-
Notifications
You must be signed in to change notification settings - Fork 9
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #460 from IntersectMBO/test
staging: #351, #350, #320, #223, #317, #385, #358, #359, #151, #358, #360, #110, #379, #382, #361, #362, #446, #188, #377, #432, #364, #451, #433
- Loading branch information
1 parent
d960a99
commit fa67064
Showing
132 changed files
with
4,778 additions
and
7,137 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -19,10 +19,6 @@ on: | |
- "test" | ||
- "staging" | ||
- "beta" | ||
skip_build: | ||
required: true | ||
type: boolean | ||
default: false | ||
resync_cardano_node_and_db: | ||
required: true | ||
type: boolean | ||
|
@@ -33,82 +29,8 @@ env: | |
CARDANO_NETWORK: ${{ inputs.cardano_network || 'sanchonet' }} | ||
|
||
jobs: | ||
check_environment_exists: | ||
name: Check if target environment exists before proceeding | ||
runs-on: ubuntu-latest | ||
defaults: | ||
run: | ||
working-directory: ./scripts/govtool | ||
steps: | ||
- name: Checkout code | ||
uses: actions/checkout@v3 | ||
- name: Check environment exists | ||
run: | | ||
make check-env-defined | ||
build_backend: | ||
name: Build and push backend Docker image | ||
if: ${{ ! inputs.skip_build }} | ||
needs: | ||
- check_environment_exists | ||
runs-on: ubuntu-latest | ||
defaults: | ||
run: | ||
working-directory: ./scripts/govtool | ||
steps: | ||
- name: Checkout code | ||
uses: actions/checkout@v3 | ||
- name: Configure AWS credentials | ||
uses: aws-actions/configure-aws-credentials@v3 | ||
with: | ||
aws-access-key-id: ${{ secrets.GHA_AWS_ACCESS_KEY_ID }} | ||
aws-secret-access-key: ${{ secrets.GHA_AWS_SECRET_ACCESS_KEY }} | ||
aws-region: eu-west-1 | ||
- name: Login to AWS ECR | ||
uses: aws-actions/configure-aws-credentials@v2 | ||
with: | ||
aws-region: eu-west-1 | ||
- name: Build and push images | ||
run: | | ||
make docker-login | ||
make build-backend | ||
make push-backend | ||
build_frontend: | ||
name: Build and push frontend Docker image | ||
if: ${{ ! inputs.skip_build }} | ||
needs: | ||
- check_environment_exists | ||
runs-on: ubuntu-latest | ||
defaults: | ||
run: | ||
working-directory: ./scripts/govtool | ||
steps: | ||
- name: Checkout code | ||
uses: actions/checkout@v3 | ||
- name: Configure AWS credentials | ||
uses: aws-actions/configure-aws-credentials@v3 | ||
with: | ||
aws-access-key-id: ${{ secrets.GHA_AWS_ACCESS_KEY_ID }} | ||
aws-secret-access-key: ${{ secrets.GHA_AWS_SECRET_ACCESS_KEY }} | ||
aws-region: eu-west-1 | ||
- name: Login to AWS ECR | ||
uses: aws-actions/configure-aws-credentials@v2 | ||
with: | ||
aws-region: eu-west-1 | ||
- name: Build and push images | ||
env: | ||
GTM_ID: ${{ secrets.GTM_ID }} | ||
SENTRY_DSN: ${{ secrets.SENTRY_DSN_FRONTEND }} | ||
run: | | ||
make docker-login | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
make build-frontend | ||
make push-frontend | ||
deploy: | ||
name: Deploy app | ||
needs: | ||
- build_backend | ||
- build_frontend | ||
runs-on: ubuntu-latest | ||
defaults: | ||
run: | ||
|
@@ -117,136 +39,58 @@ jobs: | |
DBSYNC_POSTGRES_DB: "cexplorer" | ||
DBSYNC_POSTGRES_USER: "postgres" | ||
DBSYNC_POSTGRES_PASSWORD: "pSa8JCpQOACMUdGb" | ||
FAKEDBSYNC_POSTGRES_DB: "govtool" | ||
FAKEDBSYNC_POSTGRES_USER: "test" | ||
FAKEDBSYNC_POSTGRES_PASSWORD: "test" | ||
GRAFANA_ADMIN_PASSWORD: ${{ secrets.GRAFANA_ADMIN_PASSWORD }} | ||
GRAFANA_SLACK_RECIPIENT: ${{ secrets.GRAFANA_SLACK_RECIPIENT }} | ||
GRAFANA_SLACK_OAUTH_TOKEN: ${{ secrets.GRAFANA_SLACK_OAUTH_TOKEN }} | ||
NGINX_BASIC_AUTH: ${{ secrets.NGINX_BASIC_AUTH }} | ||
SENTRY_DSN_BACKEND: ${{ secrets.SENTRY_DSN_BACKEND }} | ||
TRAEFIK_LE_EMAIL: "[email protected]" | ||
GTM_ID: ${{ secrets.GTM_ID }} | ||
