mirror of
https://github.com/immich-app/static-pages.git
synced 2026-09-30 21:27:54 +08:00
219 lines
8.2 KiB
YAML
219 lines
8.2 KiB
YAML
name: Build
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
branches: [main]
|
|
release:
|
|
types: [published]
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
ENVIRONMENT: ${{ github.ref == 'refs/heads/main' && 'prod' || 'dev' }}
|
|
MISE_TRUSTED_CONFIG_PATHS: ${{ github.workspace }}/.mise/config.toml
|
|
|
|
jobs:
|
|
build:
|
|
name: Build
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- id: token
|
|
uses: immich-app/devtools/actions/create-workflow-token@df46d635b905e618b88fc4c95baa920aeb30b309 # create-workflow-token-action-v3.0.1
|
|
with:
|
|
client-id: ${{ secrets.PUSH_O_MATIC_APP_CLIENT_ID }}
|
|
private-key: ${{ secrets.PUSH_O_MATIC_APP_KEY }}
|
|
permission-contents: read
|
|
|
|
- name: Setup Mise
|
|
uses: immich-app/devtools/actions/use-mise@06a9ef925332c91be647d6256642b86b398592c8 # use-mise-action-v3.2.1
|
|
with:
|
|
github_token: ${{ steps.token.outputs.token }}
|
|
|
|
- name: Get pnpm store directory
|
|
id: pnpm-store
|
|
run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Cache pnpm store
|
|
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
|
with:
|
|
path: ${{ steps.pnpm-store.outputs.path }}
|
|
key: ${{ runner.os }}-pnpm-store-${{ hashFiles('pnpm-lock.yaml') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-pnpm-store-
|
|
|
|
- name: Install
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Build
|
|
run: pnpm build
|
|
env:
|
|
PUBLIC_IMMICH_PAY_HOST: ${{ env.ENVIRONMENT == 'dev' && 'https://futopay-test.azurewebsites.net' || 'https://pay.futo.org' }}
|
|
PUBLIC_CF_TURNSTILE_SITE: ${{ secrets.CF_TURNSTILE_DEFAULT_INVISIBLE_SITE_KEY }}
|
|
|
|
- name: Upload builds
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: build
|
|
path: |
|
|
apps/*/build
|
|
apps/*/backend/dist
|
|
include-hidden-files: true
|
|
if-no-files-found: error
|
|
retention-days: 1
|
|
|
|
deploy:
|
|
name: Deploy
|
|
runs-on: ubuntu-latest
|
|
needs: [build]
|
|
if: ${{ !github.event.pull_request.head.repo.fork }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
app_name: ['root', 'ui', 'api', 'awesome', 'my', 'get', 'buy', 'datasets', 'survey']
|
|
env:
|
|
TF_VAR_app_name: ${{ matrix.app_name }}
|
|
TF_VAR_stage: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.number) || '' }}
|
|
TF_VAR_dist_dir: ${{ github.workspace }}/apps/${{ matrix.app_name }}.immich.app/backend/dist
|
|
TF_VAR_migrations_dir: ${{ github.workspace }}/apps/${{ matrix.app_name }}.immich.app/backend/migrations
|
|
OP_SERVICE_ACCOUNT_TOKEN: ${{ github.ref == 'refs/heads/main' && secrets.OP_TF_PROD_ENV || secrets.OP_TF_DEV_ENV }}
|
|
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with: { persist-credentials: false }
|
|
|
|
- id: token
|
|
uses: immich-app/devtools/actions/create-workflow-token@df46d635b905e618b88fc4c95baa920aeb30b309 # create-workflow-token-action-v3.0.1
|
|
with:
|
|
client-id: ${{ secrets.PUSH_O_MATIC_APP_CLIENT_ID }}
|
|
private-key: ${{ secrets.PUSH_O_MATIC_APP_KEY }}
|
|
permission-contents: read
|
|
|
|
- name: Setup Mise
|
|
uses: immich-app/devtools/actions/use-mise@06a9ef925332c91be647d6256642b86b398592c8 # use-mise-action-v3.2.1
|
|
with:
|
|
github_token: ${{ steps.token.outputs.token }}
|
|
|
|
- name: Get pnpm store directory
|
|
id: pnpm-store
|
|
run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Cache pnpm store
|
|
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
|
with:
|
|
path: ${{ steps.pnpm-store.outputs.path }}
|
|
key: ${{ runner.os }}-pnpm-store-${{ hashFiles('pnpm-lock.yaml') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-pnpm-store-
