Files
static-pages/.github/workflows/build.yml
T

219 lines
8.2 KiB
YAML

name: Build
on:
push:
branches: [main]
pull_request:
branches: [main]
release:
types: [published]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
ENVIRONMENT: ${{ github.ref == 'refs/heads/main' && 'prod' || 'dev' }}
MISE_TRUSTED_CONFIG_PATHS: ${{ github.workspace }}/.mise/config.toml
jobs:
build:
name: Build
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- id: token
uses: immich-app/devtools/actions/create-workflow-token@df46d635b905e618b88fc4c95baa920aeb30b309 # create-workflow-token-action-v3.0.1
with:
client-id: ${{ secrets.PUSH_O_MATIC_APP_CLIENT_ID }}
private-key: ${{ secrets.PUSH_O_MATIC_APP_KEY }}
permission-contents: read
- name: Setup Mise
uses: immich-app/devtools/actions/use-mise@06a9ef925332c91be647d6256642b86b398592c8 # use-mise-action-v3.2.1
with:
github_token: ${{ steps.token.outputs.token }}
- name: Get pnpm store directory
id: pnpm-store
run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- name: Cache pnpm store
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ${{ steps.pnpm-store.outputs.path }}
key: ${{ runner.os }}-pnpm-store-${{ hashFiles('pnpm-lock.yaml') }}
restore-keys: |
${{ runner.os }}-pnpm-store-
- name: Install
run: pnpm install --frozen-lockfile
- name: Build
run: pnpm build
env:
PUBLIC_IMMICH_PAY_HOST: ${{ env.ENVIRONMENT == 'dev' && 'https://futopay-test.azurewebsites.net' || 'https://pay.futo.org' }}
PUBLIC_CF_TURNSTILE_SITE: ${{ secrets.CF_TURNSTILE_DEFAULT_INVISIBLE_SITE_KEY }}
- name: Upload builds
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: build
path: |
apps/*/build
apps/*/backend/dist
include-hidden-files: true
if-no-files-found: error
retention-days: 1
deploy:
name: Deploy
runs-on: ubuntu-latest
needs: [build]
if: ${{ !github.event.pull_request.head.repo.fork }}
strategy:
fail-fast: false
matrix:
app_name: ['root', 'ui', 'api', 'awesome', 'my', 'get', 'buy', 'datasets', 'survey']
env:
TF_VAR_app_name: ${{ matrix.app_name }}
TF_VAR_stage: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.number) || '' }}
TF_VAR_dist_dir: ${{ github.workspace }}/apps/${{ matrix.app_name }}.immich.app/backend/dist
TF_VAR_migrations_dir: ${{ github.workspace }}/apps/${{ matrix.app_name }}.immich.app/backend/migrations
OP_SERVICE_ACCOUNT_TOKEN: ${{ github.ref == 'refs/heads/main' && secrets.OP_TF_PROD_ENV || secrets.OP_TF_DEV_ENV }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with: { persist-credentials: false }
- id: token
uses: immich-app/devtools/actions/create-workflow-token@df46d635b905e618b88fc4c95baa920aeb30b309 # create-workflow-token-action-v3.0.1
with:
client-id: ${{ secrets.PUSH_O_MATIC_APP_CLIENT_ID }}
private-key: ${{ secrets.PUSH_O_MATIC_APP_KEY }}
permission-contents: read
- name: Setup Mise
uses: immich-app/devtools/actions/use-mise@06a9ef925332c91be647d6256642b86b398592c8 # use-mise-action-v3.2.1
with:
github_token: ${{ steps.token.outputs.token }}
- name: Get pnpm store directory
id: pnpm-store
run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- name: Cache pnpm store
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ${{ steps.pnpm-store.outputs.path }}
key: ${{ runner.os }}-pnpm-store-${{ hashFiles('pnpm-lock.yaml') }}
restore-keys: |
${{ runner.os }}-pnpm-store-
