name: Build & Deploy on: push: branches: - main jobs: deploy: runs-on: docker steps: # --- Tools --- - name: Install tools run: | apt-get update apt-get install -y \ git \ docker.io \ openssh-client \ rsync # --- Checkout --- - name: Checkout repo run: | git clone https://git.infra.mintel.me/mmintel/klz-cables.com.git . git checkout main # --- Docker registry login --- - name: Login to registry env: REGISTRY_USER: ${{ secrets.REGISTRY_USER }} REGISTRY_PASS: ${{ secrets.REGISTRY_PASS }} run: | echo "$REGISTRY_PASS" | docker login registry.infra.mintel.me \ -u "$REGISTRY_USER" \ --password-stdin # --- Build image --- - name: Build image run: | docker build \ --pull \ -t registry.infra.mintel.me/mintel/klz-cables.com:latest . # --- Push image --- - name: Push image run: | docker push registry.infra.mintel.me/mintel/klz-cables.com:latest # --- SSH setup --- - name: Setup SSH run: | mkdir -p ~/.ssh echo "${{ secrets.ALPHA_SSH_KEY }}" > ~/.ssh/id_deploy chmod 600 ~/.ssh/id_deploy ssh-keyscan -H alpha.mintel.me >> ~/.ssh/known_hosts # --- Sync files --- - name: Sync files to server run: | tar czf - docker-compose.y*ml $([ -d ./varnish ] && echo varnish) | \ ssh -i ~/.ssh/id_deploy -o StrictHostKeyChecking=no deploy@alpha.mintel.me \ "mkdir -p /home/deploy/sites/klz-cables.com/ && tar xzf - -C /home/deploy/sites/klz-cables.com/" # --- Deploy --- - name: Deploy on server run: | ssh -i ~/.ssh/id_deploy -o StrictHostKeyChecking=no deploy@alpha.mintel.me ' cd /home/deploy/sites/klz-cables.com && (docker compose -f docker-compose.yml pull 2>/dev/null || docker compose -f docker-compose.yaml pull) && docker image prune -f && docker compose up -d '