ci: add Gitea Actions workflow + fix docker-compose for registry pull
Workflow (3 jobs, all on the local netork-runner on 10.7.224.11):
typecheck (ubuntu-latest)
→ npm ci + tsc --noEmit on every push/PR
publish (ubuntu-latest, main only)
→ docker build + push to registry.netork.io/netork/website:latest
and registry.netork.io/netork/website:main-<sha>
deploy (build/host, after publish)
→ runs directly on the host (no SSH needed)
→ copies docker-compose.yml to /opt/netork-website/
→ docker compose pull + up -d --remove-orphans
docker-compose.yml: replaced local build: . with
registry.netork.io/netork/website:latest so the deploy job
pulls the just-published image instead of building again.
Required Gitea secrets: REGISTRY_USER, REGISTRY_PASSWORD
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
efa01b5f41
commit
3ddf3b78b4
+10
-16
@@ -52,28 +52,22 @@ jobs:
|
|||||||
|
|
||||||
deploy:
|
deploy:
|
||||||
name: Deploy — pull & restart on host
|
name: Deploy — pull & restart on host
|
||||||
runs-on: ubuntu-latest
|
runs-on: build
|
||||||
needs: [publish]
|
needs: [publish]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Write SSH key
|
- name: Login to registry
|
||||||
run: |
|
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.netork.io -u "${{ secrets.REGISTRY_USER }}" --password-stdin
|
||||||
mkdir -p ~/.ssh
|
|
||||||
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
|
|
||||||
chmod 600 ~/.ssh/deploy_key
|
|
||||||
ssh-keyscan -H "${{ secrets.DEPLOY_HOST }}" >> ~/.ssh/known_hosts 2>/dev/null
|
|
||||||
|
|
||||||
- name: Deploy
|
- name: Deploy
|
||||||
run: |
|
run: |
|
||||||
ssh -i ~/.ssh/deploy_key -o StrictHostKeyChecking=no \
|
mkdir -p /opt/netork-website
|
||||||
"${{ secrets.DEPLOY_USER }}@${{ secrets.DEPLOY_HOST }}" \
|
cp docker-compose.yml /opt/netork-website/docker-compose.yml
|
||||||
"cd /opt/netork-website && \
|
cd /opt/netork-website
|
||||||
echo '${{ secrets.REGISTRY_PASSWORD }}' | docker login registry.netork.io -u '${{ secrets.REGISTRY_USER }}' --password-stdin && \
|
docker compose pull
|
||||||
docker compose pull && \
|
docker compose up -d --remove-orphans
|
||||||
docker compose up -d --remove-orphans && \
|
|
||||||
docker logout registry.netork.io"
|
|
||||||
|
|
||||||
- name: Clean up SSH key
|
- name: Logout
|
||||||
if: always()
|
if: always()
|
||||||
run: rm -f ~/.ssh/deploy_key
|
run: docker logout registry.netork.io
|
||||||
|
|||||||
+1
-2
@@ -1,7 +1,6 @@
|
|||||||
services:
|
services:
|
||||||
netork-website:
|
netork-website:
|
||||||
build: .
|
image: registry.netork.io/netork/website:latest
|
||||||
image: netork-website:latest
|
|
||||||
container_name: netork-website
|
container_name: netork-website
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
expose:
|
expose:
|
||||||
|
|||||||
Reference in New Issue
Block a user