-
Notifications
You must be signed in to change notification settings - Fork 0
84 lines (68 loc) · 3.02 KB
/
ci-cd.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
name: Application CI/CD
on:
push:
branches: [ "master" ]
jobs:
tests-n-cs:
uses: ./.github/workflows/tests-n-cs.yml
docker-image-ecr:
runs-on: ubuntu-latest
needs: tests-n-cs
steps:
- name: Check out the repository
uses: actions/checkout@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ vars.AWS_REGION }}
- name: Login to Amazon ECR
run: |
aws ecr get-login-password --region ${{ vars.AWS_REGION }} \
| docker login --username AWS --password-stdin ${{ secrets.ECR_REPOSITORY_URI }}
- name: Build Docker image (Octane)
run: docker build . --file Dockerfile.app --tag ${{ vars.DOCKER_IMAGE_TAG }}/octane
- name: Build Docker image (Nginx)
run: docker build . --file Dockerfile.nginx --tag ${{ vars.DOCKER_IMAGE_TAG }}/nginx
- name: Tag Docker images
run: |
docker tag ${{ vars.DOCKER_IMAGE_TAG }}/octane:latest ${{ secrets.ECR_REPOSITORY_URI }}:latest-octane
docker tag ${{ vars.DOCKER_IMAGE_TAG }}/nginx:latest ${{ secrets.ECR_REPOSITORY_URI }}:latest-nginx
- name: Push Docker images to ECR
run: |
docker push ${{ secrets.ECR_REPOSITORY_URI }}:latest-octane
docker push ${{ secrets.ECR_REPOSITORY_URI }}:latest-nginx
ecs-service-deploy:
runs-on: ubuntu-latest
needs: docker-image-ecr
steps:
- name: Check out the repository
uses: actions/checkout@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ vars.AWS_REGION }}
- name: Update ECS task definition
run: |
sed -i 's|<ECS_TASK_EXEC_ROLE>|${{ secrets.ECS_TASK_EXEC_ROLE }}|' ./ecs/deployment-task.json
sed -i 's|<ECS_TASK_ROLE>|${{ secrets.ECS_TASK_ROLE }}|' ./ecs/deployment-task.json
sed -i 's|<ECS_SERVICE_NAME>|${{ vars.ECS_SERVICE_NAME }}|' ./ecs/deployment-task.json
sed -i 's|<SSM_NAMESPACE>|${{ secrets.SSM_NAMESPACE }}|' ./ecs/deployment-task.json
sed -i 's|<IMAGE_OCTANE>|${{ secrets.ECR_REPOSITORY_URI }}:latest-octane|' ./ecs/deployment-task.json
sed -i 's|<IMAGE_NGINX>|${{ secrets.ECR_REPOSITORY_URI }}:latest-nginx|' ./ecs/deployment-task.json
- name: Register updated task definition
run: |
aws ecs register-task-definition \
--cli-input-json file://./ecs/deployment-task.json \
--region ${{ vars.AWS_REGION }}
- name: Deploy updated ECS service
run: |
aws ecs update-service \
--cluster ${{ vars.ECS_CLUSTER }} \
--service ${{ vars.ECS_SERVICE_NAME }} \
--task-definition ${{ vars.ECS_SERVICE_NAME }}-task \
--force-new-deployment \
--region ${{ vars.AWS_REGION }}