Skip to content

Commit 94d0d54

Browse files
committed
ci: πŸ‘· setup production deployment
1 parent 40b3bd6 commit 94d0d54

14 files changed

Lines changed: 509 additions & 0 deletions
Lines changed: 75 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,75 @@
1+
# GitHub Actions workflow for deploying the application to production environment
2+
# This workflow handles both UI deployment and database migrations
3+
name: Deploy to production environment
4+
5+
# Concurrency control to prevent multiple deployments running simultaneously
6+
# If a new deployment is triggered while one is running, the previous one will be cancelled
7+
concurrency:
8+
group: production-app-deploy
9+
cancel-in-progress: true
10+
11+
# Trigger conditions for this workflow
12+
on:
13+
push:
14+
branches:
15+
- next # Deploy on every push to next branch
16+
workflow_dispatch: # Allow manual triggering from GitHub UI
17+
18+
jobs:
19+
# Job for deploying the UI/frontend application
20+
deploy-ui:
21+
runs-on: ubuntu-latest
22+
23+
# Environment variables for Kamal deployment and container registry
24+
env:
25+
DOCKER_BUILDKIT: 1 # Enable Docker BuildKit for faster builds
26+
KAMAL_REGISTRY_LOGIN_SERVER: ${{ secrets.KAMAL_REGISTRY_LOGIN_SERVER }}
27+
KAMAL_REGISTRY_USERNAME: ${{ secrets.KAMAL_REGISTRY_USERNAME }}
28+
KAMAL_REGISTRY_PASSWORD: ${{ secrets.KAMAL_REGISTRY_PASSWORD }}
29+
KAMAL_SERVER_IP: ${{ secrets.KAMAL_SERVER_IP }}
30+
KAMAL_APP_DOMAIN: ${{ secrets.KAMAL_APP_DOMAIN }}
31+
KAMAL_APP_NAME: ${{ secrets.KAMAL_APP_NAME }}
32+
33+
steps:
34+
# Step 1: Checkout the repository code
35+
- uses: actions/checkout@v4
36+
37+
# Step 2: Setup Ruby environment for Kamal deployment tool
38+
- uses: ruby/setup-ruby@v1
39+
with:
40+
ruby-version: 3.3.1
41+
bundler-cache: true # Cache Ruby dependencies for faster builds
42+
43+
# Step 3: Install Kamal deployment tool
44+
- run: gem install kamal
45+
46+
# Step 4: Setup SSH agent for server access
47+
- uses: webfactory/ssh-agent@v0.9.0
48+
with:
49+
ssh-private-key: ${{ secrets.SSH_PRIVATE_KEY }}
50+
51+
# Step 5: Authenticate with Azure Container Registry
52+
- name: Login to Azure Container Registry
53+
uses: azure/docker-login@v1
54+
with:
55+
login-server: ${{ secrets.KAMAL_REGISTRY_LOGIN_SERVER }}
56+
username: ${{ secrets.KAMAL_REGISTRY_USERNAME }}
57+
password: ${{ secrets.KAMAL_REGISTRY_PASSWORD }}
58+
59+
# Step 6: Setup Docker Buildx for better caching and performance
60+
- name: Set up Docker Buildx for cache
61+
uses: docker/setup-buildx-action@v3
62+
63+
# Step 7: Verify Kamal installation
64+
- run: kamal version
65+
66+
# Step 8: Release any existing deployment locks
67+
# This prevents conflicts when redeploying while a previous deployment is running
68+
- run: kamal lock release
69+
# Uncomment for verbose output during troubleshooting:
70+
# - run: kamal lock release --verbose
71+
72+
# Step 9: Initial Kamal setup (only needed once per server)
73+
# Note: This step might need to be run manually on the server first time
74+
# to add the user to the docker group: `sudo usermod -aG docker $USER | newgrp docker | docker ps`
75+
- run: kamal setup
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
#!/bin/sh
2+
3+
echo "Docker set up on $KAMAL_HOSTS..."
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
#!/bin/sh
2+
3+
# A sample post-deploy hook
4+
#
5+
