diff --git a/.github/workflows/bot.yml b/.github/workflows/bot.yml index 326f2de4d..04afd1a31 100644 --- a/.github/workflows/bot.yml +++ b/.github/workflows/bot.yml @@ -21,16 +21,17 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: persist-credentials: false - name: Image name (lowercase for GHCR) env: - OWNER_RAW: ${{ github.repository_owner }} + REPO: ${{ github.repository }} run: | - OWNER="$(echo "$OWNER_RAW" | tr '[:upper:]' '[:lower:]')" - echo "BOT_IMAGE=ghcr.io/${OWNER}/tachi-bot" >> "$GITHUB_ENV" + REPO_LC="$(echo "$REPO" | tr '[:upper:]' '[:lower:]')" + echo "BOT_IMAGE=ghcr.io/${REPO_LC}-bot" >> "$GITHUB_ENV" - name: Log in to GHCR uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 @@ -67,7 +68,7 @@ jobs: matrix: destination: [boku, kamai, dev] steps: - - name: Enable SSH Key + - name: Enable SSH env: SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }} SSH_KNOWN_HOSTS: ${{ secrets.SSH_KNOWN_HOSTS }} diff --git a/.github/workflows/client.yml b/.github/workflows/client.yml index a520f2c7a..04d587941 100644 --- a/.github/workflows/client.yml +++ b/.github/workflows/client.yml @@ -25,10 +25,11 @@ jobs: test: runs-on: ubuntu-latest container: - image: ghcr.io/zkldi/tachi-dev:main + image: "ghcr.io/${{ github.repository }}-dev:main" options: --user root steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: persist-credentials: false @@ -44,12 +45,13 @@ jobs: build: runs-on: ubuntu-latest container: - image: ghcr.io/zkldi/tachi-dev:main + image: "ghcr.io/${{ github.repository }}-dev:main" options: --user root needs: test if: ${{ github.ref == 'refs/heads/main' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') }} steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: persist-credentials: false @@ -128,7 +130,7 @@ jobs: mkdir -p /tmp/boku /tmp/kamai /tmp/dev tar -C /tmp -xzf client-builds.tgz - - name: Enable SSH Key + - name: Enable SSH env: SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }} SSH_KNOWN_HOSTS: ${{ secrets.SSH_KNOWN_HOSTS }} diff --git a/.github/workflows/common.yml b/.github/workflows/common.yml index 9baef543d..f52cb8bf8 100644 --- a/.github/workflows/common.yml +++ b/.github/workflows/common.yml @@ -22,7 +22,7 @@ jobs: test: runs-on: ubuntu-latest container: - image: ghcr.io/zkldi/tachi-dev:main + image: "ghcr.io/${{ github.repository }}-dev:main" options: --user root steps: - name: Checkout diff --git a/.github/workflows/database-seeds.yml b/.github/workflows/database-seeds.yml index 189f2eb4c..a45e9b140 100644 --- a/.github/workflows/database-seeds.yml +++ b/.github/workflows/database-seeds.yml @@ -26,7 +26,7 @@ jobs: test: runs-on: ubuntu-latest container: - image: ghcr.io/zkldi/tachi-dev:main + image: "ghcr.io/${{ github.repository }}-dev:main" options: --user root steps: - name: Checkout @@ -50,7 +50,7 @@ jobs: group: "seeds-lock-${{ github.sha }}" cancel-in-progress: false steps: - - name: Enable SSH Key + - name: Enable SSH env: SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }} SSH_KNOWN_HOSTS: ${{ secrets.SSH_KNOWN_HOSTS }} @@ -63,4 +63,4 @@ jobs: - name: Deploy updates env: TACHI_HOST: ${{ secrets.TACHI_HOST }} - run: ssh ci@"$TACHI_HOST" /home/ci/tachi-devops/scripts/deploy_seeds.sh + run: ssh "ci@${TACHI_HOST}" /home/ci/tachi-devops/scripts/deploy_seeds.sh diff --git a/.github/workflows/dev-image.yml b/.github/workflows/dev-image.yml index 2e866260e..12d9e0105 