+19
-28
@@ -14,17 +14,15 @@ jobs:
|
||||
DOMAIN: ${{ vars.DOMAIN }}
|
||||
IMAGE: ${{ vars.IMAGE }}
|
||||
IMAGE_REPO: ${{ vars.IMAGE_REPO }}
|
||||
PUSH_LATEST: ${{ vars.PUSH_LATEST }}
|
||||
REGISTRY: ${{ vars.REGISTRY }}
|
||||
REGISTRY_USER: ${{ secrets.REGISTRY_USER }}
|
||||
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
||||
REGISTRY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }}
|
||||
STACK_NAME: ${{ vars.STACK_NAME }}
|
||||
TRAEFIK_NETWORK: ${{ vars.TRAEFIK_NETWORK }}
|
||||
TRAEFIK_ENTRYPOINT: ${{ vars.TRAEFIK_ENTRYPOINT }}
|
||||
DEPLOY_HOST: ${{ vars.DEPLOY_HOST }}
|
||||
DEPLOY_PORT: ${{ vars.DEPLOY_PORT }}
|
||||
DEPLOY_USER: ${{ vars.DEPLOY_USER }}
|
||||
DEPLOY_SSH_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
||||
SWARM_MANAGER_HOST: ${{ secrets.SWARM_MANAGER_HOST }}
|
||||
SWARM_SSH_USER: ${{ secrets.SWARM_SSH_USER }}
|
||||
SWARM_SSH_PORT: ${{ secrets.SWARM_SSH_PORT }}
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
@@ -54,7 +52,7 @@ jobs:
|
||||
echo "STACK_NAME=${STACK_NAME:-progcode}"
|
||||
echo "TRAEFIK_NETWORK=${TRAEFIK_NETWORK:-traefik-public}"
|
||||
echo "TRAEFIK_ENTRYPOINT=${TRAEFIK_ENTRYPOINT:-websecure}"
|
||||
echo "DEPLOY_PORT=${DEPLOY_PORT:-22}"
|
||||
echo "SWARM_SSH_PORT=${SWARM_SSH_PORT:-22}"
|
||||
} >> "${GITHUB_ENV}"
|
||||
|
||||
- name: Docker login
|
||||
@@ -64,8 +62,8 @@ jobs:
|
||||
|
||||
if [ -n "${REGISTRY_PASSWORD}" ]; then
|
||||
: "${REGISTRY:?Set REGISTRY when REGISTRY_PASSWORD is configured}"
|
||||
: "${REGISTRY_USER:?Set REGISTRY_USER secret when REGISTRY_PASSWORD is configured}"
|
||||
echo "${REGISTRY_PASSWORD}" | docker login "${REGISTRY}" -u "${REGISTRY_USER}" --password-stdin
|
||||
: "${REGISTRY_USERNAME:?Set REGISTRY_USERNAME secret when REGISTRY_PASSWORD is configured}"
|
||||
echo "${REGISTRY_PASSWORD}" | docker login "${REGISTRY}" -u "${REGISTRY_USERNAME}" --password-stdin
|
||||
else
|
||||
echo "REGISTRY_PASSWORD is not set; skipping docker login"
|
||||
fi
|
||||
@@ -83,36 +81,29 @@ jobs:
|
||||
|
||||
docker push "${IMAGE}"
|
||||
|
||||
if [ "${PUSH_LATEST:-false}" = "true" ]; then
|
||||
latest_image="${IMAGE_REPO}:latest"
|
||||
latest_image="${IMAGE_REPO}:latest"
|
||||
if [ "${IMAGE}" != "${latest_image}" ]; then
|
||||
docker tag "${IMAGE}" "${latest_image}"
|
||||
docker push "${latest_image}"
|
||||
fi
|
||||
|
||||
- name: Configure remote Docker host
|
||||
if: ${{ vars.DEPLOY_HOST != '' }}
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
: "${DEPLOY_USER:?Set DEPLOY_USER when DEPLOY_HOST is configured}"
|
||||
: "${DEPLOY_SSH_KEY:?Set DEPLOY_SSH_KEY secret when DEPLOY_HOST is configured}"
|
||||
if [ -z "${SWARM_MANAGER_HOST}" ]; then
|
||||
echo "SWARM_MANAGER_HOST is not set; using the local Docker daemon"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
