name: Monorepo Pipeline on: push: branches: - '**' tags: - '*' concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: prioritize: name: โšก Prioritize Release runs-on: docker container: image: catthehacker/ubuntu:act-latest steps: - name: ๐Ÿ›‘ Cancel Redundant Runs env: GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }} REPO: ${{ github.repository }} RUN_ID: ${{ github.run_id }} REF: ${{ github.ref }} REF_NAME: ${{ github.ref_name }} EVENT: ${{ github.event_name }} SHA: ${{ github.sha }} run: | echo "๐Ÿ”Ž Debug: Event=$EVENT, Ref=$REF, RefName=$REF_NAME, RunId=$RUN_ID" # Fetch recent runs for the repository RUNS=$(curl -s -H "Authorization: token $GITEA_TOKEN" "https://git.infra.mintel.me/api/v1/repos/$REPO/actions/runs?limit=30") case "$REF" in refs/tags/*) echo "๐Ÿš€ Release detected ($REF_NAME). Cancelling non-tag runs..." # Identify runs to cancel: in_progress/queued, NOT this run, and NOT a tag run echo "$RUNS" | jq -c '.workflow_runs[] | select(.status == "in_progress" or .status == "queued") | select(.id | tostring != "'$RUN_ID'")' | while read -r run; do ID=$(echo "$run" | jq -r '.id') RUN_REF=$(echo "$run" | jq -r '.ref') TITLE=$(echo "$run" | jq -r '.display_title') case "$RUN_REF" in refs/tags/*) echo "โญ๏ธ Skipping parallel release run $ID ($TITLE) on $RUN_REF" ;; *) echo "๐Ÿ›‘ Cancelling redundant branch run $ID ($TITLE) on $RUN_REF..." curl -X POST -s -H "Authorization: token $GITEA_TOKEN" "https://git.infra.mintel.me/api/v1/repos/$REPO/actions/runs/$ID/cancel" ;; esac done ;; *) echo "โ„น๏ธ Regular push. Checking for parallel release tag for SHA $SHA..." # Check if there's a tag run for the SAME commit TAG_RUN_ID=$(echo "$RUNS" | jq -r '.workflow_runs[] | select(.ref | startswith("refs/tags/")) | select(.head_sha == "'$SHA'") | .id' | head -n 1) if [[ -n "$TAG_RUN_ID" && "$TAG_RUN_ID" != "null" ]]; then echo "๐Ÿš€ Found parallel tag run $TAG_RUN_ID for commit $SHA. Cancelling this branch run ($RUN_ID)..." curl -X POST -s -H "Authorization: token $GITEA_TOKEN" "https://git.infra.mintel.me/api/v1/repos/$REPO/actions/runs/$RUN_ID/cancel" exit 0 fi echo "โœ… No parallel tag run found. Proceeding." ;; esac lint: name: ๐Ÿงน Lint needs: prioritize if: always() && !cancelled() && (needs.prioritize.result == 'success' || needs.prioritize.result == 'skipped') runs-on: docker container: image: catthehacker/ubuntu:act-latest env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Node.js uses: actions/setup-node@v4 with: node_version: 20 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.2.0 --activate - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline --ignore-scripts --no-color - name: Lint run: pnpm lint - name: Check Dependencies (Depcheck) run: pnpm -r exec npx --yes depcheck --skip-missing --ignores="eslint*,@eslint/*,@types/*,typescript,tsup,tsx,vitest,tailwindcss,postcss,autoprefixer,@mintel/*,ts-node,*in-the-middle,pino*,@commitlint/*,@changesets/*,globals" test: name: ๐Ÿงช Test needs: prioritize if: always() && !cancelled() && (needs.prioritize.result == 'success' || needs.prioritize.result == 'skipped') runs-on: docker container: image: catthehacker/ubuntu:act-latest env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Node.js uses: actions/setup-node@v4 with: node_version: 20 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.2.0 --activate - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline --ignore-scripts --no-color - name: Test run: pnpm test build: name: ๐Ÿ—๏ธ Build needs: prioritize if: always() && !cancelled() && (needs.prioritize.result == 'success' || needs.prioritize.result == 'skipped') runs-on: docker container: image: catthehacker/ubuntu:act-latest env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Node.js uses: actions/setup-node@v4 with: node_version: 20 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.2.0 --activate - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline --ignore-scripts --no-color - name: Build run: pnpm build release: name: ๐Ÿš€ Release needs: [lint, test, build] if: startsWith(github.ref, 'refs/tags/') runs-on: docker container: image: catthehacker/ubuntu:act-latest env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 with: fetch-depth: 0 - name: Set up Node.js uses: actions/setup-node@v4 with: node_version: 20 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.2.0 --activate - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline --ignore-scripts --no-color - name: ๐Ÿท๏ธ Sync Versions (if Tagged) run: pnpm sync-versions - name: ๐Ÿท๏ธ Release Packages (Tag-Driven) run: | echo "๐Ÿท๏ธ Tag detected [${{ github.ref_name }}], performing sync release..." pnpm release:tag build-images: name: ๐Ÿณ Build ${{ matrix.name }} needs: [lint, test, build] if: startsWith(github.ref, 'refs/tags/') runs-on: docker container: image: catthehacker/ubuntu:act-latest strategy: fail-fast: false max-parallel: 1 matrix: include: - image: nextjs file: packages/infra/docker/Dockerfile.nextjs name: Build-Base - image: runtime file: packages/infra/docker/Dockerfile.runtime name: Production Runtime - image: gatekeeper file: packages/infra/docker/Dockerfile.gatekeeper name: Gatekeeper (Product) - image: image-processor file: apps/image-service/Dockerfile name: Image Processor steps: - name: Checkout uses: actions/checkout@v4 - name: ๐Ÿณ Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: ๐Ÿ” Registry Login uses: docker/login-action@v3 with: registry: registry.infra.mintel.me username: ${{ secrets.REGISTRY_USER }} password: ${{ secrets.REGISTRY_PASS }} - name: ๐Ÿ—๏ธ Build & Push ${{ matrix.name }} uses: docker/build-push-action@v5 with: context: . file: ${{ matrix.file }} platforms: linux/amd64 pull: true provenance: false push: true secrets: | NPM_TOKEN=${{ secrets.NPM_TOKEN }} tags: | registry.infra.mintel.me/mintel/${{ matrix.image }}:${{ github.ref_name }} registry.infra.mintel.me/mintel/${{ matrix.image }}:latest