- name: Install
run: pnpm install --frozen-lockfile
- name: Install 1Password CLI
uses: 1password/install-cli-action@1a3160d5e9de1ae0803eaa08a88746f5ae3daa50 # v4.1.0
- name: Download builds
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: build
path: apps # restore pre-built build and dist folders
- name: Deploy All
working-directory: ${{ github.workspace }}/deployment
env:
APP_NAME: ${{ matrix.app_name }}
APP_DIR: ${{ github.workspace }}/apps/${{ matrix.app_name }}.immich.app
run: |
QUEUE_ARGS=(
--queue-include-dir='modules/cloudflare/pages-project'
--queue-include-dir='modules/cloudflare/static-pages'
)
if [ -d "$APP_DIR/backend/dist" ]; then
QUEUE_ARGS+=(--queue-include-dir="modules/cloudflare/workers/${APP_NAME}")
fi
op run --env-file='.env' -- terragrunt run --all apply \
--non-interactive \
--parallelism 1 \
"${QUEUE_ARGS[@]}"
- name: Cloudflare Deploy Output
id: deploy-output
working-directory: ${{ github.workspace }}/deployment/modules/cloudflare/static-pages
run: |
echo "output=$(op run --no-masking --env-file='../../../.env' -- terragrunt output -json | jq -c .)" >> $GITHUB_OUTPUT
- name: Publish Frontend to Cloudflare Pages
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN_PAGES_UPLOAD }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
BUILD_DIR: apps/${{ matrix.app_name }}.immich.app/build
PROJECT_NAME: ${{ fromJson(steps.deploy-output.outputs.output).pages_project_name.value }}
BRANCH_NAME: ${{ fromJson(steps.deploy-output.outputs.output).pages_branch.value }}
run: mise run deploy
- name: Save preview URL
if: ${{ github.event_name == 'pull_request' }}
env:
APP_NAME: ${{ matrix.app_name }}
SUBDOMAIN: ${{ fromJson(steps.deploy-output.outputs.output).immich_subdomain.value }}
run: |
mkdir -p /tmp/preview-urls
echo "${APP_NAME}|${SUBDOMAIN}" > "/tmp/preview-urls/${APP_NAME}.txt"
- name: Upload preview URL
if: ${{ github.event_name == 'pull_request' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: preview-url-${{ matrix.app_name }}
path: /tmp/preview-urls/${{ matrix.app_name }}.txt
retention-days: 1
preview-comment:
name: Preview Comment
runs-on: ubuntu-latest
needs: [deploy]
if: ${{ !cancelled() && github.event_name == 'pull_request' && !github.event.pull_request.head.repo.fork }}
steps:
- name: Download all preview URLs
continue-on-error: true
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: preview-url-*
path: /tmp/preview-urls
merge-multiple: true
- name: Build comment body
id: build-comment
env:
SHA: ${{ github.event.pull_request.head.sha }}
run: |
shopt -s nullglob
SHORT_SHA="${SHA:0:7}"
BODY="<!-- preview-urls -->"$'\n'
BODY+="### Preview Deployments ([${SHORT_SHA}](${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/commit/${SHA}))"$'\n\n'
BODY+="| App | Preview URL |"$'\n'
BODY+="|-----|-------------|"$'\n'
for file in /tmp/preview-urls/*.txt; do
IFS='|' read -r app_name subdomain < "$file"
BODY+="| ${app_name}.immich.app | [${subdomain}](https://${subdomain}) |"$'\n'
done
{
echo "body<<COMMENT_EOF"
echo "$BODY"
echo "COMMENT_EOF"
} >> $GITHUB_OUTPUT
- name: Comment
uses: immich-app/devtools/actions/sticky-comment@0135acd12ad9f3369b94a2aa3c0ae8c835a4e926 # sticky-comment-action-v1.0.0
with:
id: preview-urls
body: ${{ steps.build-comment.outputs.body }}