mkdir -p "${HOME}/.ssh"
|
||||
chmod 700 "${HOME}/.ssh"
|
||||
printf '%s\n' "${DEPLOY_SSH_KEY}" > "${HOME}/.ssh/id_deploy"
|
||||
chmod 600 "${HOME}/.ssh/id_deploy"
|
||||
ssh-keyscan -p "${DEPLOY_PORT}" "${DEPLOY_HOST}" >> "${HOME}/.ssh/known_hosts"
|
||||
: "${SWARM_SSH_USER:?Set SWARM_SSH_USER when SWARM_MANAGER_HOST is configured}"
|
||||
|
||||
cat > "${HOME}/.ssh/config" <<EOF
|
||||
Host swarm-manager
|
||||
HostName ${DEPLOY_HOST}
|
||||
Port ${DEPLOY_PORT}
|
||||
User ${DEPLOY_USER}
|
||||
IdentityFile ${HOME}/.ssh/id_deploy
|
||||
IdentitiesOnly yes
|
||||
EOF
|
||||
ssh -p "${SWARM_SSH_PORT}" \
|
||||
-o BatchMode=yes \
|
||||
"${SWARM_SSH_USER}@${SWARM_MANAGER_HOST}" \
|
||||
"docker info >/dev/null"
|
||||
|
||||
echo "DOCKER_HOST=ssh://swarm-manager" >> "${GITHUB_ENV}"
|
||||
echo "DOCKER_HOST=ssh://${SWARM_SSH_USER}@${SWARM_MANAGER_HOST}:${SWARM_SSH_PORT}" >> "${GITHUB_ENV}"
|
||||
|
||||
- name: Deploy stack
|
||||
shell: bash
|
||||
|
||||
@@ -42,16 +42,35 @@ Gitea Actions variables:
|
||||
- `STACK_NAME` — optional, defaults to `progcode`.
|
||||
- `TRAEFIK_NETWORK` — optional, defaults to `traefik-public`.
|
||||
- `TRAEFIK_ENTRYPOINT` — optional, defaults to `websecure`.
|
||||
- `PUSH_LATEST` — optional, set to `true` to also push `${IMAGE_REPO}:latest`.
|
||||
- The workflow also pushes `${IMAGE_REPO}:latest` automatically.
|
||||
|
||||
Gitea Actions secrets:
|
||||
|
||||
- `REGISTRY_USER`
|
||||
- `REGISTRY_USERNAME`
|
||||
- `REGISTRY_PASSWORD`
|
||||
- `DEPLOY_SSH_KEY` — only when deploying to a remote Swarm manager over SSH.
|
||||
- `SWARM_MANAGER_HOST`
|
||||
- `SWARM_SSH_USER`
|
||||
- `SWARM_SSH_PORT` — optional, defaults to `22`.
|
||||
|
||||
Remote Swarm deploy variables:
|
||||
The workflow follows the same SSH model as `ohuello`: the deploy SSH private key is not stored in Gitea secrets. It must be created on the Gitea runner host and mounted into job containers as `/root/.ssh:ro`, including `known_hosts`.
|
||||
|
||||
- `DEPLOY_HOST`
|
||||
- `DEPLOY_USER`
|
||||
- `DEPLOY_PORT` — optional, defaults to `22`.
|
||||
Example account or organization variables:
|
||||
|
||||
```text
|
||||
REGISTRY=git.example.com
|
||||
IMAGE_REPO=git.example.com/huncode/progcode
|
||||
DOMAIN=progcode.example.com
|
||||
STACK_NAME=progcode
|
||||
TRAEFIK_NETWORK=traefik-public
|
||||
TRAEFIK_ENTRYPOINT=websecure
|
||||
```
|
||||
|
||||
Example account or organization secrets:
|
||||
|
||||
```text
|
||||
REGISTRY_USERNAME=<gitea-user-or-token-user>
|
||||
REGISTRY_PASSWORD=<gitea-token>
|
||||
SWARM_MANAGER_HOST=<swarm-manager-origin-ip-or-ssh-host>
|
||||
SWARM_SSH_USER=deploy
|
||||
SWARM_SSH_PORT=22
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user