diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 2590f91..a85303a 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -6,105 +6,5 @@ on: - main jobs: - build: - runs-on: ubuntu-latest - name: Build Hugo Site - concurrency: - group: build-${{ github.event.pull_request.head.ref || github.ref_name }} - cancel-in-progress: true - container: - image: hugomods/hugo:debian-ci-0.150.1 - steps: - - name: Checkout code - uses: actions/checkout@v6 - with: - submodules: recursive - fetch-depth: 0 - - - name: Mark repository as safe - run: git config --global --add safe.directory '${{ github.workspace }}' - - - name: Build Hugo site - run: hugo --minify --enableGitInfo=false - - - name: Extract app name - id: app_name - shell: bash - run: | - REPO_NAME="${{ github.repository }}" - REPO_NAME="${REPO_NAME#*/}" - echo "Repository name: $REPO_NAME" - if [[ "$REPO_NAME" =~ ^website- ]]; then - APP_NAME="${REPO_NAME#website-}" - else - APP_NAME="$REPO_NAME" - fi - echo "app_name=$APP_NAME" >> $GITHUB_OUTPUT - echo "App name: $APP_NAME" - - - name: Rewrite URLs to remove /products// prefix - run: | - APP_NAME="${{ steps.app_name.outputs.app_name }}" - find ./public/en ./public/ru -type f -name "*.html" -exec sed -i "s|/products/${APP_NAME}/|/|g" {} + - - - name: Upload site artifacts - uses: actions/upload-artifact@v7 - with: - name: built-site - path: public/ - retention-days: 1 - - check-links: - runs-on: ubuntu-latest - name: Check Links - needs: build - steps: - - name: Download site artifacts - uses: actions/download-artifact@v8 - with: - name: built-site - path: . - - - name: Install htmltest - run: | - curl https://htmltest.wjdp.uk | bash - - - name: Create htmltest config - run: | - cat > .htmltest.yml << EOF - IgnoreURLs: - - "example.com" - - "astralinux.ru" - - "localhost" - - "^/assets/" - - "^/assets/js/" - - "^/images/.+$" - - "^/css/.+$" - - "^/js/.+$" - CheckMeta: false - CheckLinks: false - CheckMailto: false - CheckTel: false - CheckFavicon: false - IgnoreInternalEmptyHash: true - IgnoreCanonicalBrokenLinks: true - ExternalTimeout: 30 - EOF - - - name: Check links (English) - id: check_links_english - continue-on-error: true - run: bin/htmltest -c .htmltest.yml ./en - - - name: Check links (Russian) - id: check_links_russian - continue-on-error: true - run: bin/htmltest -c .htmltest.yml ./ru - - - name: Fail job if any link check failed - if: always() - run: | - if [ "${{ steps.check_links_english.outcome }}" == "failure" ] || [ "${{ steps.check_links_russian.outcome }}" == "failure" ]; then - echo "One or more link checks failed" - exit 1 - fi + call-reusable: + uses: deckhouse/hugo-web-product-module/.github/workflows/build.yaml@main \ No newline at end of file diff --git a/.github/workflows/deploy-dev.yaml b/.github/workflows/deploy-dev.yaml index 821783f..6f7a262 100644 --- a/.github/workflows/deploy-dev.yaml +++ b/.github/workflows/deploy-dev.yaml @@ -7,185 +7,6 @@ on: types: - labeled -# Cancel in-progress jobs for the same tag/branch. -concurrency: - group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event.label.name }}-deploy - cancel-in-progress: true - -permissions: - contents: read - id-token: write - issues: write - pull-requests: write - jobs: - deploy: - name: Deploy to ${{ github.event.label.name }} - runs-on: ubuntu-latest - if: > - (github.event.label.name == 'deploy/test' || github.event.label.name == 'deploy/stage') - && startsWith(github.repository, 'deckhouse/') - steps: - - name: Checkout code - uses: actions/checkout@v6 - with: - ref: ${{ github.event.pull_request.head.sha }} - submodules: recursive - fetch-depth: 0 - - - name: Extract environment - id: env - run: | - LABEL="${{ github.event.label.name }}" - ENV="${LABEL#deploy/}" - echo "env=$ENV" >> $GITHUB_OUTPUT - - - name: Validate that Environment variable set - run: | - if [ -z "${{ steps.env.outputs.env }}" ]; then - echo "::error::Can't determine environment name." - exit 1 - fi - echo "Environment: ${{ steps.env.outputs.env }}" - - - name: Create deployment comment - id: comment - uses: actions/github-script@v8 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - script: | - const env = '${{ steps.env.outputs.env }}'; - const comment = await github.rest.issues.createComment({ - owner: context.repo.owner, - repo: context.repo.repo, - issue_number: context.payload.pull_request.number, - body: `## 🚀 Deployment Started\n\n**Environment:** \`${env}\`\n\n_This comment will be updated with deployment status._` - }); - console.log(`Created comment: ${comment.data.id}`); - return comment.data.id; - - - name: Import secrets - id: secrets - uses: hashicorp/vault-action@v3 - with: - url: https://seguro.flant.com - path: github - role: deckhouse-web-products - method: jwt - jwtGithubAudience: github-access-aud - secrets: | - projects/data/6db2f1ee-9b6f-4f4f-8381-2fb43060478a/github/registry_host DECKHOUSE_DEV_REGISTRY_HOST | DECKHOUSE_DEV_REGISTRY_HOST ; - projects/data/101ceaca-97cd-462f-aed5-070d9b9de175/dev-registry/writetoken login | DECKHOUSE_DEV_REGISTRY_USER ; - projects/data/101ceaca-97cd-462f-aed5-070d9b9de175/dev-registry/writetoken password | DECKHOUSE_DEV_REGISTRY_PASSWORD ; - projects/data/6db2f1ee-9b6f-4f4f-8381-2fb43060478a/github/documentation_deploy_secret KUBECONFIG_BASE64_DEV_25 | KUBECONFIG_BASE64_DEV ; - - - name: Check dev registry credentials - id: check_dev_registry - env: - HOST: ${{steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_HOST}} - run: | - if [[ -n $HOST ]]; then - echo "has_credentials=true" >> $GITHUB_OUTPUT - echo "web_registry_path=${{steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_HOST }}/deckhouse/site" >> $GITHUB_OUTPUT - fi - - - name: Login to dev registry - uses: docker/login-action@v3 - if: ${{ steps.check_dev_registry.outputs.has_credentials == 'true' }} - with: - registry: ${{ steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_HOST }} - username: ${{ steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_USER }} - password: ${{ steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_PASSWORD }} - logout: false - - - name: Deploy to ${{ steps.env.outputs.env }} - uses: werf/actions/converge@v2 - id: deploy - with: - channel: beta - kube-config-base64-data: ${{ steps.secrets.outputs.KUBECONFIG_BASE64_DEV }} - env: ${{ steps.env.outputs.env }} - env: - WERF_REPO: ${{ steps.check_dev_registry.outputs.web_registry_path }} - WERF_SET_URL: "global.url=deckhouse.${{ steps.env.outputs.env }}.flant.dev" - WERF_SET_URL_RU: "global.url_ru=deckhouse-ru.${{ steps.env.outputs.env }}.flant.dev" - - - name: Update comment - deployment succeeded - if: success() && steps.comment.outputs.result - uses: actions/github-script@v8 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - script: | - const env = '${{ steps.env.outputs.env }}'; - const commentId = ${{ steps.comment.outputs.result }}; - if (!commentId) { - console.log('No comment ID available, skipping update'); - return; - } - const repoName = context.repo.repo; - const appName = repoName.startsWith('website-') ? repoName.replace(/^website-/, '') : repoName; - const urlEn = `https://deckhouse.${env}.flant.dev/products/${appName}/documentation/`; - const urlRu = `https://deckhouse-ru.${env}.flant.dev/products/${appName}/documentation/`; - - await github.rest.issues.updateComment({ - owner: context.repo.owner, - repo: context.repo.repo, - comment_id: commentId, - body: `## ✅ Deployment Succeeded\n\n**Environment:** \`${env}\`\n\n**Access URLs:**\n\n- 🇬🇧 [English](${urlEn})\n- 🇷🇺 [Russian](${urlRu})` - }); - console.log(`Updated comment ${commentId} with success status`); - - - name: Update comment - deployment failed - if: failure() && steps.comment.outputs.result - uses: actions/github-script@v8 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - script: | - const env = '${{ steps.env.outputs.env }}'; - const commentId = ${{ steps.comment.outputs.result }}; - if (!commentId) { - console.log('No comment ID available, skipping update'); - return; - } - - const jobs = await github.rest.actions.listJobsForWorkflowRun({ - owner: context.repo.owner, - repo: context.repo.repo, - run_id: context.runId - }); - - const job = jobs.data.jobs.find(j => j.name === 'deploy'); - const jobId = job ? job.id : null; - - let logsUrl; - if (jobId) { - logsUrl = `${context.serverUrl}/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}/job/${jobId}`; - } else { - logsUrl = `${context.serverUrl}/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}`; - } - - await github.rest.issues.updateComment({ - owner: context.repo.owner, - repo: context.repo.repo, - comment_id: commentId, - body: `## ❌ Deployment Failed\n\n**Environment:** \`${env}\`\n\nPlease check the [workflow logs](${logsUrl}) for details.` - }); - console.log(`Updated comment ${commentId} with failure status`); - - - name: Remove deploy label - if: always() - uses: actions/github-script@v8 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - script: | - const label = context.payload.label.name; - if (label && (label === 'deploy/test' || label === 'deploy/stage')) { - await github.rest.issues.removeLabel({ - owner: context.repo.owner, - repo: context.repo.repo, - issue_number: context.payload.pull_request.number, - name: label - }); - console.log(`Removed label: ${label}`); - } - + call-reusable: + uses: deckhouse/hugo-web-product-module/.github/workflows/deploy-dev.yaml@main \ No newline at end of file diff --git a/.github/workflows/deploy-prod.yaml b/.github/workflows/deploy-prod.yaml index 0f4ef82..b9b743a 100644 --- a/.github/workflows/deploy-prod.yaml +++ b/.github/workflows/deploy-prod.yaml @@ -7,136 +7,6 @@ on: types: - closed -# Cancel in-progress jobs for the same tag/branch. -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: false - -permissions: - contents: read - id-token: write - jobs: - deploy: - runs-on: "regular" - if: > - github.event.pull_request.merged == true && - github.event.pull_request.base.ref == 'main' && - startsWith(github.repository, 'deckhouse/') - steps: - - name: Checkout code - uses: actions/checkout@v6 - with: - ref: ${{ github.event.pull_request.merge_commit_sha || github.sha }} - submodules: recursive - fetch-depth: 0 - - - name: Set environment - id: env - run: | - echo "env=production" >> $GITHUB_OUTPUT - - - name: Import secrets - id: secrets - uses: hashicorp/vault-action@v3 - with: - url: https://seguro.flant.com - path: github - role: deckhouse-web-products - method: jwt - jwtGithubAudience: github-access-aud - secrets: | - projects/data/6db2f1ee-9b6f-4f4f-8381-2fb43060478a/github/registry_host DECKHOUSE_REGISTRY_HOST | DECKHOUSE_REGISTRY_HOST ; - projects/data/6db2f1ee-9b6f-4f4f-8381-2fb43060478a/github/registry_host DECKHOUSE_DEV_REGISTRY_HOST | DECKHOUSE_DEV_REGISTRY_HOST ; - projects/data/101ceaca-97cd-462f-aed5-070d9b9de175/dev-registry/writetoken login | DECKHOUSE_DEV_REGISTRY_USER ; - projects/data/101ceaca-97cd-462f-aed5-070d9b9de175/dev-registry/writetoken password | DECKHOUSE_DEV_REGISTRY_PASSWORD ; - projects/data/101ceaca-97cd-462f-aed5-070d9b9de175/registry-write/demotoken login | DECKHOUSE_REGISTRY_USER ; - projects/data/101ceaca-97cd-462f-aed5-070d9b9de175/registry-write/demotoken password | DECKHOUSE_REGISTRY_PASSWORD ; - projects/data/6db2f1ee-9b6f-4f4f-8381-2fb43060478a/github/registry_host DECKHOUSE_REGISTRY_READ_HOST | DECKHOUSE_REGISTRY_READ_HOST ; - projects/data/6db2f1ee-9b6f-4f4f-8381-2fb43060478a/github/registry_read_token login | DECKHOUSE_REGISTRY_READ_USER ; - projects/data/6db2f1ee-9b6f-4f4f-8381-2fb43060478a/github/registry_read_token password | DECKHOUSE_REGISTRY_READ_PASSWORD ; - projects/data/6db2f1ee-9b6f-4f4f-8381-2fb43060478a/github/documentation_deploy_secret KUBECONFIG_BASE64_PROD_25 | KUBECONFIG_BASE64_PROD ; - - - name: Check dev registry credentials - id: check_dev_registry - env: - HOST: ${{steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_HOST}} - run: | - if [[ -n $HOST ]]; then - echo "has_credentials=true" >> $GITHUB_OUTPUT - echo "web_registry_path=${{steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_HOST }}/deckhouse/site" >> $GITHUB_OUTPUT - fi - - - name: Login to dev registry - uses: docker/login-action@v3 - if: ${{ steps.check_dev_registry.outputs.has_credentials == 'true' }} - with: - registry: ${{ steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_HOST }} - username: ${{ steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_USER }} - password: ${{ steps.secrets.outputs.DECKHOUSE_DEV_REGISTRY_PASSWORD }} - logout: false - - - name: Check rw registry credentials - id: check_rw_registry - env: - HOST: ${{steps.secrets.outputs.DECKHOUSE_REGISTRY_HOST}} - run: | - if [[ -n $HOST ]]; then - echo "has_credentials=true" >> $GITHUB_OUTPUT - echo "web_registry_path=${{steps.secrets.outputs.DECKHOUSE_REGISTRY_HOST }}/deckhouse/site" >> $GITHUB_OUTPUT - fi - - - name: Login to rw registry - uses: docker/login-action@v3 - if: ${{ steps.check_rw_registry.outputs.has_credentials == 'true' }} - with: - registry: ${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_HOST }} - username: ${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_USER }} - password: ${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_PASSWORD }} - logout: false - - - name: Check readonly registry credentials - id: check_readonly_registry - env: - HOST: ${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_READ_HOST }} - run: | - if [[ -n $HOST ]]; then - echo "has_credentials=true" >> $GITHUB_OUTPUT - echo "web_registry_path=${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_READ_HOST }}/deckhouse/site" >> $GITHUB_OUTPUT - fi - - - name: Login to readonly registry - uses: docker/login-action@v3 - if: ${{ steps.check_readonly_registry.outputs.has_credentials == 'true' }} - with: - registry: ${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_READ_HOST }} - username: ${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_READ_USER }} - password: ${{ steps.secrets.outputs.DECKHOUSE_REGISTRY_READ_PASSWORD }} - logout: false - - - name: Build - id: build - uses: werf/actions/build@v2 - with: - channel: beta - kube-config-base64-data: ${{ steps.secrets.outputs.KUBECONFIG_BASE64_PROD }} - env: ${{ steps.env.outputs.env }} - env: - WERF_VIRTUAL_MERGE: 0 - WERF_REPO: ${{ steps.check_rw_registry.outputs.web_registry_path }} - WERF_SECONDARY_REPO: ${{ steps.check_dev_registry.outputs.web_registry_path }} - WERF_SET_URL: "global.url=deckhouse.io" - WERF_SET_URL_RU: "global.url_ru=deckhouse.ru" - - - name: Deploy to ${{ steps.env.outputs.env }} - id: deploy - uses: werf/actions/converge@v2 - with: - channel: beta - kube-config-base64-data: ${{ steps.secrets.outputs.KUBECONFIG_BASE64_PROD }} - env: ${{ steps.env.outputs.env }} - env: - WERF_VIRTUAL_MERGE: 0 - WERF_REPO: ${{ steps.check_readonly_registry.outputs.web_registry_path }} - WERF_SET_URL: "global.url=deckhouse.io" - WERF_SET_URL_RU: "global.url_ru=deckhouse.ru" + call-reusable: + uses: deckhouse/hugo-web-product-module/.github/workflows/deploy-prod.yaml@main diff --git a/.github/workflows/lint-markdown.yaml b/.github/workflows/lint-markdown.yaml index 0124b5f..f9a8d70 100644 --- a/.github/workflows/lint-markdown.yaml +++ b/.github/workflows/lint-markdown.yaml @@ -4,22 +4,5 @@ on: push: jobs: - lint-markdown: - runs-on: ubuntu-latest - name: Lint Markdown Files - steps: - - name: Checkout code - uses: actions/checkout@v6 - - - name: Run markdownlint - run: make lint-markdown - - - name: How to fix linting errors - if: failure() - run: | - echo "::error::Markdown linting failed!" - echo "To fix the errors automatically, run:" - echo " make lint-markdown-fix" - echo "" - echo "Or fix them manually according to the errors shown above." - + call-reusable: + uses: deckhouse/hugo-web-product-module/.github/workflows/lint-markdown.yaml@main