-
Notifications
You must be signed in to change notification settings - Fork 2
80 lines (73 loc) · 2.63 KB
/
Copy pathdeploy.yml
File metadata and controls
80 lines (73 loc) · 2.63 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
name: deploy
on:
push:
branches: [ dev ]
pull_request:
branches: [ dev ]
types: [ opened, reopened, synchronize, ready_for_review ]
workflow_dispatch:
jobs:
build-and-deploy:
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
concurrency:
group: deploy-soomteum
cancel-in-progress: true
steps:
- uses: actions/checkout@v4
# 1) OIDC로 AWS 자격 구성
- name: Configure AWS
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_ROLE_TO_ASSUME }}
aws-region: ${{ secrets.AWS_REGION }}
# 2) ECR 로그인
- name: Login to ECR
uses: aws-actions/amazon-ecr-login@v2
# 3) Spring Boot 이미지 Build & Push (:latest + :sha7)
- name: Build and Push
env:
ACCOUNT: ${{ secrets.AWS_ACCOUNT_ID }}
REGION: ${{ secrets.AWS_REGION }}
REPO: ${{ secrets.ECR_REPO }}
run: |
IMAGE=$ACCOUNT.dkr.ecr.$REGION.amazonaws.com/$REPO
TAG=${GITHUB_SHA::7}
docker build -t $IMAGE:$TAG -t $IMAGE:latest .
docker push $IMAGE:$TAG
docker push $IMAGE:latest
echo "TAG=$TAG" >> $GITHUB_ENV
# 4) SSM Online 대기
- name: Wait until SSM is Online
run: |
for i in {1..5}; do
STATUS=$(aws ssm describe-instance-information \
--query "InstanceInformationList[?InstanceId=='${{ secrets.EC2_INSTANCE_ID }}'].PingStatus" \
--output text || true)
if [ "$STATUS" = "Online" ]; then
echo "SSM Online"
exit 0
fi
echo "SSM status: $STATUS (retry $i/5)"
sleep 10
done
echo "SSM not Online"
exit 1
# 5) SSM으로 EC2에 배포 (compose가 ${IMAGE_TAG:-latest} 사용)
- name: Deploy on EC2 via SSM
run: |
CMD='aws ecr get-login-password --region ${{ secrets.AWS_REGION }} \
| docker login --username AWS --password-stdin ${{ secrets.AWS_ACCOUNT_ID }}.dkr.ecr.${{ secrets.AWS_REGION }}.amazonaws.com \
&& cd /srv/caddy \
&& export IMAGE_TAG=${{ env.TAG }} \
&& docker compose pull app \
&& docker compose up -d app \
&& docker image prune -f'
aws ssm send-command \
--instance-ids ${{ secrets.EC2_INSTANCE_ID }} \
--region ${{ secrets.AWS_REGION }} \
--document-name "AWS-RunShellScript" \
--comment "soomteum deploy ${{ env.TAG }}" \
--parameters commands=["$CMD"]