mirror of
https://gitlab.com/mbugroup/lti-api.git
synced 2026-05-20 05:21:57 +00:00
159 lines
4.6 KiB
YAML
159 lines
4.6 KiB
YAML
stages:
|
|
- build
|
|
- gitops
|
|
|
|
variables:
|
|
AWS_REGION: ap-southeast-3
|
|
ECR_REGISTRY: 886436954922.dkr.ecr.ap-southeast-3.amazonaws.com
|
|
ECR_REPO_NAME: mbugroup/lti-api
|
|
ECR_REPOSITORY: ${ECR_REGISTRY}/${ECR_REPO_NAME}
|
|
|
|
DOCKER_HOST: unix:///var/run/docker.sock
|
|
DOCKER_TLS_CERTDIR: ""
|
|
DOCKER_BUILDKIT: "1"
|
|
|
|
workflow:
|
|
rules:
|
|
- if: '$CI_COMMIT_BRANCH'
|
|
|
|
# =========================
|
|
# Helper: login ECR
|
|
# =========================
|
|
.ecr_login: &ecr_login |
|
|
AWS_CLI_ENV_ARGS=""
|
|
AWS_CLI_ENV_ARGS="$AWS_CLI_ENV_ARGS -e AWS_REGION=$AWS_REGION"
|
|
AWS_CLI_ENV_ARGS="$AWS_CLI_ENV_ARGS -e AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID:-}"
|
|
AWS_CLI_ENV_ARGS="$AWS_CLI_ENV_ARGS -e AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY:-}"
|
|
if [ -n "${AWS_SESSION_TOKEN:-}" ]; then
|
|
AWS_CLI_ENV_ARGS="$AWS_CLI_ENV_ARGS -e AWS_SESSION_TOKEN=$AWS_SESSION_TOKEN"
|
|
fi
|
|
|
|
PASS="$(docker run --rm $AWS_CLI_ENV_ARGS public.ecr.aws/aws-cli/aws-cli:latest \
|
|
ecr get-login-password --region "$AWS_REGION" || true)"
|
|
if [ -z "$PASS" ]; then
|
|
echo "ERROR: Failed to get ECR login password."
|
|
exit 1
|
|
fi
|
|
echo "$PASS" | docker login --username AWS --password-stdin "$ECR_REGISTRY"
|
|
|
|
# =========================
|
|
# DEV
|
|
# =========================
|
|
build_push_dev_lti:
|
|
stage: build
|
|
image: public.ecr.aws/docker/library/docker:27
|
|
tags: [self-hosted-dev]
|
|
rules:
|
|
- if: '$CI_COMMIT_BRANCH == "development"'
|
|
variables:
|
|
IMAGE_TAG: "dev-${CI_COMMIT_SHORT_SHA}"
|
|
before_script:
|
|
- set -eu
|
|
- docker version
|
|
- docker info
|
|
- *ecr_login
|
|
script: |
|
|
set -eu
|
|
echo "Build & push: $ECR_REPOSITORY:$IMAGE_TAG"
|
|
|
|
docker build \
|
|
-t "$ECR_REPOSITORY:$IMAGE_TAG" \
|
|
.
