ci: publish famapp images to valhalla registry
Add Gitea Actions workflows (ci.yml, release.yml) that build and push to registry.ginnoir.com. Disable GitHub release creation. Update all doc/compose references from ghcr.io to registry.ginnoir.com. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
4f92a98921
commit
4084c3af91
@@ -0,0 +1,49 @@
|
|||||||
|
name: CI
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
checks:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Enable pnpm
|
||||||
|
run: |
|
||||||
|
corepack enable
|
||||||
|
corepack prepare pnpm@10.33.3 --activate
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: pnpm install --frozen-lockfile
|
||||||
|
|
||||||
|
- name: Typecheck
|
||||||
|
run: pnpm typecheck
|
||||||
|
|
||||||
|
- name: Lint
|
||||||
|
run: pnpm lint
|
||||||
|
|
||||||
|
- name: Format check
|
||||||
|
run: pnpm format:check
|
||||||
|
|
||||||
|
build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Enable pnpm
|
||||||
|
run: |
|
||||||
|
corepack enable
|
||||||
|
corepack prepare pnpm@10.33.3 --activate
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: pnpm install --frozen-lockfile
|
||||||
|
|
||||||
|
- name: Build
|
||||||
|
run: pnpm build
|
||||||
|
env:
|
||||||
|
DATABASE_URL: postgres://ci_user:ci_password@localhost:5432/ci_database
|
||||||
|
AUTH_SECRET: ci-auth-secret-for-build
|
||||||
|
NEXT_PUBLIC_APP_URL: http://localhost:3000
|
||||||
@@ -0,0 +1,48 @@
|
|||||||
|
name: Release Image
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
tags:
|
||||||
|
- "v*"
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build-and-push:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Derive image tags
|
||||||
|
id: meta
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
VERSION="${GITEA_REF_NAME#v}"
|
||||||
|
MAJOR_MINOR="$(printf '%s' "$VERSION" | awk -F. '{print $1"."$2}')"
|
||||||
|
{
|
||||||
|
echo "version=$VERSION"
|
||||||
|
echo "major_minor=$MAJOR_MINOR"
|
||||||
|
echo "image=registry.ginnoir.com/ginnoir/famapp"
|
||||||
|
} >> "$GITEA_OUTPUT"
|
||||||
|
|
||||||
|
- name: Install docker
|
||||||
|
run: apt-get update -qq && apt-get install -y -qq docker.io
|
||||||
|
|
||||||
|
- name: Login to registry
|
||||||
|
run: |
|
||||||
|
echo "${{ secrets.REGISTRY_PUSH_PASSWORD }}" | docker login registry.ginnoir.com \
|
||||||
|
--username "${{ secrets.REGISTRY_PUSH_USERNAME }}" \
|
||||||
|
--password-stdin
|
||||||
|
|
||||||
|
- name: Build image
|
||||||
|
run: |
|
||||||
|
docker build \
|
||||||
|
-t "${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}" \
|
||||||
|
-t "${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.major_minor }}" \
|
||||||
|
-t "${{ steps.meta.outputs.image }}:latest" \
|
||||||
|
.
|
||||||
|
|
||||||
|
- name: Push image
|
||||||
|
run: |
|
||||||
|
docker push "${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}"
|
||||||
|
docker push "${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.major_minor }}"
|
||||||
|
docker push "${{ steps.meta.outputs.image }}:latest"
|
||||||
+1
-2
@@ -8,8 +8,7 @@
|
|||||||
"requireBranch": "main"
|
"requireBranch": "main"
|
||||||
},
|
},
|
||||||
"github": {
|
"github": {
|
||||||
"release": true,
|
"release": false
|
||||||
"releaseName": "v${version}"
|
|
||||||
},
|
},
|
||||||
"hooks": {
|
"hooks": {
|
||||||
"before:git:release": "echo 'Check: README.md reflects current modules and env vars before tagging'"
|
"before:git:release": "echo 'Check: README.md reflects current modules and env vars before tagging'"
|
||||||
|
|||||||
@@ -74,7 +74,7 @@ The container runs database migrations automatically on start. The first user to
|
|||||||
Pin `FAMAPP_IMAGE` in `deploy/.env` after the first deploy:
|
Pin `FAMAPP_IMAGE` in `deploy/.env` after the first deploy:
|
||||||
|
|
||||||
```
|
```
|
||||||
FAMAPP_IMAGE=ghcr.io/ginnoir/famapp:v0.4.7
|
FAMAPP_IMAGE=registry.ginnoir.com/ginnoir/famapp:v0.4.7
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -155,4 +155,4 @@ See [`CLAUDE.md`](CLAUDE.md) for the full architecture brief and [`docs/decision
|
|||||||
| Pre-deploy checklist | [`docs/tasks/09-pre-deploy-checklist.md`](docs/tasks/09-pre-deploy-checklist.md) |
|
| Pre-deploy checklist | [`docs/tasks/09-pre-deploy-checklist.md`](docs/tasks/09-pre-deploy-checklist.md) |
|
||||||
| Changelog | [`CHANGELOG.md`](CHANGELOG.md) |
|
| Changelog | [`CHANGELOG.md`](CHANGELOG.md) |
|
||||||
|
|
||||||
Cutting a release: tag `vX.Y.Z` on `main` and push — CI builds and pushes `ghcr.io/ginnoir/famapp:vX.Y.Z` automatically.