# These environment variables are available:
6+
# KAMAL_RECORDED_AT
7+
# KAMAL_PERFORMER
8+
# KAMAL_VERSION
9+
# KAMAL_HOSTS
10+
# KAMAL_ROLE (if set)
11+
# KAMAL_DESTINATION (if set)
12+
# KAMAL_RUNTIME
13+
14+
echo "$KAMAL_PERFORMER deployed $KAMAL_VERSION to $KAMAL_DESTINATION in $KAMAL_RUNTIME seconds"
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
#!/bin/sh
2+
3+
echo "Rebooted kamal-proxy on $KAMAL_HOSTS"
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
#!/bin/sh
2+
3+
# A sample pre-build hook
4+
#
5+
# Checks:
6+
# 1. We have a clean checkout
7+
# 2. A remote is configured
8+
# 3. The branch has been pushed to the remote
9+
# 4. The version we are deploying matches the remote
10+
#
11+
# These environment variables are available:
12+
# KAMAL_RECORDED_AT
13+
# KAMAL_PERFORMER
14+
# KAMAL_VERSION
15+
# KAMAL_HOSTS
16+
# KAMAL_ROLE (if set)
17+
# KAMAL_DESTINATION (if set)
18+
19+
if [ -n "$(git status --porcelain)" ]; then
20+
echo "Git checkout is not clean, aborting..." >&2
21+
git status --porcelain >&2
22+
exit 1
23+
fi
24+
25+
first_remote=$(git remote)
26+
27+
if [ -z "$first_remote" ]; then
28+
echo "No git remote set, aborting..." >&2
29+
exit 1
30+
fi
31+
32+
current_branch=$(git branch --show-current)
33+
34+
if [ -z "$current_branch" ]; then
35+
echo "Not on a git branch, aborting..." >&2
36+
exit 1
37+
fi
38+
39+
remote_head=$(git ls-remote $first_remote --tags $current_branch | cut -f1)
40+
41+
if [ -z "$remote_head" ]; then
42+
echo "Branch not pushed to remote, aborting..." >&2
43+
exit 1
44+
fi
45+
46+
if [ "$KAMAL_VERSION" != "$remote_head" ]; then
47+
echo "Version ($KAMAL_VERSION) does not match remote HEAD ($remote_head), aborting..." >&2
48+
exit 1
49+
fi
50+
51+
exit 0
Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
#!/usr/bin/env ruby
2+
3+
# A sample pre-connect check
4+
#
5+
# Warms DNS before connecting to hosts in parallel
6+
#
7+
# These environment variables are available:
8+
# KAMAL_RECORDED_AT
9+
# KAMAL_PERFORMER
10+
# KAMAL_VERSION
11+
# KAMAL_HOSTS
12+
# KAMAL_ROLE (if set)
13+
# KAMAL_DESTINATION (if set)
14+
# KAMAL_RUNTIME
15+
16+
hosts = ENV["KAMAL_HOSTS"].split(",")
17+
results = nil
18+
max = 3
19+
20+
elapsed = Benchmark.realtime do
21+
results = hosts.map do |host|
22+
Thread.new do
23+
tries = 1
24+
25+
begin
26+
Socket.getaddrinfo(host, 0, Socket::AF_UNSPEC, Socket::SOCK_STREAM, nil, Socket::AI_CANONNAME)
27+
rescue SocketError
28+
if tries < max
29+
puts "Retrying DNS warmup: #{host}"
30+
tries += 1
31+
sleep rand
32+
retry
33+
else
34+
puts "DNS warmup failed: #{host}"
35+
host
36+
end
37+
end
38+
39+
tries
40+
end
41+
end.map(&:value)
42+
end
43+
44+
retries = results.sum - hosts.size
45+
nopes = results.count { |r| r == max }
46+
47+
puts "Prewarmed %d DNS lookups in %.2f sec: %d retries, %d failures" % [ hosts.size, elapsed, retries, nopes ]
Lines changed: 109 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
1+
#!/usr/bin/env ruby
2+
3+
# A sample pre-deploy hook
4+
#
5+
# Checks the Github status of the build, waiting for a pending build to complete for up to 720 seconds.
6+
#
7+
# Fails unless the combined status is "success"
8+
#
9+
# These environment variables are available:
10+
# KAMAL_RECORDED_AT
11+
# KAMAL_PERFORMER
12+
# KAMAL_VERSION
13+
# KAMAL_HOSTS
14+
# KAMAL_COMMAND
15+
# KAMAL_SUBCOMMAND
16+
# KAMAL_ROLE (if set)
17+