SENTRY_DSN: ${{ secrets.SENTRY_DSN_FRONTEND }} | ||
PIPELINE_URL: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }} | ||
steps: | ||
- name: Checkout code | ||
uses: actions/checkout@v3 | ||
- name: Configure AWS credentials | ||
uses: aws-actions/configure-aws-credentials@v3 | ||
with: | ||
aws-access-key-id: ${{ secrets.GHA_AWS_ACCESS_KEY_ID }} | ||
aws-secret-access-key: ${{ secrets.GHA_AWS_SECRET_ACCESS_KEY }} | ||
aws-region: eu-west-1 | ||
- name: Login to AWS ECR | ||
uses: aws-actions/configure-aws-credentials@v2 | ||
with: | ||
aws-region: eu-west-1 | ||
- name: Setup SSH agent | ||
uses: webfactory/[email protected] | ||
with: | ||
ssh-private-key: ${{ secrets.GHA_SSH_PRIVATE_KEY }} | ||
- name: Prepare and upload app config | ||
run: | | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
export DOMAIN=${DOMAIN:-$ENVIRONMENT-$CARDANO_NETWORK.govtool.byron.network} | ||
make prepare-config | ||
make upload-config | ||
- name: Destroy Cardano Node, DB sync and Postgres if required | ||
if: ${{ inputs.resync_cardano_node_and_db }} | ||
run: | | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
make destroy-cardano-node-and-dbsync; | ||
- name: Deploy app | ||
run: | | ||
make docker-login | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
make deploy-stack | ||
- name: Reprovision Grafana | ||
run: | | ||
sleep 30 # give grafana time to start up | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
DOMAIN=${DOMAIN:-$ENVIRONMENT-$CARDANO_NETWORK.govtool.byron.network} | ||
curl -X POST -u "admin:$GRAFANA_ADMIN_PASSWORD" https://$DOMAIN/grafana/api/admin/provisioning/alerting/reload | ||
curl -X POST -u "admin:$GRAFANA_ADMIN_PASSWORD" https://$DOMAIN/grafana/api/admin/provisioning/dashboards/reload | ||
curl -X POST -u "admin:$GRAFANA_ADMIN_PASSWORD" https://$DOMAIN/grafana/api/admin/provisioning/notifications/reload | ||
- name: Notify on Slack | ||
env: | ||
SLACK_WEBHOOK_URL: ${{ secrets.DEPLOY_NOTIFY_SLACK_WEBHOOK_URL }} | ||
run: | | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
make notify | ||
deploy_without_build: | ||
name: Deploy app without building | ||
if: ${{ inputs.skip_build }} | ||
needs: | ||
- check_environment_exists | ||
runs-on: ubuntu-latest | ||
defaults: | ||
run: | ||
working-directory: ./scripts/govtool | ||
env: | ||
DBSYNC_POSTGRES_DB: "cexplorer" | ||
DBSYNC_POSTGRES_USER: "postgres" | ||
DBSYNC_POSTGRES_PASSWORD: "pSa8JCpQOACMUdGb" | ||
FAKEDBSYNC_POSTGRES_DB: "govtool" | ||
FAKEDBSYNC_POSTGRES_USER: "test" | ||
FAKEDBSYNC_POSTGRES_PASSWORD: "test" | ||
GRAFANA_ADMIN_PASSWORD: ${{ secrets.GRAFANA_ADMIN_PASSWORD }} | ||
GRAFANA_SLACK_RECIPIENT: ${{ secrets.GRAFANA_SLACK_RECIPIENT }} | ||
GRAFANA_SLACK_OAUTH_TOKEN: ${{ secrets.GRAFANA_SLACK_OAUTH_TOKEN }} | ||
NGINX_BASIC_AUTH: ${{ secrets.NGINX_BASIC_AUTH }} | ||
SENTRY_DSN_BACKEND: ${{ secrets.SENTRY_DSN_BACKEND }} | ||
TRAEFIK_LE_EMAIL: "[email protected]" | ||
steps: | ||
- name: Checkout code | ||
uses: actions/checkout@v3 | ||
fetch-depth: 0 | ||
|
||
- name: Configure AWS credentials | ||
uses: aws-actions/configure-aws-credentials@v3 | ||
with: | ||
aws-access-key-id: ${{ secrets.GHA_AWS_ACCESS_KEY_ID }} | ||
aws-secret-access-key: ${{ secrets.GHA_AWS_SECRET_ACCESS_KEY }} | ||
aws-region: eu-west-1 | ||
|
||
- name: Login to AWS ECR | ||
uses: aws-actions/configure-aws-credentials@v2 | ||
with: | ||
aws-region: eu-west-1 | ||
|
||
- name: Setup SSH agent | ||
uses: webfactory/[email protected] | ||
with: | ||
ssh-private-key: ${{ secrets.GHA_SSH_PRIVATE_KEY }} | ||
- name: Prepare and upload app config | ||
|
||
- name: Set domain | ||
run: | | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