|
|
|
|
- name: Install
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Install 1Password CLI
|
|
uses: 1password/install-cli-action@1a3160d5e9de1ae0803eaa08a88746f5ae3daa50 # v4.1.0
|
|
|
|
- name: Download builds
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
name: build
|
|
path: apps # restore pre-built build and dist folders
|
|
|
|
- name: Deploy All
|
|
working-directory: ${{ github.workspace }}/deployment
|
|
env:
|
|
APP_NAME: ${{ matrix.app_name }}
|
|
APP_DIR: ${{ github.workspace }}/apps/${{ matrix.app_name }}.immich.app
|
|
run: |
|
|
QUEUE_ARGS=(
|
|
--queue-include-dir='modules/cloudflare/pages-project'
|
|
--queue-include-dir='modules/cloudflare/static-pages'
|
|
)
|
|
if [ -d "$APP_DIR/backend/dist" ]; then
|
|
QUEUE_ARGS+=(--queue-include-dir="modules/cloudflare/workers/${APP_NAME}")
|
|
fi
|
|
|
|
op run --env-file='.env' -- terragrunt run --all apply \
|
|
--non-interactive \
|
|
--parallelism 1 \
|
|
"${QUEUE_ARGS[@]}"
|
|
|
|
- name: Cloudflare Deploy Output
|
|
id: deploy-output
|
|
working-directory: ${{ github.workspace }}/deployment/modules/cloudflare/static-pages
|
|
run: |
|
|
echo "output=$(op run --no-masking --env-file='../../../.env' -- terragrunt output -json | jq -c .)" >> $GITHUB_OUTPUT
|
|
|
|
- name: Publish Frontend to Cloudflare Pages
|
|
env:
|
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN_PAGES_UPLOAD }}
|
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
|
BUILD_DIR: apps/${{ matrix.app_name }}.immich.app/build
|
|
PROJECT_NAME: ${{ fromJson(steps.deploy-output.outputs.output).pages_project_name.value }}
|
|
BRANCH_NAME: ${{ fromJson(steps.deploy-output.outputs.output).pages_branch.value }}
|
|
run: mise run deploy
|
|
|
|
- name: Save preview URL
|
|
if: ${{ github.event_name == 'pull_request' }}
|
|
env:
|
|
APP_NAME: ${{ matrix.app_name }}
|
|
SUBDOMAIN: ${{ fromJson(steps.deploy-output.outputs.output).immich_subdomain.value }}
|
|
run: |
|
|
mkdir -p /tmp/preview-urls
|
|
echo "${APP_NAME}|${SUBDOMAIN}" > "/tmp/preview-urls/${APP_NAME}.txt"
|
|
|
|
- name: Upload preview URL
|
|
if: ${{ github.event_name == 'pull_request' }}
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: preview-url-${{ matrix.app_name }}
|
|
path: /tmp/preview-urls/${{ matrix.app_name }}.txt
|
|
retention-days: 1
|
|
|
|
preview-comment:
|
|
name: Preview Comment
|
|
runs-on: ubuntu-latest
|
|
needs: [deploy]
|
|
if: ${{ !cancelled() && github.event_name == 'pull_request' && !github.event.pull_request.head.repo.fork }}
|
|
steps:
|
|
- name: Download all preview URLs
|
|
continue-on-error: true
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
pattern: preview-url-*
|
|
path: /tmp/preview-urls
|
|
merge-multiple: true
|
|
|
|
- name: Build comment body
|
|
id: build-comment
|
|
env:
|
|
SHA: ${{ github.event.pull_request.head.sha }}
|
|
run: |
|
|
shopt -s nullglob
|
|
SHORT_SHA="${SHA:0:7}"
|
|
BODY="<!-- preview-urls -->"$'\n'
|
|
BODY+="### Preview Deployments ([${SHORT_SHA}](${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/commit/${SHA}))"$'\n\n'
|
|
BODY+="| App | Preview URL |"$'\n'
|
|
BODY+="|-----|-------------|"$'\n'
|
|
for file in /tmp/preview-urls/*.txt; do
|
|
IFS='|' read -r app_name subdomain < "$file"
|
|
BODY+="| ${app_name}.immich.app | [${subdomain}](https://${subdomain}) |"$'\n'
|
|
done
|
|
{
|
|
echo "body<<COMMENT_EOF"
|
|
echo "$BODY"
|
|
echo "COMMENT_EOF"
|
|
} >> $GITHUB_OUTPUT
|
|
|
|
- name: Comment
|
|
uses: immich-app/devtools/actions/sticky-comment@0135acd12ad9f3369b94a2aa3c0ae8c835a4e926 # sticky-comment-action-v1.0.0
|
|
with:
|
|
id: preview-urls
|
|
body: ${{ steps.build-comment.outputs.body }}
|