# KAMAL_DESTINATION (if set)
18+
19+
# Only check the build status for production deployments
20+
if ENV["KAMAL_COMMAND"] == "rollback" || ENV["KAMAL_DESTINATION"] != "production"
21+
exit 0
22+
end
23+
24+
require "bundler/inline"
25+
26+
# true = install gems so this is fast on repeat invocations
27+
gemfile(true, quiet: true) do
28+
source "https://rubygems.org"
29+
30+
gem "octokit"
31+
gem "faraday-retry"
32+
end
33+
34+
MAX_ATTEMPTS = 72
35+
ATTEMPTS_GAP = 10
36+
37+
def exit_with_error(message)
38+
$stderr.puts message
39+
exit 1
40+
end
41+
42+
class GithubStatusChecks
43+
attr_reader :remote_url, :git_sha, :github_client, :combined_status
44+
45+
def initialize
46+
@remote_url = `git config --get remote.origin.url`.strip.delete_prefix("https://github.com/")
47+
@git_sha = `git rev-parse HEAD`.strip
48+
@github_client = Octokit::Client.new(access_token: ENV["GITHUB_TOKEN"])
49+
refresh!
50+
end
51+
52+
def refresh!
53+
@combined_status = github_client.combined_status(remote_url, git_sha)
54+
end
55+
56+
def state
57+
combined_status[:state]
58+
end
59+
60+
def first_status_url
61+
first_status = combined_status[:statuses].find { |status| status[:state] == state }
62+
first_status && first_status[:target_url]
63+
end
64+
65+
def complete_count
66+
combined_status[:statuses].count { |status| status[:state] != "pending"}
67+
end
68+
69+
def total_count
70+
combined_status[:statuses].count
71+
end
72+
73+
def current_status
74+
if total_count > 0
75+
"Completed #{complete_count}/#{total_count} checks, see #{first_status_url} ..."
76+
else
77+
"Build not started..."
78+
end
79+
end
80+
end
81+
82+
83+
$stdout.sync = true
84+
85+
puts "Checking build status..."
86+
attempts = 0
87+
checks = GithubStatusChecks.new
88+
89+
begin
90+
loop do
91+
case checks.state
92+
when "success"
93+
puts "Checks passed, see #{checks.first_status_url}"
94+
exit 0
95+
when "failure"
96+
exit_with_error "Checks failed, see #{checks.first_status_url}"
97+
when "pending"
98+
attempts += 1
99+
end
100+
101+
exit_with_error "Checks are still pending, gave up after #{MAX_ATTEMPTS * ATTEMPTS_GAP} seconds" if attempts == MAX_ATTEMPTS
102+
103+
puts checks.current_status
104+
sleep(ATTEMPTS_GAP)
105+
checks.refresh!
106+
end
107+
rescue Octokit::NotFound
108+
exit_with_error "Build status could not be found"
109+
end
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
#!/bin/sh
2+
3+
echo "Rebooting kamal-proxy on $KAMAL_HOSTS..."

β€Ž.kamal/secretsβ€Ž

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# Secrets defined here are available for reference under registry/password, env/secret, builder/secrets,
2+
# and accessories/*/env/secret in config/deploy.yml. All secrets should be pulled from either
3+
# password manager, ENV, or a file. DO NOT ENTER RAW CREDENTIALS HERE! This file needs to be safe for git.
4+
5+
# Registry secrets
6+
KAMAL_REGISTRY_PASSWORD=$KAMAL_REGISTRY_PASSWORD
7+
KAMAL_REGISTRY_USERNAME=$KAMAL_REGISTRY_USERNAME
8+
KAMAL_REGISTRY_LOGIN_SERVER=$KAMAL_REGISTRY_LOGIN_SERVER # only if you're not using docker hub
9+
10+
# Host secrets
11+
KAMAL_APP_NAME=$KAMAL_APP_NAME
12+
KAMAL_APP_DOMAIN=$KAMAL_APP_DOMAIN
13+
KAMAL_SERVER_IP=$KAMAL_SERVER_IP

β€Ž.kamal/secrets-commonβ€Ž

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
# Common secrets for all environments

0 commit comments

Comments
Β (0)