Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 35 additions & 13 deletions .github/workflows/deploy-dev.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# WF for deploying to test/stage envs on PR label 'deploy/test' or 'deploy/stage'

name: Deploy on label
name: Deploy to dev environments

on:
pull_request_target:
Expand All @@ -20,8 +20,11 @@ permissions:

jobs:
deploy:
name: Deploy to ${{ github.event.label.name }}
runs-on: ubuntu-latest
if: ${{ github.event.label.name == 'deploy/test' || github.event.label.name == 'deploy/stage' }}
if: >
(github.event.label.name == 'deploy/test' || github.event.label.name == 'deploy/stage')
&& startsWith(github.repository, 'deckhouse/')
steps:
- name: Checkout code
uses: actions/checkout@v4
Expand Down Expand Up @@ -50,8 +53,8 @@ jobs:
issue_number: context.payload.pull_request.number,
body: `## 🚀 Deployment Started\n\n**Environment:** \`${env}\`\n\n_This comment will be updated with deployment status._`
});
core.setOutput('comment_id', comment.data.id);
console.log(`Created comment: ${comment.data.id}`);
return comment.data.id;

- name: Validate that Environment variable set
run: |
Expand Down Expand Up @@ -95,6 +98,18 @@ jobs:
password: ${{ steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_PASSWORD }}
logout: false

- name: Validate deployment prerequisites
run: |
if [ -z "${{ steps.check_dev_registry.outputs.web_registry_path }}" ]; then
echo "::error::Dev registry credentials are missing. Cannot deploy."
exit 1
fi
if [ -z "${{ steps.secrets.outputs.KUBECONFIG_BASE64_DEV }}" ]; then
echo "::error::Dev kubeconfig is missing. Cannot deploy."
exit 1
fi
echo "✓ All prerequisites validated"

- name: Install werf
uses: werf/actions/install@v2

Expand All @@ -111,18 +126,22 @@ jobs:
werf converge

- name: Update comment - deployment succeeded
if: success()
if: success() && steps.comment.outputs.result
uses: actions/github-script@v7
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
const env = '${{ steps.env.outputs.env }}';
const commentId = ${{ steps.comment.outputs.comment_id }};
const commentId = ${{ steps.comment.outputs.result }};
if (!commentId) {
console.log('No comment ID available, skipping update');
return;
}
const repoName = context.repo.repo;
const appName = repoName.startsWith('website-') ? repoName.replace(/^website-/, '') : repoName;
const urlEn = `https://deckhouse.${env}.flant.com/products/${appName}/documentation/`;
const urlRu = `https://deckhouse.ru.${env}.flant.com/products/${appName}/documentation/`;

await github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
Expand All @@ -132,31 +151,34 @@ jobs:
console.log(`Updated comment ${commentId} with success status`);

- name: Update comment - deployment failed
if: failure()
if: failure() && steps.comment.outputs.result
uses: actions/github-script@v7
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
const env = '${{ steps.env.outputs.env }}';
const commentId = ${{ steps.comment.outputs.comment_id }};

// Get the job ID for the failed job
const commentId = ${{ steps.comment.outputs.result }};
if (!commentId) {
console.log('No comment ID available, skipping update');
return;
}

const jobs = await github.rest.actions.listJobsForWorkflowRun({
owner: context.repo.owner,
repo: context.repo.repo,
run_id: context.runId
});

const job = jobs.data.jobs.find(j => j.name === 'deploy');
const jobId = job ? job.id : null;

let logsUrl;
if (jobId) {
logsUrl = `${context.serverUrl}/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}/job/${jobId}`;
} else {
logsUrl = `${context.serverUrl}/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}`;
}

await github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
Expand Down
28 changes: 21 additions & 7 deletions .github/workflows/deploy-prod.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,15 +2,14 @@

name: Deploy to production

# On every push to main branch.
on:
push:
branches:
- 'main'
pull_request:
types:
- closed

# Cancel in-progress jobs for the same tag/branch.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event.label.name }}-deploy
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false

permissions:
Expand All @@ -20,12 +19,15 @@ permissions:
jobs:
deploy:
runs-on: "regular"
if: ${{ github.event.label.name == 'deploy/test' || github.event.label.name == 'deploy/stage' }}
if: >
github.event.pull_request.merged == true &&
github.event.pull_request.base.ref == 'main' &&
startsWith(github.repository, 'deckhouse/')
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }}
ref: ${{ github.event.pull_request.merge_commit_sha || github.sha }}
submodules: recursive
fetch-depth: 0

Expand Down Expand Up @@ -90,6 +92,18 @@ jobs:
password: ${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_PASSWORD }}
logout: false

- name: Validate deployment prerequisites
run: |
if [ -z "${{ steps.check_rw_registry.outputs.web_registry_path }}" ]; then
echo "::error::Production registry credentials are missing. Cannot deploy."
exit 1
fi
if [ -z "${{ steps.secrets.outputs.KUBECONFIG_BASE64_PROD }}" ]; then
echo "::error::Production kubeconfig is missing. Cannot deploy."
exit 1
fi
echo "✓ All prerequisites validated"

- name: Install werf
uses: werf/actions/install@v2

Expand Down
Loading