name: Build and Deploy on: push: branches: [main] pull_request: branches: [main] concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true env: MISE_TRUSTED_CONFIG_PATHS: ${{ github.workspace }}/.mise/config.toml ENVIRONMENT: ${{ github.ref == 'refs/heads/main' && 'prod' || 'dev' }} jobs: build: strategy: matrix: name: [backend, frontend] name: Build ${{ matrix.name }} runs-on: ubuntu-latest defaults: run: working-directory: ./${{ matrix.name }} steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - id: token uses: immich-app/devtools/actions/create-workflow-token@df46d635b905e618b88fc4c95baa920aeb30b309 # create-workflow-token-action-v3.0.1 with: client-id: ${{ secrets.PUSH_O_MATIC_APP_CLIENT_ID }} private-key: ${{ secrets.PUSH_O_MATIC_APP_KEY }} permission-contents: read - name: Setup Mise uses: immich-app/devtools/actions/use-mise@06a9ef925332c91be647d6256642b86b398592c8 # use-mise-action-v3.2.1 with: github_token: ${{ steps.token.outputs.token }} - name: Run npm install run: npm ci - name: Run build run: npm run build - name: Upload build output uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: build-output-${{ matrix.name }} if-no-files-found: error path: dist retention-days: 1 merge: name: Merge Artifacts runs-on: ubuntu-latest needs: build steps: - name: Merge Artifacts uses: actions/upload-artifact/merge@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: build-output retention-days: 1 deploy: name: Deploy runs-on: ubuntu-latest needs: merge env: TF_VAR_dist_dir: ${{ github.workspace }}/dist TF_VAR_stage: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.number) || '' }} TF_VAR_pages_branch: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.number) || github.ref_name }} OP_SERVICE_ACCOUNT_TOKEN: ${{ github.ref == 'refs/heads/main' && secrets.OP_TF_PROD_ENV || secrets.OP_TF_DEV_ENV }} working_dir: 'deployment' steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: 'Get build artifact' uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: build-output path: '${{ github.workspace }}/dist' - name: Install 1Password CLI uses: 1password/install-cli-action@1a3160d5e9de1ae0803eaa08a88746f5ae3daa50 # v4.1.0 - id: token uses: immich-app/devtools/actions/create-workflow-token@df46d635b905e618b88fc4c95baa920aeb30b309 # create-workflow-token-action-v3.0.1 with: client-id: ${{ secrets.PUSH_O_MATIC_APP_CLIENT_ID }} private-key: ${{ secrets.PUSH_O_MATIC_APP_KEY }} permission-contents: read - name: Setup Mise uses: immich-app/devtools/actions/use-mise@06a9ef925332c91be647d6256642b86b398592c8 # use-mise-action-v3.2.1 with: github_token: ${{ steps.token.outputs.token }} - name: Deploy All working-directory: ${{ env.working_dir }} run: op run --env-file=".env" -- terragrunt run --all apply --non-interactive - name: Deploy Backend Output id: deploy-backend-output working-directory: ${{ env.working_dir }}/modules/cloudflare/backend run: | echo "output=$(op run --no-masking --env-file='../../../.env' -- terragrunt output -json | jq -c .)" >> $GITHUB_OUTPUT - name: Deploy Frontend Output id: deploy-frontend-output working-directory: ${{ env.working_dir }}/modules/cloudflare/frontend run: | echo "output=$(op run --no-masking --env-file='../../../.env' -- terragrunt output -json | jq -c .)" >> $GITHUB_OUTPUT - name: Publish Frontend to Cloudflare Pages env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN_PAGES_UPLOAD }} CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} BUILD_DIR: dist/frontend PROJECT_NAME: ${{ fromJson(steps.deploy-frontend-output.outputs.output).pages_project_name.value }} BRANCH_NAME: ${{ fromJson(steps.deploy-frontend-output.outputs.output).pages_branch.value }} run: mise run deploy - name: Comment uses: immich-app/devtools/actions/sticky-comment@0135acd12ad9f3369b94a2aa3c0ae8c835a4e926 # sticky-comment-action-v1.0.0 if: ${{ github.event_name == 'pull_request' }} with: id: web-pr-url body: | 🚀 Preview deployed to: - Frontend URL: https://${{ fromJson(steps.deploy-frontend-output.outputs.output).immich_subdomain.value }} - Backend URL: ${{ fromJson(steps.deploy-backend-output.outputs.output).data_api_url.value }}