Files
k_deploy_workflows/.gitea/workflows/deploy.yaml
T
renovate-bot 09494f6be4
Release / Release (push) Successful in 10s
chore(deps): update azure/k8s-deploy action to v7 (#76)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [azure/k8s-deploy](https://github.com/azure/k8s-deploy) | action | major | `v6.0.0` → `v7.0.0` |

---

### Release Notes

<details>
<summary>azure/k8s-deploy (azure/k8s-deploy)</summary>

### [`v7.0.0`](https://github.com/Azure/k8s-deploy/releases/tag/v7.0.0)

[Compare Source](https://github.com/azure/k8s-deploy/compare/v7.0.0...v7.0.0)

##### Changed

- [#&#8203;528](https://github.com/azure/k8s-deploy/issues/528) [Confine manifest paths to GITHUB\_WORKSPACE (**breaking**: workflows passing `manifests:` paths outside the workspace now fail with a clear error)](https://github.com/Azure/k8s-deploy/pull/528)
- [#&#8203;527](https://github.com/azure/k8s-deploy/issues/527) [Pin release workflow to commit SHA for supply chain safety](https://github.com/Azure/k8s-deploy/pull/527)

##### Security

- [#&#8203;528](https://github.com/azure/k8s-deploy/issues/528) [Harden URL fetcher error handling in writeYamlFromURLToFile](https://github.com/Azure/k8s-deploy/pull/528)
- [#&#8203;537](https://github.com/azure/k8s-deploy/issues/537) [Bump undici from 6.25.0 to 6.27.0](https://github.com/Azure/k8s-deploy/pull/537)
- [#&#8203;536](https://github.com/azure/k8s-deploy/issues/536) [Bump actions/checkout in /.github/workflows in the actions group](https://github.com/Azure/k8s-deploy/pull/536)
- [#&#8203;534](https://github.com/azure/k8s-deploy/issues/534) [Bump the actions group with 3 updates](https://github.com/Azure/k8s-deploy/pull/534)
- [#&#8203;533](https://github.com/azure/k8s-deploy/issues/533) [Bump esbuild from 0.28.0 to 0.28.1](https://github.com/Azure/k8s-deploy/pull/533)
- [#&#8203;532](https://github.com/azure/k8s-deploy/issues/532) [Bump github/codeql-action in /.github/workflows in the actions group](https://github.com/Azure/k8s-deploy/pull/532)
- [#&#8203;531](https://github.com/azure/k8s-deploy/issues/531) [Bump @&#8203;types/node from 25.9.1 to 25.9.2 in the actions group](https://github.com/Azure/k8s-deploy/pull/531)
- [#&#8203;530](https://github.com/azure/k8s-deploy/issues/530) [Bump the actions group in /.github/workflows with 2 updates](https://github.com/Azure/k8s-deploy/pull/530)
- [#&#8203;529](https://github.com/azure/k8s-deploy/issues/529) [Bump the actions group with 2 updates](https://github.com/Azure/k8s-deploy/pull/529)
- [#&#8203;526](https://github.com/azure/k8s-deploy/issues/526) [Bump the actions group in /.github/workflows with 2 updates](https://github.com/Azure/k8s-deploy/pull/526)
- [#&#8203;525](https://github.com/azure/k8s-deploy/issues/525) [Bump the actions group with 2 updates](https://github.com/Azure/k8s-deploy/pull/525)
- [#&#8203;524](https://github.com/azure/k8s-deploy/issues/524) [Bump @&#8203;types/node from 25.7.0 to 25.9.0 in the actions group](https://github.com/Azure/k8s-deploy/pull/524)
- [#&#8203;523](https://github.com/azure/k8s-deploy/issues/523) [Bump github/codeql-action in /.github/workflows in the actions group](https://github.com/Azure/k8s-deploy/pull/523)

### [`v7`](https://github.com/azure/k8s-deploy/compare/v6.0.0...v7.0.0)

[Compare Source](https://github.com/azure/k8s-deploy/compare/v6.0.0...v7.0.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjMuOSIsInVwZGF0ZWRJblZlciI6IjQzLjI2My45IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJhY3Rpb24iLCJhdXRvbWVyZ2UiLCJkZXBzIl19-->

Reviewed-on: https://gitea.t000-n.de/t.behrendt/k_deploy_workflows/pulls/76
Reviewed-by: t.behrendt <2+t.behrendt@noreply.localhost>
Co-authored-by: Renovate Bot <renovate@t00n.de>
Co-committed-by: Renovate Bot <renovate@t00n.de>
2026-07-25 15:48:23 +02:00