|
Cutting a release: tag `vX.Y.Z` on `main` and push — Gitea Actions builds and pushes `registry.ginnoir.com/ginnoir/famapp:vX.Y.Z` automatically.
|
||||||
|
|||||||
+2
-2
@@ -35,14 +35,14 @@ git tag v0.1.0
|
|||||||
git push origin v0.1.0
|
git push origin v0.1.0
|
||||||
```
|
```
|
||||||
|
|
||||||
`.github/workflows/release.yml` builds + pushes `ghcr.io/ginnoir/famapp:v0.1.0`, `:0.1`, and `:latest` to GHCR.
|
`.gitea/workflows/release.yml` builds + pushes `registry.ginnoir.com/ginnoir/famapp:v0.1.0`, `:0.1`, and `:latest` to the self-hosted registry.
|
||||||
|
|
||||||
## Deploying a release on the host
|
## Deploying a release on the host
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd /srv/famapp/deploy
|
cd /srv/famapp/deploy
|
||||||
# pin to the tag you just cut
|
# pin to the tag you just cut
|
||||||
sed -i 's|FAMAPP_IMAGE=.*|FAMAPP_IMAGE=ghcr.io/ginnoir/famapp:v0.1.0|' .env
|
sed -i 's|FAMAPP_IMAGE=.*|FAMAPP_IMAGE=registry.ginnoir.com/ginnoir/famapp:v0.1.0|' .env
|
||||||
docker compose pull famapp
|
docker compose pull famapp
|
||||||
docker compose up -d famapp
|
docker compose up -d famapp
|
||||||
docker compose logs -f famapp # watch migrations + boot
|
docker compose logs -f famapp # watch migrations + boot
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ volumes:
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
famapp:
|
famapp:
|
||||||
image: ${FAMAPP_IMAGE:-ghcr.io/ginnoir/famapp:latest}
|
image: ${FAMAPP_IMAGE:-registry.ginnoir.com/ginnoir/famapp:latest}
|
||||||
pull_policy: ${FAMAPP_PULL_POLICY:-always}
|
pull_policy: ${FAMAPP_PULL_POLICY:-always}
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
+10
-10
@@ -98,15 +98,15 @@ Only needed on the machine that cuts releases (`pnpm release`).
|
|||||||
|
|
||||||
Used by `deploy/compose.example.yaml`. Set in `deploy/.env` on the server — not in the local `.env`.
|
Used by `deploy/compose.example.yaml`. Set in `deploy/.env` on the server — not in the local `.env`.
