name: Deploy on: push: branches: - main workflow_dispatch: jobs: check-changes: runs-on: ubuntu-latest outputs: node-labels: ${{ steps.filter.outputs.node-labels }} coredns: ${{ steps.filter.outputs.coredns }} traefik: ${{ steps.filter.outputs.traefik }} steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 0 - uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1 id: filter with: filters: | node-labels: - 'node-labels/**' coredns: - 'coredns/**' traefik: - 'traefik/**' deploy-node-labels: runs-on: ubuntu-latest needs: check-changes if: ${{ needs.check-changes.outputs.node-labels == 'true' || github.event_name == 'workflow_dispatch' }} steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0 - uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0 with: method: kubeconfig kubeconfig: ${{ secrets.KUBECONFIG }} - name: Deploy run: | kubectl apply --server-side --field-manager=t000-n -f node-labels deploy-coredns: runs-on: ubuntu-latest needs: check-changes if: ${{ needs.check-changes.outputs.coredns == 'true' || github.event_name == 'workflow_dispatch' }} steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0 - uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0 with: method: kubeconfig kubeconfig: ${{ secrets.KUBECONFIG }} - name: Deploy run: | kubectl apply -n kube-system -f coredns - name: Restart coredns run: | kubectl -n kube-system rollout restart deployment coredns deploy-traefik: runs-on: ubuntu-latest needs: check-changes if: ${{ needs.check-changes.outputs.traefik == 'true' || github.event_name == 'workflow_dispatch' }} steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0 - uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0 with: method: kubeconfig kubeconfig: ${{ secrets.KUBECONFIG }} - name: Set ionos api credentials uses: azure/k8s-create-secret@6e0ba8047235646753f2a3a3b359b4d0006ff218 # v5.0.1 with: namespace: kube-system secret-name: ionos-api-credentials secret-type: generic data: | { "apiKey": "${{ secrets.IONOS_API_KEY }}" } - name: Set admin basic auth credentials uses: azure/k8s-create-secret@6e0ba8047235646753f2a3a3b359b4d0006ff218 # v5.0.1 with: namespace: kube-system secret-name: admin-basic-auth-credentials secret-type: Opaque data: | { "auth": "${{ secrets.ADMIN_BASIC_AUTH_CREDENTIALS }}" } - name: Deploy uses: azure/k8s-deploy@c8cfec839dc09896b3b8cc40cd13d04792680771 # v5.1.0 with: action: deploy manifests: "traefik/" strategy: basic namespace: kube-system deploy-docker-registry-secret: runs-on: ubuntu-latest needs: check-changes steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0 - uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0 with: method: kubeconfig kubeconfig: ${{ secrets.KUBECONFIG }} - name: Set docker registry credentials run: | kubectl create secret docker-registry regcred-dockerhub \ --docker-server=https://index.docker.io/v1/ \ --docker-username="${{ secrets.DOCKER_USERNAME }}" \ --docker-password="${{ secrets.DOCKER_PASSWORD }}" \ --docker-email="${{ secrets.DOCKER_EMAIL }}" \ --namespace=default \ --dry-run=client -o yaml | kubectl apply -f - - name: Configure image pull secret globally run: | kubectl patch serviceaccount default -p '{"imagePullSecrets": [{"name": "regcred-dockerhub"}]}'