name: Build on: push: branches: [main] pull_request: branches: [main] concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true env: TG_NON_INTERACTIVE: 'true' jobs: build: name: Build runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup pnpm uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - name: Setup Node uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version-file: '.nvmrc' - name: Run pnpm install run: pnpm install --frozen-lockfile - name: Build run: pnpm build - name: Upload build output uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: build-output path: 'dist' retention-days: 7 deploy-dev: name: Deploy (dev) runs-on: ubuntu-latest needs: [build] env: ENVIRONMENT: dev TF_VAR_stage: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.number) || '' }} TF_VAR_dist_dir: ${{ github.workspace }}/dist TF_VAR_migrations_dir: ${{ github.workspace }}/apps/version/migrations OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }} steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Get build artifact uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: 'build-output' path: '${{ github.workspace }}/dist' - name: Install 1Password CLI uses: 1password/install-cli-action@1a3160d5e9de1ae0803eaa08a88746f5ae3daa50 # v4.1.0 - id: token uses: immich-app/devtools/actions/create-workflow-token@df46d635b905e618b88fc4c95baa920aeb30b309 # create-workflow-token-action-v3.0.1 with: client-id: ${{ secrets.PUSH_O_MATIC_APP_CLIENT_ID }} private-key: ${{ secrets.PUSH_O_MATIC_APP_KEY }} permission-contents: read permission-pull-requests: write - name: Setup Mise uses: immich-app/devtools/actions/use-mise@06a9ef925332c91be647d6256642b86b398592c8 # use-mise-action-v3.2.1 with: github_token: ${{ steps.token.outputs.token }} - name: Deploy All working-directory: ${{ github.workspace }}/deployment run: mise run tf:apply - name: Collect preview URLs if: ${{ github.event_name == 'pull_request' }} id: preview-urls working-directory: ${{ github.workspace }}/deployment run: | BODY=""$'\n' SHORT_SHA="${{ github.event.pull_request.head.sha }}" SHORT_SHA="${SHORT_SHA:0:7}" BODY+="### Preview Deployments ([${SHORT_SHA}](${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/commit/${{ github.event.pull_request.head.sha }}))"$'\n\n' BODY+="| Worker | Preview URL |"$'\n' BODY+="|--------|-------------|"$'\n' for dir in modules/cloudflare/workers/*/; do worker_name=$(basename "$dir") cd "${{ github.workspace }}/deployment/${dir}" url=$(mise run tg output -raw preview_url 2>/dev/null) || true cd "${{ github.workspace }}/deployment" if [ -n "$url" ]; then BODY+="| ${worker_name} | [${url}](${url}) |"$'\n' fi done { echo "body<> $GITHUB_OUTPUT - name: Comment preview URLs if: ${{ github.event_name == 'pull_request' }} uses: immich-app/devtools/actions/sticky-comment@0135acd12ad9f3369b94a2aa3c0ae8c835a4e926 # sticky-comment-action-v1.0.0 with: id: preview-urls body: ${{ steps.preview-urls.outputs.body }} token: ${{ steps.token.outputs.token }} deploy-prod: name: Deploy (prod) if: github.ref == 'refs/heads/main' runs-on: ubuntu-latest needs: [build] env: ENVIRONMENT: prod TF_VAR_stage: '' TF_VAR_dist_dir: ${{ github.workspace }}/dist TF_VAR_migrations_dir: ${{ github.workspace }}/apps/version/migrations OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }} steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Get build artifact uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: 'build-output' path: '${{ github.workspace }}/dist' - name: Install 1Password CLI uses: 1password/install-cli-action@1a3160d5e9de1ae0803eaa08a88746f5ae3daa50 # v4.1.0 - id: token uses: immich-app/devtools/actions/create-workflow-token@df46d635b905e618b88fc4c95baa920aeb30b309 # create-workflow-token-action-v3.0.1 with: client-id: ${{ secrets.PUSH_O_MATIC_APP_CLIENT_ID }} private-key: ${{ secrets.PUSH_O_MATIC_APP_KEY }} permission-contents: read - name: Setup Mise uses: immich-app/devtools/actions/use-mise@06a9ef925332c91be647d6256642b86b398592c8 # use-mise-action-v3.2.1 with: github_token: ${{ steps.token.outputs.token }} - name: Deploy All working-directory: ${{ github.workspace }}/deployment run: mise run tf:apply