|
||||||
|
|
||||||
| Variable | Description |
|
| Variable | Description |
|
||||||
| ------------------------------------------------------------------- | ----------------------------------------------------------------- |
|
| ------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
|
||||||
| `FAMAPP_IMAGE` | Docker image tag to deploy (e.g. `ghcr.io/ginnoir/famapp:v0.4.7`) |
|
| `FAMAPP_IMAGE` | Docker image tag to deploy (e.g. `registry.ginnoir.com/ginnoir/famapp:v0.4.7`) |
|
||||||
| `FAMAPP_PORT` | Host port to bind (default: `3000`) |
|
| `FAMAPP_PORT` | Host port to bind (default: `3000`) |
|
||||||
| `FAMAPP_PULL_POLICY` | Docker pull policy (default: `always`) |
|
| `FAMAPP_PULL_POLICY` | Docker pull policy (default: `always`) |
|
||||||
| `FAMAPP_DB_USER` / `FAMAPP_DB_PASSWORD` / `FAMAPP_DB_NAME` | Postgres credentials for the famapp database |
|
| `FAMAPP_DB_USER` / `FAMAPP_DB_PASSWORD` / `FAMAPP_DB_NAME` | Postgres credentials for the famapp database |
|
||||||
| `AUTHENTIK_DB_USER` / `AUTHENTIK_DB_PASSWORD` / `AUTHENTIK_DB_NAME` | Postgres credentials for the Authentik database |
|
| `AUTHENTIK_DB_USER` / `AUTHENTIK_DB_PASSWORD` / `AUTHENTIK_DB_NAME` | Postgres credentials for the Authentik database |
|
||||||
| `AUTHENTIK_SECRET_KEY` | Authentik signing key — generate with `openssl rand -base64 60` |
|
| `AUTHENTIK_SECRET_KEY` | Authentik signing key — generate with `openssl rand -base64 60` |
|
||||||
| `AUTHENTIK_IMAGE_TAG` | Authentik server image tag (default: `2024.12.3`) |
|
| `AUTHENTIK_IMAGE_TAG` | Authentik server image tag (default: `2024.12.3`) |
|
||||||
| `RUN_MIGRATIONS` | Set `false` to skip auto-migration on start (default: `true`) |
|
| `RUN_MIGRATIONS` | Set `false` to skip auto-migration on start (default: `true`) |
|
||||||
|
|
||||||
<!-- END AUTO-GENERATED -->
|
<!-- END AUTO-GENERATED -->
|
||||||
|
|||||||
+6
-6
@@ -15,11 +15,11 @@ pnpm release:patch # or :minor / :major
|
|||||||
# Requires GITHUB_TOKEN in .env
|
# Requires GITHUB_TOKEN in .env
|
||||||
```
|
```
|
||||||
|
|
||||||
CI (`release.yml`) then builds and pushes the Docker image to GHCR:
|
Gitea Actions (`release.yml`) then builds and pushes the Docker image to the self-hosted registry:
|
||||||
|
|
||||||
- `ghcr.io/ginnoir/famapp:v0.x.y`
|
- `registry.ginnoir.com/ginnoir/famapp:v0.x.y`
|
||||||
- `ghcr.io/ginnoir/famapp:0.x` (minor alias)
|
- `registry.ginnoir.com/ginnoir/famapp:0.x` (minor alias)
|
||||||
- `ghcr.io/ginnoir/famapp:latest`
|
- `registry.ginnoir.com/ginnoir/famapp:latest`
|
||||||
|
|
||||||
## Deploying a release
|
## Deploying a release
|
||||||
|
|
||||||
@@ -27,7 +27,7 @@ On the home server, in `/srv/famapp/deploy/`:
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Pin the new tag
|
# Pin the new tag
|
||||||
sed -i 's|FAMAPP_IMAGE=.*|FAMAPP_IMAGE=ghcr.io/ginnoir/famapp:v0.x.y|' .env
|
sed -i 's|FAMAPP_IMAGE=.*|FAMAPP_IMAGE=registry.ginnoir.com/ginnoir/famapp:v0.x.y|' .env
|
||||||
|
|
||||||
# Pull and restart only the app container
|
# Pull and restart only the app container
|
||||||
docker compose pull famapp
|
docker compose pull famapp
|
||||||
@@ -60,7 +60,7 @@ docker compose exec famapp-db pg_isready -U famapp -d famapp
|
|||||||
1. Find the previous working tag in `CHANGELOG.md` or `docker images`.
|
1. Find the previous working tag in `CHANGELOG.md` or `docker images`.
|
||||||
2. Pin it in `deploy/.env`:
|
2. Pin it in `deploy/.env`:
|
||||||
```bash
|
```bash
|
||||||
sed -i 's|FAMAPP_IMAGE=.*|FAMAPP_IMAGE=ghcr.io/ginnoir/famapp:v0.x.y|' .env
|
sed -i 's|FAMAPP_IMAGE=.*|FAMAPP_IMAGE=registry.ginnoir.com/ginnoir/famapp:v0.x.y|' .env
|
||||||
```
|
```
|
||||||
3. Restart the container:
|
3. Restart the container:
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
Reference in New Issue
Block a user