name: Monorepo Pipeline on: push: branches: - '**' tags: - 'v*' concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: prioritize: name: โšก Prioritize Release runs-on: docker container: image: catthehacker/ubuntu:act-latest steps: - name: ๐Ÿ›‘ Cancel Redundant Runs env: GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }} REPO: ${{ github.repository }} RUN_ID: ${{ github.run_id }} REF: ${{ github.ref }} REF_NAME: ${{ github.ref_name }} EVENT: ${{ github.event_name }} run: | echo "๐Ÿ”Ž Debug: Event=$EVENT, Ref=$REF, RefName=$REF_NAME, RunId=$RUN_ID" case "$REF" in refs/tags/v*) echo "๐Ÿš€ Release detected ($REF_NAME). Cancelling non-tag runs..." # Fetch all runs RUNS=$(curl -s -H "Authorization: token $GITEA_TOKEN" "https://git.infra.mintel.me/api/v1/repos/$REPO/actions/runs") # Identify runs to cancel: in_progress/queued, NOT this run, and NOT a tag run echo "$RUNS" | jq -c '.workflow_runs[] | select(.status == "in_progress" or .status == "queued") | select(.id | tostring != "'$RUN_ID'")' | while read -r run; do ID=$(echo "$run" | jq -r '.id') RUN_REF=$(echo "$run" | jq -r '.ref') TITLE=$(echo "$run" | jq -r '.display_title') case "$RUN_REF" in refs/tags/v*) echo "โญ๏ธ Skipping parallel release run $ID ($TITLE) on $RUN_REF" ;; *) echo "๐Ÿ›‘ Cancelling redundant branch run $ID ($TITLE) on $RUN_REF..." curl -X POST -s -H "Authorization: token $GITEA_TOKEN" "https://git.infra.mintel.me/api/v1/repos/$REPO/actions/runs/$ID/cancel" ;; esac done ;; *) echo "โ„น๏ธ Regular push. No prioritization needed." ;; esac lint: name: ๐Ÿงน Lint needs: prioritize if: always() && !cancelled() && (needs.prioritize.result == 'success' || needs.prioritize.result == 'skipped') runs-on: docker container: image: catthehacker/ubuntu:act-latest env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Node.js uses: actions/setup-node@v4 with: node_version: 20 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.2.0 --activate - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline --ignore-scripts --no-color - name: Lint run: pnpm lint test: name: ๐Ÿงช Test needs: prioritize if: always() && !cancelled() && (needs.prioritize.result == 'success' || needs.prioritize.result == 'skipped') runs-on: docker container: image: catthehacker/ubuntu:act-latest env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Node.js uses: actions/setup-node@v4 with: node_version: 20 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.2.0 --activate - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline --ignore-scripts --no-color - name: Test run: pnpm test build: name: ๐Ÿ—๏ธ Build needs: prioritize if: always() && !cancelled() && (needs.prioritize.result == 'success' || needs.prioritize.result == 'skipped') runs-on: docker container: image: catthehacker/ubuntu:act-latest env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Node.js uses: actions/setup-node@v4 with: node_version: 20 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.2.0 --activate - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline --ignore-scripts --no-color - name: Build run: pnpm build release: name: ๐Ÿš€ Release needs: [lint, test, build] if: startsWith(github.ref, 'refs/tags/v') runs-on: docker container: image: catthehacker/ubuntu:act-latest env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 with: fetch-depth: 0 - name: Set up Node.js uses: actions/setup-node@v4 with: node_version: 20 - name: Enable pnpm run: corepack enable && corepack prepare pnpm@10.2.0 --activate - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline --ignore-scripts --no-color - name: ๐Ÿท๏ธ Sync Versions (if Tagged) run: pnpm sync-versions - name: ๐Ÿท๏ธ Release Packages (Tag-Driven) run: | echo "๐Ÿท๏ธ Tag detected [${{ github.ref_name }}], performing sync release..." pnpm release:tag build-images: name: ๐Ÿณ Build ${{ matrix.name }} needs: [lint, test, build] if: startsWith(github.ref, 'refs/tags/v') runs-on: docker container: image: catthehacker/ubuntu:act-latest strategy: fail-fast: false max-parallel: 1 matrix: include: - image: nextjs file: packages/infra/docker/Dockerfile.nextjs name: Build-Base - image: runtime file: packages/infra/docker/Dockerfile.runtime name: Production Runtime - image: gatekeeper file: packages/infra/docker/Dockerfile.gatekeeper name: Gatekeeper (Product) - image: directus file: packages/infra/docker/Dockerfile.directus name: Directus (Base) steps: - name: Checkout uses: actions/checkout@v4 - name: ๐Ÿณ Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: ๐Ÿ” Registry Login uses: docker/login-action@v3 with: registry: registry.infra.mintel.me username: ${{ secrets.REGISTRY_USER }} password: ${{ secrets.REGISTRY_PASS }} - name: ๐Ÿ—๏ธ Build & Push ${{ matrix.name }} uses: docker/build-push-action@v5 with: context: . file: ${{ matrix.file }} platforms: linux/arm64 pull: true push: true secrets: | NPM_TOKEN=${{ secrets.NPM_TOKEN }} tags: | registry.infra.mintel.me/mintel/${{ matrix.image }}:${{ github.ref_name }} registry.infra.mintel.me/mintel/${{ matrix.image }}:latest cache-from: type=registry,ref=registry.infra.mintel.me/mintel/${{ matrix.image }}:buildcache cache-to: type=registry,ref=registry.infra.mintel.me/mintel/${{ matrix.image }}:buildcache,mode=max