FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
guardscale/.github/workflows/release.yml at main · techcto/guardscale · GitHub
techcto
guardscale
Repository navigation
Code
Issues
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
guardscale
/
.github
/
workflows
/
release.yml
Copy path
View runs
More file actions
More file actions
Latest commit
History
History
History
77 lines (77 loc) · 4.31 KB
Breadcrumbs
guardscale
/
.github
/
workflows
/
release.yml
Copy path
File metadata and controls
77 lines (77 loc) · 4.31 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
name
:
Release GuardScale
on
:
push
:
tags
:
['v*']
workflow_dispatch
:
inputs
:
release_version
:
{description: Version without leading v, required: true}
permissions
:
contents
:
read
id-token
:
write
env
:
AWS_REGION
:
${{ vars.AWS_REGION || 'us-east-1' }}
MP_AWS_ECR
:
${{ vars.MP_AWS_ECR }}
GUARDSCALE_CFT_BUCKET
:
${{ vars.GUARDSCALE_CFT_BUCKET || 'guardscale' }}
jobs
:
release
:
runs-on
:
ubuntu-latest
steps
:
-
uses
:
actions/checkout@v4
-
id
:
version
name
:
Resolve release version
env
:
{INPUT_VERSION: '${{ github.event.inputs.release_version }}'}
run
:
|
version="$INPUT_VERSION"
if [ -z "$version" ]; then version="${GITHUB_REF_NAME#v}"; fi
case "$version" in ''|*[!0-9A-Za-z.-]*) exit 1;; esac
echo "value=$version" >> "$GITHUB_OUTPUT"
-
uses
:
aws-actions/configure-aws-credentials@v4
with
:
aws-region
:
${{ env.AWS_REGION }}
aws-access-key-id
:
${{ vars.MP_AWS_ACCESS_KEY_ID }}
aws-secret-access-key
:
${{ secrets.MP_AWS_SECRET_ACCESS_KEY }}
-
run
:
aws ecr get-login-password --region "$AWS_REGION" | docker login --username AWS --password-stdin "$MP_AWS_ECR"
-
uses
:
docker/setup-buildx-action@v3
-
uses
:
actions/setup-go@v5
with
:
go-version-file
:
go.mod
cache
:
true
-
name
:
Test and build agent artifacts
env
:
{VERSION: '${{ steps.version.outputs.value }}'}
run
:
|
go test ./...
mkdir -p dist/agent
for arch in amd64 arm64; do
GOOS=linux GOARCH="$arch" CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o "dist/agent/guardscale-linux-$arch" ./cmd/guardscale
done
cp configs/config.example.yaml dist/agent/config.example.yaml
cp systemd/guardscale.service dist/agent/guardscale.service
cp devops/install-agent.sh dist/agent/install-agent.sh
cd dist/agent
sha256sum guardscale-linux-* config.example.yaml guardscale.service install-agent.sh > SHA256SUMS
-
name
:
Build and publish service images
env
:
{VERSION: '${{ steps.version.outputs.value }}'}
run
:
|
for service in web api worker agent; do
repository="${{ vars.GUARDSCALE_REPOSITORY_PREFIX || 'solodev/guardian' }}-$service"
aws ecr describe-repositories --repository-names "$repository" >/dev/null 2>&1 || aws ecr create-repository --repository-name "$repository" --image-scanning-configuration scanOnPush=true >/dev/null
image="$MP_AWS_ECR/$repository:$VERSION"
docker buildx build --platform linux/amd64 --provenance=false --sbom=false --push -f "devops/docker/Dockerfile.$service" -t "$image" .
done
-
name
:
Publish agent and CloudFormation artifacts
env
:
{VERSION: '${{ steps.version.outputs.value }}'}
run
:
|
bash devops/public-assets.sh
aws s3 cp dist/agent/ "s3://$GUARDSCALE_CFT_BUCKET/agent/$VERSION/" --recursive --cache-control "public,max-age=31536000,immutable" --no-progress
aws s3 cp dist/agent/ "s3://$GUARDSCALE_CFT_BUCKET/agent/latest/" --recursive --cache-control no-cache --no-progress
aws s3 cp devops/cloudformation/guardscale.yaml "s3://$GUARDSCALE_CFT_BUCKET/cloudformation/guardscale-$VERSION.yaml" --content-type text/yaml --cache-control no-cache --no-progress
aws s3 cp devops/cloudformation/guardscale.yaml "s3://$GUARDSCALE_CFT_BUCKET/cloudformation/guardscale.yaml" --content-type text/yaml --cache-control no-cache --no-progress
aws s3 cp devops/cloudformation/guardscale-existing.yaml "s3://$GUARDSCALE_CFT_BUCKET/cloudformation/guardscale-existing-$VERSION.yaml" --content-type text/yaml --cache-control no-cache --no-progress
aws s3 cp devops/cloudformation/guardscale-existing.yaml "s3://$GUARDSCALE_CFT_BUCKET/cloudformation/guardscale-existing.yaml" --content-type text/yaml --cache-control no-cache --no-progress
-
name
:
Submit AWS Marketplace changeset
if
:
${{ vars.MP_AWS_MARKETPLACE_PRODUCT_ID != '' }}
env
:
MP_AWS_MARKETPLACE_PRODUCT_ID
:
${{ vars.MP_AWS_MARKETPLACE_PRODUCT_ID }}
RELEASE_VERSION
:
${{ steps.version.outputs.value }}
GUARDSCALE_REPOSITORY_PREFIX
:
${{ vars.GUARDSCALE_REPOSITORY_PREFIX || 'solodev/guardian' }}
run
:
bash devops/changeset.sh
Back
|
FazBrowse Home
|
New Git URL