100644 --- a/.github/workflows/dev-image.yml +++ b/.github/workflows/dev-image.yml @@ -29,10 +29,18 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: persist-credentials: false + - name: Image name (lowercase for GHCR) + env: + REPO: ${{ github.repository }} + run: | + REPO_LC="$(echo "$REPO" | tr '[:upper:]' '[:lower:]')" + echo "DEV_IMAGE=ghcr.io/${REPO_LC}-dev" >> "$GITHUB_ENV" + - name: Log in to GHCR if: ${{ github.event_name != 'pull_request' }} uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 @@ -51,7 +59,7 @@ jobs: file: Dockerfile.dev push: ${{ github.ref == 'refs/heads/main' && github.event_name != 'pull_request' }} tags: | - ghcr.io/zkldi/tachi-dev:main - ghcr.io/zkldi/tachi-dev:${{ github.sha }} + ${{ env.DEV_IMAGE }}:main + ${{ env.DEV_IMAGE }}:${{ github.sha }} cache-from: type=gha,scope=dev-image cache-to: type=gha,mode=max,scope=dev-image diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 63c63255c..973ff22e0 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -31,7 +31,7 @@ jobs: - name: Build Docs run: docker run -v ./site:/site --entrypoint="mkdocs" docs build - - name: Enable SSH Key + - name: Enable SSH env: SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }} SSH_KNOWN_HOSTS: ${{ secrets.SSH_KNOWN_HOSTS }} @@ -44,4 +44,4 @@ jobs: - name: Deploy docs env: TACHI_HOST: ${{ secrets.TACHI_HOST }} - run: rsync --recursive --compress --delete --progress ./site/. ci@"$TACHI_HOST":tachi-docs + run: rsync --recursive --compress --delete --progress ./site/. "ci@${TACHI_HOST}:tachi-docs" diff --git a/.github/workflows/github-bot.yml b/.github/workflows/github-bot.yml index 6e8310cb2..9c91ea1db 100644 --- a/.github/workflows/github-bot.yml +++ b/.github/workflows/github-bot.yml @@ -20,16 +20,17 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: persist-credentials: false - name: Image name (lowercase for GHCR) env: - OWNER_RAW: ${{ github.repository_owner }} + REPO: ${{ github.repository }} run: | - OWNER="$(echo "$OWNER_RAW" | tr '[:upper:]' '[:lower:]')" - echo "GHBOT_IMAGE=ghcr.io/${OWNER}/tachi-ghbot" >> "$GITHUB_ENV" + REPO_LC="$(echo "$REPO" | tr '[:upper:]' '[:lower:]')" + echo "GHBOT_IMAGE=ghcr.io/${REPO_LC}-ghbot" >> "$GITHUB_ENV" - name: Log in to GHCR uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 @@ -42,7 +43,6 @@ jobs: uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1 - name: Build and push - id: docker_build uses: docker/build-push-action@48aba3b46d1b1fec4febb7c5d0c644b249a11355 # v6.10.0 with: context: . @@ -56,15 +56,12 @@ jobs: cache-from: type=gha,scope=${{ github.ref_name }}-github-bot cache-to: type=gha,mode=max,scope=${{ github.ref_name }}-github-bot - - name: Image digest - run: echo "${{ steps.docker_build.outputs.digest }}" - deploy: runs-on: ubuntu-latest needs: [docker-push] if: ${{ github.ref == 'refs/heads/main' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') }} steps: - - name: Enable SSH Key + - name: Enable SSH env: SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }} SSH_KNOWN_HOSTS: ${{ secrets.SSH_KNOWN_HOSTS }} diff --git a/.github/workflows/homepage.yml b/.github/workflows/homepage.yml index 5ee4e7049..103a16e67 100644 --- a/.github/workflows/homepage.yml +++ b/.github/workflows/homepage.yml @@ -16,7 +16,7 @@ jobs: deploy: runs-on: ubuntu-latest container: - image: ghcr.io/zkldi/tachi-dev:main + image: "ghcr.io/${{ github.repository }}-dev:main" options: --user root if: ${{ github.ref == 'refs/heads/main' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') }} steps: @@ -31,7 +31,7 @@ jobs: - name: Build run: bun run --filter tachi-homepage build - - name: Enable SSH Key + - name: Enable SSH env: SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }} SSH_KNOWN_HOSTS: ${{ secrets.SSH_KNOWN_HOSTS }} @@ -44,4 +44,4 @@ jobs: - name: Deploy env: TACHI_HOST: ${{ secrets.TACHI_HOST }} - run: rsync --recursive --compress --delete --progress ./homepage/dist/. ci@"$TACHI_HOST":tachi + run: rsync --recursive --compress --delete --progress ./homepage/dist/. "ci@${TACHI_HOST}:tachi" diff --git a/.github/workflows/seeds-webui.yml b/.github/workflows/seeds-webui.yml index 4a5101d4a..92534637e 100644 --- a/.github/workflows/seeds-webui.yml +++ b/.github/workflows/seeds-webui.yml @@ -26,10 +26,11 @@ jobs: build: runs-on: ubuntu-latest container: - image: ghcr.io/zkldi/tachi-dev:main + image: "ghcr.io/${{ github.repository }}-dev:main" options: --user root steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: persist-credentials: false diff --git a/.github/workflows/server.yml b/.github/workflows/server.yml index 6ea54427b..b192c5878 100644 --- a/.github/workflows/server.yml +++ b/.github/workflows/server.yml @@ -36,7 +36,7 @@ jobs: test: runs-on: ubuntu-latest container: - image: ghcr.io/zkldi/tachi-dev:main + image: "ghcr.io/${{ github.repository }}-dev:main" options: --user root env: NODE_ENV: "test" @@ -72,7 +72,8 @@ jobs: --health-timeout 5s --health-retries 10 steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: persist-credentials: false @@ -105,7 +106,8 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: persist-credentials: false @@ -113,7 +115,8 @@ jobs: env: REPO: ${{ github.repository }} run: | - echo "TACHI_IMAGE=ghcr.io/$(echo "$REPO" | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV" + REPO_LC="$(echo "$REPO" | tr '[:upper:]' '[:lower:]')" + echo "TACHI_IMAGE=ghcr.io/${REPO_LC}" >> "$GITHUB_ENV" echo "SHORT_SHA=$(git rev-parse --short HEAD)" >> "$GITHUB_ENV" - name: Log in to GHCR diff --git a/Justfile-repo b/Justfile-repo index 3e1b10c0a..58d33d079 100644 --- a/Justfile-repo +++ b/Justfile-repo @@ -15,3 +15,15 @@ setup: # containers! enable-zkldi-deploy-code: git submodule update --init --remote deploy + +# Same image as GHA `docker-push` (prod-unified). Context is always repo root via `git rev-parse`. +docker-build-server: assert-docker-host + #!/usr/bin/env bash + set -euo pipefail + root="$(git rev-parse --show-toplevel)" + exec docker build \ + -f "$root/docker/Dockerfile.server" \ + --target prod-unified \ + --build-arg "COMMIT_HASH=$(git -C "$root" rev-parse --short HEAD)" \ + -t tachi-server:local \ + "$root" diff --git a/docker/Dockerfile.server b/docker/Dockerfile.server index 33ad3569f..1f9b3ac16 100644 --- a/docker/Dockerfile.server +++ b/docker/Dockerfile.server @@ -1,4 +1,5 @@ -# Build context must be the repo root. +# Build context must be the repo root (same as GHA docker-push: context `.`). +# docker build -f docker/Dockerfile.server --target prod-unified --build-arg COMMIT_HASH="$(git rev-parse --short HEAD)" -t tachi-server:local . # docker build -f docker/Dockerfile.server --target prod-api . # docker build -f docker/Dockerfile.server --target prod-job-worker . # docker build -f docker/Dockerfile.server --target prod-cron-worker .