1.5
142-
env:
143-
APPTOKEN: ${{ secrets.GITHUB_TOKEN }}
144-
USERNAME: ${{ secrets.DEPLOY_USERNAME }}
145-
with:
146-
host: ${{ secrets.DEPLOY_HOST }}
147-
username: ${{ secrets.DEPLOY_USERNAME }}
148-
key: ${{ secrets.DEPLOY_KEY }}
149-
port: 22
150-
envs: APPTOKEN,USERNAME
151-
script: |
152-
echo $APPTOKEN | docker login ghcr.io -u $USERNAME --password-stdin
153-
cd ~/.deploy/${{ github.event.repository.name }}
154-
docker compose pull
155-
docker compose up app -d
98+
- name: Migration
99+
if: env.HAS_MIGRATIONS == 'true'
100+
run: |
101+
kamal server exec --no-interactive 'echo "${{ env.KAMAL_REGISTRY_PASSWORD }}" | docker login ghcr.io -u ${{ env.KAMAL_REGISTRY_USERNAME }} --password-stdin'
102+
kamal server exec --no-interactive "docker pull ghcr.io/${{ env.image_repository_name }}:latest || true"
103+
kamal app exec --no-reuse --no-interactive --version=latest "--AppTasks=migrate"
104+
105+
- name: Deploy with Kamal
106+
run: |
107+
kamal lock release -v
108+
kamal deploy -P --version latest

.kamal/hooks/docker-setup.sample

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
#!/bin/sh
2+
3+
echo "Docker set up on $KAMAL_HOSTS..."

.kamal/hooks/post-deploy.sample

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
#!/bin/sh
2+
3+
# A sample post-deploy hook
4+
#
5+
# These environment variables are available:
6+
# KAMAL_RECORDED_AT
7+
# KAMAL_PERFORMER
8+
# KAMAL_VERSION
9+
# KAMAL_HOSTS
10+
# KAMAL_ROLE (if set)
11+
# KAMAL_DESTINATION (if set)
12+
# KAMAL_RUNTIME
13+
14+
echo "$KAMAL_PERFORMER deployed $KAMAL_VERSION to $KAMAL_DESTINATION in $KAMAL_RUNTIME seconds"
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
#!/bin/sh
2+
3+
echo "Rebooted kamal-proxy on $KAMAL_HOSTS"

0 commit comments

Comments
 (0)