name: Build & Deploy KLZ Cables on: push: branches: - main jobs: deploy: runs-on: docker steps: - name: Checkout repo uses: actions/checkout@v3 - name: Install tools run: | apt-get update apt-get install -y \ docker.io \ openssh-client \ rsync \ qemu-user-static \ binfmt-support - name: Set up QEMU run: | docker run --rm --privileged multiarch/qemu-user-static --reset -p yes - name: Login to registry env: REGISTRY_USER: ${{ secrets.REGISTRY_USER }} REGISTRY_PASS: ${{ secrets.REGISTRY_PASS }} run: | echo "$REGISTRY_PASS" | DOCKER_API_VERSION=1.44 docker login registry.infra.mintel.me -u "$REGISTRY_USER" --password-stdin - name: Build image for AMD64 run: | # Build for AMD64 (x86_64) DOCKER_API_VERSION=1.44 docker build \ --platform linux/amd64 \ --pull \ --build-arg NEXT_PUBLIC_UMAMI_WEBSITE_ID=${{ secrets.NEXT_PUBLIC_UMAMI_WEBSITE_ID }} \ --build-arg NEXT_PUBLIC_UMAMI_SCRIPT_URL=${{ secrets.NEXT_PUBLIC_UMAMI_SCRIPT_URL }} \ --build-arg NEXT_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }} \ -t registry.infra.mintel.me/mintel/klz-cables.com:amd64 . - name: Build image for ARM64 run: | # Build for ARM64 using QEMU emulation DOCKER_API_VERSION=1.44 docker build \ --platform linux/arm64 \ --pull \ --build-arg NEXT_PUBLIC_UMAMI_WEBSITE_ID=${{ secrets.NEXT_PUBLIC_UMAMI_WEBSITE_ID }} \ --build-arg NEXT_PUBLIC_UMAMI_SCRIPT_URL=${{ secrets.NEXT_PUBLIC_UMAMI_SCRIPT_URL }} \ --build-arg NEXT_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }} \ -t registry.infra.mintel.me/mintel/klz-cables.com:arm64 . - name: Push architecture-specific images run: | # Push both architecture-specific images DOCKER_API_VERSION=1.44 docker push registry.infra.mintel.me/mintel/klz-cables.com:amd64 DOCKER_API_VERSION=1.44 docker push registry.infra.mintel.me/mintel/klz-cables.com:arm64 - name: Create and push multi-arch manifest run: | # Create multi-arch manifest DOCKER_API_VERSION=1.44 docker manifest create \ registry.infra.mintel.me/mintel/klz-cables.com:latest \ registry.infra.mintel.me/mintel/klz-cables.com:amd64 \ registry.infra.mintel.me/mintel/klz-cables.com:arm64 # Push the manifest DOCKER_API_VERSION=1.44 docker manifest push \ registry.infra.mintel.me/mintel/klz-cables.com:latest - name: Setup SSH run: | mkdir -p ~/.ssh printf "%s\n" "${{ secrets.ALPHA_SSH_KEY }}" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 ssh-keyscan -H alpha.mintel.me >> ~/.ssh/known_hosts - name: Deploy on server run: | # Bundle files and secrets, then run deployment in ONE connection tar czf - docker-compose.yml varnish 2>/dev/null | \ ssh -i ~/.ssh/id_ed25519 -o StrictHostKeyChecking=no -o IPQoS=0x00 deploy@alpha.mintel.me " set -e mkdir -p /home/deploy/sites/klz-cables.com/ tar xzf - -C /home/deploy/sites/klz-cables.com/ cd /home/deploy/sites/klz-cables.com/ echo '=== Creating .env ===' cat > .env << EOF NEXT_PUBLIC_UMAMI_WEBSITE_ID=${{ secrets.NEXT_PUBLIC_UMAMI_WEBSITE_ID }} NEXT_PUBLIC_UMAMI_SCRIPT_URL=${{ secrets.NEXT_PUBLIC_UMAMI_SCRIPT_URL }} SENTRY_DSN=${{ secrets.SENTRY_DSN }} REDIS_URL=${{ secrets.REDIS_URL }} REDIS_KEY_PREFIX=${{ secrets.REDIS_KEY_PREFIX }} EOF echo '=== Login & Pull ===' echo '${{ secrets.REGISTRY_PASS }}' | docker login registry.infra.mintel.me -u '${{ secrets.REGISTRY_USER }}' --password-stdin docker pull registry.infra.mintel.me/mintel/klz-cables.com:latest echo '=== Run ===' # Force recreate ensures the new image is used docker compose up -d --force-recreate --remove-orphans echo '=== Done ===' "