e9b699a881
Release / Release (push) Has been cancelled
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [azure/k8s-create-secret](https://github.com/azure/k8s-create-secret) | action | major | `v5.0.1` → `v6.0.0` | --- ### Release Notes <details> <summary>azure/k8s-create-secret (azure/k8s-create-secret)</summary> ### [`v6.0.0`](https://github.com/Azure/k8s-create-secret/releases/tag/v6.0.0) [Compare Source](https://github.com/azure/k8s-create-secret/compare/v5.0.1...v6.0.0) ##### Added - [#​172](https://github.com/Azure/k8s-create-secret/pull/172) Added logic for TLS secret type handling - [#​166](https://github.com/Azure/k8s-create-secret/pull/166) Add husky pre-commit hook ##### Changed - [#​238](https://github.com/Azure/k8s-create-secret/pull/238) Migrate project to ESM with esbuild and vitest - [#​229](https://github.com/Azure/k8s-create-secret/pull/229) Update Node.js runtime from node20 to node24 - [#​215](https://github.com/Azure/k8s-create-secret/pull/215) Use docker driver in minikube setup - [#​180](https://github.com/Azure/k8s-create-secret/pull/180) Update CODEOWNERS - Bump npm dependencies: `@types/node`, `prettier`, `undici`, `@actions/http-client`, `handlebars`, `picomatch`, `minimatch`, `js-yaml`, `glob`, `tar-fs`, `form-data`, `jest` ([#​174](https://github.com/azure/k8s-create-secret/issues/174), [#​175](https://github.com/azure/k8s-create-secret/issues/175), [#​178](https://github.com/azure/k8s-create-secret/issues/178), [#​179](https://github.com/azure/k8s-create-secret/issues/179), [#​194](https://github.com/azure/k8s-create-secret/issues/194), [#​201](https://github.com/azure/k8s-create-secret/issues/201), [#​203](https://github.com/azure/k8s-create-secret/issues/203), [#​205](https://github.com/azure/k8s-create-secret/issues/205), [#​206](https://github.com/azure/k8s-create-secret/issues/206), [#​209](https://github.com/azure/k8s-create-secret/issues/209), [#​213](https://github.com/azure/k8s-create-secret/issues/213), [#​223](https://github.com/azure/k8s-create-secret/issues/223), [#​226](https://github.com/azure/k8s-create-secret/issues/226), [#​231](https://github.com/azure/k8s-create-secret/issues/231), [#​235](https://github.com/azure/k8s-create-secret/issues/235), [#​236](https://github.com/azure/k8s-create-secret/issues/236)) - Bump GitHub Actions: `github/codeql-action`, `actions/setup-node`, and other grouped action updates in `.github/workflows` ([#​163](https://github.com/azure/k8s-create-secret/issues/163), [#​164](https://github.com/azure/k8s-create-secret/issues/164), [#​169](https://github.com/azure/k8s-create-secret/issues/169), [#​170](https://github.com/azure/k8s-create-secret/issues/170), [#​182](https://github.com/azure/k8s-create-secret/issues/182), [#​183](https://github.com/azure/k8s-create-secret/issues/183), [#​184](https://github.com/azure/k8s-create-secret/issues/184), [#​185](https://github.com/azure/k8s-create-secret/issues/185), [#​186](https://github.com/azure/k8s-create-secret/issues/186), [#​187](https://github.com/azure/k8s-create-secret/issues/187), [#​188](https://github.com/azure/k8s-create-secret/issues/188), [#​189](https://github.com/azure/k8s-create-secret/issues/189), [#​190](https://github.com/azure/k8s-create-secret/issues/190), [#​191](https://github.com/azure/k8s-create-secret/issues/191), [#​197](https://github.com/azure/k8s-create-secret/issues/197), [#​198](https://github.com/azure/k8s-create-secret/issues/198), [#​199](https://github.com/azure/k8s-create-secret/issues/199), [#​200](https://github.com/azure/k8s-create-secret/issues/200), [#​204](https://github.com/azure/k8s-create-secret/issues/204), [#​207](https://github.com/azure/k8s-create-secret/issues/207), [#​208](https://github.com/azure/k8s-create-secret/issues/208), [#​210](https://github.com/azure/k8s-create-secret/issues/210), [#​211](https://github.com/azure/k8s-create-secret/issues/211), [#​212](https://github.com/azure/k8s-create-secret/issues/212), [#​214](https://github.com/azure/k8s-create-secret/issues/214), [#​216](https://github.com/azure/k8s-create-secret/issues/216), [#​217](https://github.com/azure/k8s-create-secret/issues/217), [#​218](https://github.com/azure/k8s-create-secret/issues/218), [#​219](https://github.com/azure/k8s-create-secret/issues/219), [#​221](https://github.com/azure/k8s-create-secret/issues/221), [#​224](https://github.com/azure/k8s-create-secret/issues/224), [#​225](https://github.com/azure/k8s-create-secret/issues/225), [#​227](https://github.com/azure/k8s-create-secret/issues/227), [#​228](https://github.com/azure/k8s-create-secret/issues/228), [#​233](https://github.com/azure/k8s-create-secret/issues/233), [#​237](https://github.com/azure/k8s-create-secret/issues/237)) ##### Fixed - [#​168](https://github.com/Azure/k8s-create-secret/pull/168) Fix for generic secret types </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41LjQiLCJ1cGRhdGVkSW5WZXIiOiI0My41LjQiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImFjdGlvbiIsImRlcHMiXX0=--> Reviewed-on: https://gitea.t000-n.de/t.behrendt/k_deploy_workflows/pulls/53 Reviewed-by: t.behrendt <t.behrendt@noreply.localhost> Co-authored-by: Renovate Bot <renovate@t00n.de> Co-committed-by: Renovate Bot <renovate@t00n.de>
165 lines
6.7 KiB
YAML
165 lines
6.7 KiB
YAML
name: Deploy
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
k8s_dir:
|
|
description: "Override the default k8s directory path (k8s/)"
|
|
required: false
|
|
default: "k8s/"
|
|
type: string
|
|
helmfile_path:
|
|
description: "Override the default helmfile path (hemfile.yaml)"
|
|
required: false
|
|
default: "helmfile.yaml"
|
|
type: string
|
|
skip_helm_deployment:
|
|
description: "Skip Helm deployment even if helmfile.yaml exists"
|
|
required: false
|
|
default: false
|
|
type: boolean
|
|
skip_shared_secrets_deployment:
|
|
description: "Skip shared secrets deployment (e.g. restic backup secret)"
|
|
required: false
|
|
default: false
|
|
type: boolean
|
|
helmfile_env:
|
|
description: "Optional JSON object string of environment variables for Helmfile"
|
|
required: false
|
|
default: "{}"
|
|
type: string
|
|
|
|
jobs:
|
|
detect-service-type:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
has_helmfile: ${{ steps.check-helmfile.outputs.exists }}
|
|
has_k8s: ${{ steps.check-k8s.outputs.exists }}
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- name: Check if helmfile.yaml exists
|
|
id: check-helmfile
|
|
run: |
|
|
if [ -f "${{ inputs.helmfile_path }}" ]; then
|
|
echo "exists=true" >> $GITHUB_OUTPUT
|
|
echo "Found helmfile.yaml at ${{ inputs.helmfile_path }}"
|
|
else
|
|
echo "exists=false" >> $GITHUB_OUTPUT
|
|
echo "No helmfile.yaml found at ${{ inputs.helmfile_path }}"
|
|
fi
|
|
- name: Check if k8s directory exists
|
|
id: check-k8s
|
|
run: |
|
|
if [ -d "${{ inputs.k8s_dir }}" ]; then
|
|
echo "exists=true" >> $GITHUB_OUTPUT
|
|
echo "Found k8s directory at ${{ inputs.k8s_dir }}"
|
|
else
|
|
echo "exists=false" >> $GITHUB_OUTPUT
|
|
echo "No k8s directory found at ${{ inputs.k8s_dir }}"
|
|
fi
|
|
|
|
deploy-shared-secrets:
|
|
runs-on: ubuntu-latest
|
|
needs: detect-service-type
|
|
if: inputs.skip_shared_secrets_deployment != 'true'
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_actions/.gitea/actions/extract-namespace-from-repo-name@0.0.1
|
|
id: namespace
|
|
with:
|
|
repo: ${{ github.repository }}
|
|
- uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0