export DOMAIN=${DOMAIN:-$ENVIRONMENT-$CARDANO_NETWORK.govtool.byron.network} | ||
make prepare-config | ||
make upload-config | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then | ||
echo "DOMAIN=staging.govtool.byron.network" >> $GITHUB_ENV | ||
elif [[ "${{ inputs.environment }}" == "beta" ]]; then | ||
echo "DOMAIN=sanchogov.tools" >> $GITHUB_ENV | ||
else | ||
echo "DOMAIN=${DOMAIN:-$ENVIRONMENT-$CARDANO_NETWORK.govtool.byron.network}" >> $GITHUB_ENV | ||
fi | ||
- name: Destroy Cardano Node, DB sync and Postgres if required | ||
if: ${{ inputs.resync_cardano_node_and_db }} | ||
run: | | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
make destroy-cardano-node-and-dbsync; | ||
make --debug=b destroy-cardano-node-and-dbsync | ||
- name: Deploy app | ||
run: | | ||
make docker-login | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
make deploy-stack | ||
make --debug=b all | ||
- name: Reprovision Grafana | ||
run: | | ||
sleep 30 # give grafana time to start up | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
DOMAIN=${DOMAIN:-$ENVIRONMENT-$CARDANO_NETWORK.govtool.byron.network} | ||
curl -X POST -u "admin:$GRAFANA_ADMIN_PASSWORD" https://$DOMAIN/grafana/api/admin/provisioning/alerting/reload | ||
curl -X POST -u "admin:$GRAFANA_ADMIN_PASSWORD" https://$DOMAIN/grafana/api/admin/provisioning/dashboards/reload | ||
curl -X POST -u "admin:$GRAFANA_ADMIN_PASSWORD" https://$DOMAIN/grafana/api/admin/provisioning/notifications/reload | ||
- name: Notify on Slack | ||
run: | | ||
if [[ "${{ inputs.environment }}" == "staging" ]]; then export DOMAIN=staging.govtool.byron.network; fi; | ||
if [[ "${{ inputs.environment }}" == "beta" ]]; then export DOMAIN=sanchogov.tools; fi; | ||
make notify | ||
make --debug=b reload-grafana |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,31 @@ | ||
common_mk := ../../scripts/govtool/common.mk | ||
ifeq ($(origin $(common_mk)), undefined) | ||
$(eval $(common_mk) := included) | ||
include $(common_mk) | ||
endif | ||
|
||
.DEFAULT_GOAL := push-backend | ||
|
||
# image tags | ||
base_backend_image_tag := $(shell git hash-object $(root_dir)/govtool/backend/vva-be.cabal) | ||
backend_image_tag := $(shell git log -n 1 --format="%H" -- $(root_dir)/govtool/backend) | ||
|
||
.PHONY: build-backend-base | ||
build-backend-base: docker-login | ||
$(call check_image_on_ecr,backend-base,$(base_backend_image_tag)) || \ | ||
$(docker) build --file $(root_dir)/govtool/backend/Dockerfile.base --tag "$(repo_url)/backend-base:$(base_backend_image_tag)" $(root_dir)/govtool/backend | ||
|
||
.PHONY: push-backend-base | ||
push-backend-base: build-backend-base | ||
$(call check_image_on_ecr,backend-base,$(base_backend_image_tag)) || \ | ||
$(docker) push $(repo_url)/backend-base:$(base_backend_image_tag) | ||
|
||
.PHONY: build-backend | ||
build-backend: build-backend-base | ||
$(call check_image_on_ecr,backend,$(backend_image_tag)) || \ | ||
$(docker) build --build-arg BASE_IMAGE_TAG=$(base_backend_image_tag) --tag "$(repo_url)/backend:$(backend_image_tag)" $(root_dir)/govtool/backend | ||
|
||
.PHONY: push-backend | ||
push-backend: push-backend-base build-backend | ||
$(call check_image_on_ecr,backend,$(backend_image_tag)) || \ | ||
$(docker) push $(repo_url)/backend:$(backend_image_tag) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,16 @@ | ||
{ pkgs ? import <nixpkgs> {} }: | ||
let | ||
project = import ./default.nix { inherit pkgs; }; | ||
in | ||
project.overrideAttrs (attrs: { | ||
buildInputs = attrs.buildInputs ++ (with pkgs; [ | ||
awscli | ||
docker | ||
git | ||
gnumake | ||
]); | ||
|
||
shellHook = '' | ||
ln -s ${project}/libexec/yarn-nix-example/node_modules node_modules | ||
''; | ||
}) |
Oops, something went wrong.