feat: framework deploy templates for PHP/Laravel, Java/Spring, Flask,… #49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CD | |
| # What this actually automates today: on a push to master, build the | |
| # backend and frontend production images and publish them to GHCR | |
| # (ghcr.io) -- using the repo's built-in GITHUB_TOKEN, so this runs with | |
| # zero secrets to configure and nothing fabricated. | |
| # | |
| # What it deliberately does NOT do: apply Terraform, touch a real AWS | |
| # account, or deploy anywhere. The `deploy` job is a placeholder gated by | |
| # the `production` GitHub Environment -- it will only run once someone | |
| # with repo admin rights creates that environment (Settings > Environments) | |
| # and adds required reviewers, and its single step is a clearly-labelled | |
| # TODO, not a real deployment command. Wiring it to a real target (which | |
| # AWS account, which Terraform state backend, which secrets) needs a team | |
| # decision, not something to invent silently in a workflow file. | |
| on: | |
| push: | |
| branches: ["master", "main"] | |
| tags: ["v*"] | |
| workflow_dispatch: {} | |
| permissions: | |
| contents: read | |
| packages: write | |
| jobs: | |
| build-and-push-backend: | |
| name: Build & push backend image | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set lowercase repository name | |
| # ghcr.io (and Docker registries in general) require lowercase | |
| # repository names. github.repository preserves the account's | |
| # real casing (NadaBhm/devguard-ai), which buildx then rejects | |
| # with "repository name must be lowercase" -- confirmed failing | |
| # on every push since at least commit 792cf52. | |
| run: echo "REPO_LOWER=$(echo '${{ github.repository }}' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV | |
| - name: Log in to GHCR | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Build and push | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| file: infrastructure/Dockerfile.backend | |
| push: true | |
| tags: | | |
| ghcr.io/${{ env.REPO_LOWER }}/backend:${{ github.sha }} | |
| ghcr.io/${{ env.REPO_LOWER }}/backend:latest | |
| build-and-push-frontend: | |
| name: Build & push frontend image | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set lowercase repository name | |
| run: echo "REPO_LOWER=$(echo '${{ github.repository }}' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV | |
| - name: Log in to GHCR | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Build and push | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| file: infrastructure/Dockerfile.frontend.prod | |
| push: true | |
| tags: | | |
| ghcr.io/${{ env.REPO_LOWER }}/frontend:${{ github.sha }} | |
| ghcr.io/${{ env.REPO_LOWER }}/frontend:latest | |
| deploy: | |
| name: Deploy (placeholder, gated) | |
| needs: [build-and-push-backend, build-and-push-frontend] | |
| runs-on: ubuntu-latest | |
| # Requires a "production" Environment to exist under Settings > | |
| # Environments with required reviewers configured -- until then, this | |
| # job simply waits forever / must be created first. That's intentional: | |
| # no deployment should run unattended before the team has actually | |
| # decided on a target and approval process. | |
| environment: production | |
| steps: | |
| - name: Deploy | |
| run: | | |
| echo "TODO: no real deployment target configured yet." | |
| echo "Images are published at ghcr.io/${{ github.repository }}/{backend,frontend}:${{ github.sha }}" | |
| echo "This step should apply Terraform / update the real AWS target once the team decides on one." | |
| exit 1 |