171 lines
7.1 KiB
YAML

name: Deploy
on:
workflow_call:
inputs:
k8s_dir:
description: "Override the default k8s directory path (k8s/)"
required: false
default: "k8s/"
type: string
helmfile_path:
description: "Override the default helmfile path (hemfile.yaml)"
required: false
default: "helmfile.yaml"
type: string
skip_helm_deployment:
description: "Skip Helm deployment even if helmfile.yaml exists"
required: false
default: false
type: boolean
skip_shared_secrets_deployment:
description: "Skip shared secrets deployment (e.g. restic backup secret)"
required: false
default: false
type: boolean
helmfile_env:
description: "Optional JSON object string of environment variables for Helmfile"
required: false
default: "{}"
type: string
namespace:
description: "Override the default namespace (extracted from repository name)"
required: false
default: ""
type: string
jobs:
detect-service-type:
runs-on: ubuntu-latest
outputs:
has_helmfile: ${{ steps.check-helmfile.outputs.exists }}
has_k8s: ${{ steps.check-k8s.outputs.exists }}
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Check if helmfile.yaml exists
id: check-helmfile
run: |
if [ -f "${{ inputs.helmfile_path }}" ]; then
echo "exists=true" >> $GITHUB_OUTPUT
echo "Found helmfile.yaml at ${{ inputs.helmfile_path }}"
else
echo "exists=false" >> $GITHUB_OUTPUT
echo "No helmfile.yaml found at ${{ inputs.helmfile_path }}"
fi
- name: Check if k8s directory exists
id: check-k8s
run: |
if [ -d "${{ inputs.k8s_dir }}" ]; then
echo "exists=true" >> $GITHUB_OUTPUT
echo "Found k8s directory at ${{ inputs.k8s_dir }}"
else
echo "exists=false" >> $GITHUB_OUTPUT
echo "No k8s directory found at ${{ inputs.k8s_dir }}"
fi
deploy-shared-secrets:
runs-on: ubuntu-latest
needs: detect-service-type
if: inputs.skip_shared_secrets_deployment != 'true'
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_actions/.gitea/actions/extract-namespace-from-repo-name@244a64884838c35a5fc0dc42e0b82bb70b253dfc # 0.0.1
id: namespace
with:
repo: ${{ github.repository }}
- uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0
- uses: azure/k8s-set-context@8698eba2499e9012f0d5085f8798077cce4bc526 # v5.0.1
with:
method: kubeconfig
kubeconfig: ${{ secrets.KUBECONFIG }}
- name: Set restic backup secret
uses: azure/k8s-create-secret@ba774cded95cc0d795806a986fecd1205a6c2320 # v6.0.1
with:
namespace: ${{ inputs.namespace || steps.namespace.outputs.namespace }}
secret-name: backupsidecar-secret
secret-type: generic
data: |
{
"restic_password": "${{ secrets.RESTIC_PASSWORD }}",
"restic_rest_username": "${{ secrets.RESTIC_REST_USERNAME }}",
"restic_rest_password": "${{ secrets.RESTIC_REST_PASSWORD }}",
"gotify_token": "${{ secrets.GOTIFY_TOKEN }}"
}
deploy-k8s:
runs-on: ubuntu-latest
needs: detect-service-type
if: needs.detect-service-type.outputs.has_k8s == 'true'
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_actions/.gitea/actions/extract-namespace-from-repo-name@244a64884838c35a5fc0dc42e0b82bb70b253dfc # 0.0.1
id: namespace
with:
repo: ${{ github.repository }}
- uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0
- uses: azure/k8s-set-context@8698eba2499e9012f0d5085f8798077cce4bc526 # v5.0.1
with:
method: kubeconfig
kubeconfig: ${{ secrets.KUBECONFIG }}
- name: Deploy Kubernetes manifests
uses: azure/k8s-deploy@51ca02a8b7225fbd0924aac359c5b336a5f1e5b4 # v7.0.0
with:
action: deploy
manifests: "${{ inputs.k8s_dir }}"
strategy: basic
namespace: ${{ inputs.namespace || steps.namespace.outputs.namespace }}
deploy-helm:
runs-on: ubuntu-latest
needs: detect-service-type
if: |
needs.detect-service-type.outputs.has_helmfile == 'true' &&
needs.detect-service-type.outputs.has_k8s == 'true' &&
inputs.skip_helm_deployment != 'true'
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_actions/.gitea/actions/extract-namespace-from-repo-name@244a64884838c35a5fc0dc42e0b82bb70b253dfc # 0.0.1
id: namespace
with:
repo: ${{ github.repository }}
- uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
- uses: azure/k8s-set-context@8698eba2499e9012f0d5085f8798077cce4bc526 # v5.0.1
with:
method: kubeconfig
kubeconfig: ${{ secrets.KUBECONFIG }}
- name: Deploy Helm
uses: helmfile/helmfile-action@1f44bcb43e5fb17ecb2685d8b6081ec5f6aa5fcf # v2.4.7
with:
helmfile-args: apply
namespace: ${{ inputs.namespace || steps.namespace.outputs.namespace }}
env: ${{ fromJSON(inputs.helmfile_env) }}
# Summary job that always runs to show what was deployed
deployment-summary:
runs-on: ubuntu-latest
needs: [detect-service-type, deploy-k8s, deploy-helm]
if: always()
steps:
- name: Deployment Summary
run: |
echo "## Deployment Summary" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
if [ "${{ needs.detect-service-type.outputs.has_k8s }}" == "true" ]; then
echo "✅ **Kubernetes deployment**: Completed" >> $GITHUB_STEP_SUMMARY
else
echo "❌ **Kubernetes deployment**: Skipped (no k8s/ directory found)" >> $GITHUB_STEP_SUMMARY
fi
if [ "${{ needs.detect-service-type.outputs.has_helmfile }}" == "true" ] && [ "${{ inputs.skip_helm_deployment }}" != "true" ]; then
echo "✅ **Helm deployment**: Completed" >> $GITHUB_STEP_SUMMARY
elif [ "${{ needs.detect-service-type.outputs.has_helmfile }}" == "true" ] && [ "${{ inputs.skip_helm_deployment }}" == "true" ]; then
echo "⏭️ **Helm deployment**: Skipped (manually disabled)" >> $GITHUB_STEP_SUMMARY
else
echo "⏭️ **Helm deployment**: Skipped (no helmfile.yaml found)" >> $GITHUB_STEP_SUMMARY
fi
echo "" >> $GITHUB_STEP_SUMMARY
echo "**Service Type**: ${{ needs.detect-service-type.outputs.has_helmfile == 'true' && 'Helm + Kubernetes' || 'Kubernetes Only' }}" >> $GITHUB_STEP_SUMMARY