|
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
|
with:
|
|
method: kubeconfig
|
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
|
- name: Set restic backup secret
|
|
uses: azure/k8s-create-secret@5e49ad902ac755e0815974a44904c728da961747 # v6.0.0
|
|
with:
|
|
namespace: ${{ steps.namespace.outputs.namespace }}
|
|
secret-name: backupsidecar-secret
|
|
secret-type: generic
|
|
data: |
|
|
{
|
|
"restic_password": "${{ secrets.RESTIC_PASSWORD }}",
|
|
"restic_rest_username": "${{ secrets.RESTIC_REST_USERNAME }}",
|
|
"restic_rest_password": "${{ secrets.RESTIC_REST_PASSWORD }}",
|
|
"gotify_token": "${{ secrets.GOTIFY_TOKEN }}"
|
|
}
|
|
|
|
deploy-k8s:
|
|
runs-on: ubuntu-latest
|
|
needs: detect-service-type
|
|
if: needs.detect-service-type.outputs.has_k8s == 'true'
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_actions/.gitea/actions/extract-namespace-from-repo-name@0.0.1
|
|
id: namespace
|
|
with:
|
|
repo: ${{ github.repository }}
|
|
- uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0
|
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
|
with:
|
|
method: kubeconfig
|
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
|
- name: Deploy Kubernetes manifests
|
|
uses: azure/k8s-deploy@c7ebd0d5f39477a23f1b5dea0f52e6db04adf28e # v6.0.0
|
|
with:
|
|
action: deploy
|
|
manifests: "${{ inputs.k8s_dir }}"
|
|
strategy: basic
|
|
namespace: ${{ steps.namespace.outputs.namespace }}
|
|
|
|
deploy-helm:
|
|
runs-on: ubuntu-latest
|
|
needs: detect-service-type
|
|
if: |
|
|
needs.detect-service-type.outputs.has_helmfile == 'true' &&
|
|
needs.detect-service-type.outputs.has_k8s == 'true' &&
|
|
inputs.skip_helm_deployment != 'true'
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_actions/.gitea/actions/extract-namespace-from-repo-name@0.0.1
|
|
id: namespace
|
|
with:
|
|
repo: ${{ github.repository }}
|
|
- uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0
|
|
- uses: azure/setup-helm@dda3372f752e03dde6b3237bc9431cdc2f7a02a2 # v5
|
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
|
with:
|
|
method: kubeconfig
|
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
|
- name: Deploy Helm
|
|
uses: helmfile/helmfile-action@02671705b1dda1dc4b0a4ddd4f9f1ea8f4568c6f # v2.4.3
|
|
with:
|
|
helmfile-args: apply
|
|
env: ${{ fromJSON(inputs.helmfile_env) }}
|
|
|
|
# Summary job that always runs to show what was deployed
|
|
deployment-summary:
|
|
runs-on: ubuntu-latest
|
|
needs: [detect-service-type, deploy-k8s, deploy-helm]
|
|
if: always()
|
|
steps:
|
|
- name: Deployment Summary
|
|
run: |
|
|
echo "## Deployment Summary" >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
|
|
if [ "${{ needs.detect-service-type.outputs.has_k8s }}" == "true" ]; then
|
|
echo "✅ **Kubernetes deployment**: Completed" >> $GITHUB_STEP_SUMMARY
|
|
else
|
|
echo "❌ **Kubernetes deployment**: Skipped (no k8s/ directory found)" >> $GITHUB_STEP_SUMMARY
|
|
fi
|
|
|
|
if [ "${{ needs.detect-service-type.outputs.has_helmfile }}" == "true" ] && [ "${{ inputs.skip_helm_deployment }}" != "true" ]; then
|
|
echo "✅ **Helm deployment**: Completed" >> $GITHUB_STEP_SUMMARY
|
|
elif [ "${{ needs.detect-service-type.outputs.has_helmfile }}" == "true" ] && [ "${{ inputs.skip_helm_deployment }}" == "true" ]; then
|
|
echo "⏭️ **Helm deployment**: Skipped (manually disabled)" >> $GITHUB_STEP_SUMMARY
|
|
else
|
|
echo "⏭️ **Helm deployment**: Skipped (no helmfile.yaml found)" >> $GITHUB_STEP_SUMMARY
|
|
fi
|
|
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "**Service Type**: ${{ needs.detect-service-type.outputs.has_helmfile == 'true' && 'Helm + Kubernetes' || 'Kubernetes Only' }}" >> $GITHUB_STEP_SUMMARY
|