-
Notifications
You must be signed in to change notification settings - Fork 4
150 lines (134 loc) · 5.58 KB
/
Copy pathdeploy-main.yml
File metadata and controls
150 lines (134 loc) · 5.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
name: Build & Deploy main to mittwald
on:
push:
branches:
- main
# `publish.yml` dispatches this after it created a GitHub Release that no push
# to `main` follows — a pre-graduated promotion (RFC #2711). The docs bake the
# GitHub Releases list in at build time (`output: "export"`), so without a
# rebuild `/releases` keeps showing the release before the promotion. Also the
# manual handle for any other "the deployed site is stale" case.
workflow_dispatch:
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}
concurrency:
group: deploy-main-${{ github.ref }}
cancel-in-progress: false
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
include:
- app: docs
context: apps/docs
image_suffix: docs
- app: storybook
context: packages/components
image_suffix: storybook
steps:
- name: Checkout repository
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v6
- uses: ./.github/actions/prepare-workspace
# The image used to build this itself, which meant a second toolchain
# install and the whole dependency chain rebuilt inside the image — 80 of
# the 449 seconds a docs preview took. Here the runner builds that chain
# and the image only packages what comes out.
#
# NEXT_BASE_PATH was a build-arg for the same reason; the value is the one
# the Dockerfile passed.
- name: Build the docs
if: matrix.image_suffix == 'docs'
run: pnpm nx build docs
env:
NEXT_BASE_PATH: ""
# `main` is the writer that seeds this cache for everyone else. A PR reads
# caches from its own branch and from the default branch, never from
# another PR's. Without an entry written here the broadest restore-key in
# build-previews.yml finds nothing, so every PR's first docs build
# compiles cold. Turbopack's persistent build cache lives in this
# directory (~200MB) and is on by default in Next 16.
#
# Save only — the same split as the nx cache (test.yml writes, everyone
# else restores). What this job builds goes straight to production, so it
# depends on the source and the lockfile alone, never on a blob an earlier
# run left behind. Restoring here would also let the broadest restore-key
# carry a cache across a Next version bump into the deployed image. After
# the build rather than in a post-step, so a build that failed seeds
# nothing.
- name: Save the Next.js build cache
if: matrix.image_suffix == 'docs'
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
with:
path: apps/docs/.next/cache
key:
nextjs-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}-${{
github.sha }}
# Two commands because `build:storybook` declares no nx dependency on the
# components build — the same pair the Dockerfile ran.
- name: Build Storybook
if: matrix.image_suffix == 'storybook'
run: |
pnpm nx build components
pnpm nx build:storybook components
- name: Log in to the Container registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata for Docs
id: meta-docs
if: matrix.image_suffix == 'docs'
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images:
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}/${{ matrix.image_suffix }}
tags: |
type=ref,event=branch
type=raw,value=latest
type=sha
- name: Extract metadata for Storybook
id: meta-storybook
if: matrix.image_suffix == 'storybook'
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images:
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}/${{ matrix.image_suffix }}
tags: |
type=ref,event=branch
type=raw,value=latest
type=sha
- name: Build and push Docker image
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
# The built output and the server config beside it, nothing else — see
# the context's own .dockerignore.
context: ${{ matrix.context }}
push: true
provenance: false # single-manifest image (as before v7)
tags:
${{ matrix.image_suffix == 'docs' && steps.meta-docs.outputs.tags ||
steps.meta-storybook.outputs.tags }}
labels:
${{ matrix.image_suffix == 'docs' && steps.meta-docs.outputs.labels
|| steps.meta-storybook.outputs.labels }}
- name: Trigger docs redeploy webhook
if: matrix.image_suffix == 'docs'
run:
curl --fail --silent --show-error --location "$FLOW_REDEPLOY_WEBHOOK"
env:
FLOW_REDEPLOY_WEBHOOK: ${{ secrets.FLOW_REDEPLOY_WEBHOOK }}
- name: Trigger storybook redeploy webhook
if: matrix.image_suffix == 'storybook'
run:
curl --fail --silent --show-error --location
"$STORYBOOK_REDEPLOY_WEBHOOK"
env:
STORYBOOK_REDEPLOY_WEBHOOK: ${{ secrets.STORYBOOK_REDEPLOY_WEBHOOK }}