Skip to content

Remove Redis password from ecs deployment task #2

Remove Redis password from ecs deployment task

Remove Redis password from ecs deployment task #2

Workflow file for this run

name: Application CI/CD
on:
push:
branches: [ "master" ]
jobs:
tests-n-cs:
uses: ./.github/workflows/tests-n-cs.yml
docker-image-ecr:
runs-on: ubuntu-latest
needs: tests-n-cs
steps:
- name: Check out the repository
uses: actions/checkout@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ vars.AWS_REGION }}
- name: Build Docker image (Octane)
run: docker build . --file Dockerfile.app --tag ${{ vars.DOCKER_IMAGE_TAG }}/octane
- name: Build Docker image (Nginx)
run: docker build . --file Dockerfile.nginx --tag ${{ vars.DOCKER_IMAGE_TAG }}/nginx
- name: Login to Amazon ECR
run: |
aws ecr get-login-password --region ${{ vars.AWS_REGION }} \
| docker login --username AWS --password-stdin ${{ secrets.ECR_REPOSITORY_URI }}
- name: Tag Docker images
run: |
docker tag ${{ vars.DOCKER_IMAGE_TAG }}/octane:latest ${{ secrets.ECR_REPOSITORY_URI }}:latest-octane
docker tag ${{ vars.DOCKER_IMAGE_TAG }}/nginx:latest ${{ secrets.ECR_REPOSITORY_URI }}:latest-nginx
- name: Push Docker images to ECR
run: |
docker push ${{ secrets.ECR_REPOSITORY_URI }}:latest-octane
docker push ${{ secrets.ECR_REPOSITORY_URI }}:latest-nginx
ecs-service-deploy:
runs-on: ubuntu-latest
needs: docker-image-ecr
steps:
- name: Check out the repository
uses: actions/checkout@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ vars.AWS_REGION }}
- name: Update ECS task definition
run: |
sed -i 's|<ECS_TASK_EXEC_ROLE>|${{ secrets.ECS_TASK_EXEC_ROLE }}|' ./ecs/deployment-task.json
sed -i 's|<ECS_SERVICE_NAME>|${{ vars.ECS_SERVICE_NAME }}|' ./ecs/deployment-task.json
sed -i 's|<SSM_NAMESPACE>|${{ secrets.SSM_NAMESPACE }}|' ./ecs/deployment-task.json
sed -i 's|<IMAGE_OCTANE>|${{ secrets.ECR_REPOSITORY_URI }}:latest-octane|' ./ecs/deployment-task.json
sed -i 's|<IMAGE_NGINX>|${{ secrets.ECR_REPOSITORY_URI }}:latest-nginx|' ./ecs/deployment-task.json
- name: Register updated task definition
run: |
aws ecs register-task-definition \
--cli-input-json file://./ecs/deployment-task.json \
--region ${{ vars.AWS_REGION }}
- name: Deploy updated ECS service
run: |
aws ecs update-service \
--cluster ${{ vars.ECS_CLUSTER }} \
--service ${{ vars.ECS_SERVICE_NAME }} \
--force-new-deployment \
--region ${{ vars.AWS_REGION }}