Skip to content

Commit 2f6653f

Browse files
author
Lev Brouk
committed
Merge remote-tracking branch 'e2b/main' into lev-storage-rationalize
2 parents 5787a00 + 9153aa3 commit 2f6653f

164 files changed

Lines changed: 9837 additions & 1951 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.env.gcp.template‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -125,7 +125,7 @@ PERSISTENT_VOLUME_TYPES=
125125
CLIENT_PROXY_OIDC_ISSUER_URL=
126126

127127
# Dashboard API user profile resolver (default: supabase)
128-
# One of: supabase, ory, supabase-ory-fallback
128+
# One of: supabase, ory
129129
USER_PROFILE_PROVIDER=
130130
# Ory Network admin SDK URL (required when USER_PROFILE_PROVIDER uses ory)
131131
# e.g. https://<project-slug>.projects.oryapis.com

‎.github/actions/deploy-setup/action.yml‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ runs:
1616
using: "composite"
1717
steps:
1818
- name: Pull infisical secrets into temporary file
19-
uses: Infisical/secrets-action@v1.0.15
19+
uses: Infisical/secrets-action@v1.0.16
2020
with:
2121
method: "oidc"
2222
identity-id: ${{ inputs.infisical_machine_identity_id }}
@@ -45,7 +45,7 @@ runs:
4545
shell: bash
4646

4747
- name: Load environment variables from Infisical
48-
uses: Infisical/secrets-action@v1.0.15
48+
uses: Infisical/secrets-action@v1.0.16
4949
with:
5050
method: "oidc"
5151
identity-id: ${{ inputs.infisical_machine_identity_id }}
@@ -54,14 +54,14 @@ runs:
5454
export-type: "env"
5555

5656
- name: Setup Service Account
57-
uses: google-github-actions/auth@v2
57+
uses: google-github-actions/auth@v3
5858
with:
5959
project_id: ${{ env.GCP_PROJECT_ID }}
6060
workload_identity_provider: ${{ env.GH_WORKLOAD_IDENTITY_PROVIDER }}
6161

6262
- name: Set up Cloud SDK
6363
if: inputs.install_gcloud == 'true'
64-
uses: google-github-actions/setup-gcloud@v2
64+
uses: google-github-actions/setup-gcloud@v3
6565

6666
- name: Setup Terraform
6767
uses: hashicorp/setup-terraform@v3
Lines changed: 98 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,98 @@
1+
name: Build and upload images
2+
3+
on:
4+
push:
5+
branches:
6+
- main
7+
8+
workflow_dispatch:
9+
10+
permissions:
11+
contents: read
12+
id-token: write
13+
14+
jobs:
15+
build-images:
16+
name: Build and upload images to the ${{ matrix.environment }} environment
17+
runs-on: ci-builder
18+
strategy:
19+
fail-fast: false
20+
matrix:
21+
environment:
22+
- staging
23+
- foxtrot
24+
- juliett
25+
environment: ${{ matrix.environment }}
26+
concurrency:
27+
group: build-images-${{ matrix.environment }}
28+
cancel-in-progress: false
29+
permissions:
30+
contents: read
31+
id-token: write
32+
33+
steps:
34+
- name: Checkout repository
35+
uses: actions/checkout@v5
36+
with:
37+
ref: ${{ github.sha }}
38+
persist-credentials: false
39+
40+
- name: Pull deployment secrets into temporary file
41+
uses: Infisical/secrets-action@v1.0.16
42+
with:
43+
method: "oidc"
44+
identity-id: ${{ vars.INFISICAL_MACHINE_IDENTITY_ID }}
45+
project-slug: "infra-deployment"
46+
env-slug: ${{ matrix.environment }}
47+
export-type: "file"
48+
file-output-path: "/.env.infisical"
49+
50+
- name: Load deployment environment
51+
env:
52+
ENVIRONMENT: ${{ matrix.environment }}
53+
run: |
54+
echo "${ENVIRONMENT}" > .last_used_env
55+
cat .env.infisical | sed "s/='\(.*\)'$/=\1/g" > ".env.${ENVIRONMENT}"
56+
57+
set -a
58+
. ".env.${ENVIRONMENT}"
59+
set +a
60+
61+
echo "GCP_REGION=${GCP_REGION}" >> "$GITHUB_ENV"
62+
echo "GCP_PROJECT_ID=${GCP_PROJECT_ID}" >> "$GITHUB_ENV"
63+
echo "GH_WORKLOAD_IDENTITY_PROVIDER=${GH_WORKLOAD_IDENTITY_PROVIDER}" >> "$GITHUB_ENV"
64+
65+
- name: Load runtime environment
66+
uses: Infisical/secrets-action@v1.0.16
67+
with:
68+
method: "oidc"
69+
identity-id: ${{ vars.INFISICAL_MACHINE_IDENTITY_ID }}
70+
project-slug: "infra-deployment-env"
71+
env-slug: ${{ matrix.environment }}
72+
export-type: "env"
73+
74+
- name: Setup Service Account
75+
uses: google-github-actions/auth@v3
76+
with:
77+
project_id: ${{ env.GCP_PROJECT_ID }}
78+
workload_identity_provider: ${{ env.GH_WORKLOAD_IDENTITY_PROVIDER }}
79+
80+
- name: Set up Cloud SDK
81+
uses: google-github-actions/setup-gcloud@v3
82+
83+
- name: Set up Docker
84+
env:
85+
GCP_REGION: ${{ env.GCP_REGION }}
86+
run: |
87+
gcloud auth configure-docker "${GCP_REGION}-docker.pkg.dev" --quiet
88+
ACCESS_TOKEN="$(gcloud auth print-access-token)"
89+
DOCKER_AUTH_BASE64="$(echo -n "{\"username\":\"oauth2accesstoken\",\"password\":\"$ACCESS_TOKEN\"}" | base64 -w 0)"
90+
91+
echo "::add-mask::$DOCKER_AUTH_BASE64"
92+
echo "DOCKER_AUTH_BASE64=${DOCKER_AUTH_BASE64}" >> "$GITHUB_ENV"
93+
94+
- name: Build and upload images
95+
env:
96+
AUTO_CONFIRM_DEPLOY: true
97+
ENVD_UPLOAD_MODE: versioned
98+
run: make build-and-upload

‎.github/workflows/pr-tests-arm64.yml‎

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,25 @@ jobs:
2424
- name: Checkout repository
2525
uses: actions/checkout@v5
2626

27+
# Don't use go-setup-cache here: its key has no arch component, so this
28+
# job would share it with amd64 jobs and restore a multi-GB cache of
29+
# useless amd64 objects, then rebuild everything for arm64 on top —
30+
# which can fill the runner disk (and the arm64 objects never get
31+
# saved). Keep a dedicated arm64-keyed cache instead.
2732
- name: Setup Go
28-
uses: ./.github/actions/go-setup-cache
33+
uses: actions/setup-go@v6
34+
with:
35+
go-version-file: go.work
36+
cache: false
37+
38+
- name: Restore ARM64 Go cache
39+
uses: actions/cache@v5
40+
with:
41+
path: |
42+
~/go/pkg/mod
43+
~/.cache/go-build
44+
key: go-arm64-cross-${{ hashFiles('go.work', 'packages/*/go.mod', 'packages/*/go.sum') }}
45+
restore-keys: go-arm64-cross-
2946

3047
- name: Install ARM64 cross-compiler
3148
run: sudo apt-get update && sudo apt-get install -y gcc-aarch64-linux-gnu

0 commit comments

Comments
 (0)