something to do with... (#59)

* something to do with...

* kill and die

* ririri midori
This commit is contained in:
zk
2026-04-28 22:56:24 +01:00
committed by GitHub
parent b8a98b581c
commit 374f1af8e0
31 changed files with 29689 additions and 450 deletions
+46 -25
View File
@@ -6,54 +6,75 @@ on:
- "main"
paths:
- "github-bot/**"
- "docker/Dockerfile.ghbot"
- ".github/workflows/github-bot.yml"
workflow_dispatch:
permissions:
contents: read
jobs:
docker-push:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@v3
- name: Docker Hub login
uses: docker/login-action@v2
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_TOKEN }}
persist-credentials: false
- name: Image name (lowercase for GHCR)
env:
OWNER_RAW: ${{ github.repository_owner }}
run: |
OWNER="$(echo "$OWNER_RAW" | tr '[:upper:]' '[:lower:]')"
echo "GHBOT_IMAGE=ghcr.io/${OWNER}/tachi-ghbot" >> "$GITHUB_ENV"
- name: Log in to GHCR
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
- name: Build and push
id: docker_build
uses: docker/build-push-action@v3
uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6.10.0
with:
context: ./
push: true
tags: ${{ secrets.DOCKER_USERNAME }}/tachi-gh-bot:stable
file: ./Dockerfile.ghbot
cache-from: type=gha,scope=$GITHUB_REF_NAME-github-bot
cache-to: type=gha,mode=max,scope=$GITHUB_REF_NAME-github-bot
context: .
file: docker/Dockerfile.ghbot
push: ${{ github.ref == 'refs/heads/main' }}
provenance: true
sbom: true
tags: |
${{ env.GHBOT_IMAGE }}:${{ github.sha }}
${{ env.GHBOT_IMAGE }}:main
cache-from: type=gha,scope=${{ github.ref_name }}-github-bot
cache-to: type=gha,mode=max,scope=${{ github.ref_name }}-github-bot
- name: Image digest
run: echo ${{ steps.docker_build.outputs.digest }}
run: echo "${{ steps.docker_build.outputs.digest }}"
deploy:
runs-on: ubuntu-latest
needs: [docker-push]
if: ${{ github.event_name == 'push' || github.event_name == 'workflow_dispatch' }}
if: ${{ github.ref == 'refs/heads/main' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') }}
steps:
- name: Enable SSH Key
env:
SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }}
SSH_KNOWN_HOSTS: ${{ secrets.SSH_KNOWN_HOSTS }}
run: |
mkdir -p ~/.ssh
echo "$SSH_PRIVATE_KEY" > ~/.ssh/id_rsa
sudo chmod 600 ~/.ssh/id_rsa
echo "$SSH_KNOWN_HOSTS" > ~/.ssh/known_hosts
env:
SSH_PRIVATE_KEY: ${{secrets.SSH_PRIVATE_KEY}}
SSH_KNOWN_HOSTS: ${{secrets.SSH_KNOWN_HOSTS}}
printf '%s' "$SSH_PRIVATE_KEY" > ~/.ssh/id_rsa
chmod 600 ~/.ssh/id_rsa
printf '%s' "$SSH_KNOWN_HOSTS" > ~/.ssh/known_hosts
- name: Deploy updates
run: ssh ci@"$TACHI_HOST" /home/ci/tachi-devops/scripts/deploy_bot.sh
env:
TACHI_HOST: ${{secrets.TACHI_HOST}}
TACHI_HOST: ${{ secrets.TACHI_HOST }}
run: ssh "ci@${TACHI_HOST}" /opt/tachi/deploy/scripts/deploy-ghbot.sh