|
|
|
|
docker push "$ECR_REPOSITORY:$IMAGE_TAG"
|
|
|
|
update_gitops_dev_lti:
|
|
stage: gitops
|
|
image: public.ecr.aws/docker/library/alpine:3.20
|
|
tags: [self-hosted-dev]
|
|
rules:
|
|
- if: '$CI_COMMIT_BRANCH == "development"'
|
|
needs: ["build_push_dev_lti"]
|
|
variables:
|
|
IMAGE_TAG: "dev-${CI_COMMIT_SHORT_SHA}"
|
|
GITOPS_BRANCH: main
|
|
VALUES_FILE: environments/lti/dev/lti-values-dev.yaml
|
|
GITOPS_REPO_URL: https://oauth2:${GITOPS_TOKEN}@gitlab.com/cristian.anggita.parjaman/gitops.git
|
|
before_script:
|
|
- set -eu
|
|
- apk add --no-cache git yq
|
|
- git config --global user.email "ci@gitlab"
|
|
- git config --global user.name "gitlab-ci"
|
|
script: |
|
|
set -eu
|
|
rm -rf gitops
|
|
git clone --depth 1 --branch "$GITOPS_BRANCH" "$GITOPS_REPO_URL" gitops
|
|
cd gitops
|
|
|
|
echo "Updating DEV image.tag to $IMAGE_TAG in $VALUES_FILE"
|
|
yq -i '.image.repository = strenv(ECR_REPOSITORY)' "$VALUES_FILE"
|
|
yq -i '.image.tag = strenv(IMAGE_TAG)' "$VALUES_FILE"
|
|
|
|
git add "$VALUES_FILE"
|
|
if git diff --cached --quiet; then
|
|
echo "No changes to commit"
|
|
exit 0
|
|
fi
|
|
git commit -m "lti dev deploy ${IMAGE_TAG}"
|
|
git push origin "$GITOPS_BRANCH"
|
|
|
|
# =========================
|
|
# PROD
|
|
# =========================
|
|
# build_push_prod_lti:
|
|
# stage: build
|
|
# image: public.ecr.aws/docker/library/docker:27
|
|
# tags: [self-hosted-dev]
|
|
# rules:
|
|
# - if: '$CI_COMMIT_BRANCH == "production"'
|
|
# variables:
|
|
# IMAGE_TAG: "prod-${CI_COMMIT_SHORT_SHA}"
|
|
# before_script:
|
|
# - set -eu
|
|
# - docker version
|
|
# - docker info
|
|
# - *ecr_login
|
|
# script: |
|
|
# set -eu
|
|
# echo "Build & push: $ECR_REPOSITORY:$IMAGE_TAG"
|
|
|
|
# docker build \
|
|
# -t "$ECR_REPOSITORY:$IMAGE_TAG" \
|
|
# .
|
|
|
|
# docker push "$ECR_REPOSITORY:$IMAGE_TAG"
|
|
|
|
# update_gitops_prod_lti:
|
|
# stage: gitops
|
|
# image: public.ecr.aws/docker/library/alpine:3.20
|
|
# tags: [self-hosted-dev]
|
|
# rules:
|
|
# - if: '$CI_COMMIT_BRANCH == "production"'
|
|
# needs: ["build_push_prod_lti"]
|
|
# variables:
|
|
# IMAGE_TAG: "prod-${CI_COMMIT_SHORT_SHA}"
|
|
# GITOPS_BRANCH: main
|
|
# VALUES_FILE: environments/lti/prod/lti-values-prod.yaml
|
|
# GITOPS_REPO_URL: https://oauth2:${GITOPS_TOKEN}@gitlab.com/cristian.anggita.parjaman/gitops.git
|
|
# before_script:
|
|
# - set -eu
|
|
# - apk add --no-cache git yq
|
|
# - git config --global user.email "ci@gitlab"
|
|
# - git config --global user.name "gitlab-ci"
|
|
# script: |
|
|
# set -eu
|
|
# rm -rf gitops
|
|
# git clone --depth 1 --branch "$GITOPS_BRANCH" "$GITOPS_REPO_URL" gitops
|
|
# cd gitops
|
|
|
|
# echo "Updating PROD image.tag to $IMAGE_TAG in $VALUES_FILE"
|
|
# yq -i '.image.repository = strenv(ECR_REPOSITORY)' "$VALUES_FILE"
|
|
# yq -i '.image.tag = strenv(IMAGE_TAG)' "$VALUES_FILE"
|
|
|
|
# git add "$VALUES_FILE"
|
|
# if git diff --cached --quiet; then
|
|
# echo "No changes to commit"
|
|
# exit 0
|
|
# fi
|
|
# git commit -m "lti prod deploy ${IMAGE_TAG}"
|
|
# git push origin "$GITOPS_BRANCH" |