Repository navigation
201 lines (173 loc) · 7 KB
/
Copy pathci_cd.yml
File metadata and controls
201 lines (173 loc) · 7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
name: CI/CD
on:
# Push on main and release tags
push:
branches:
- main
tags:
- "[0-9]+.[0-9]+.[0-9]+"
# PR
pull_request:
branches:
- main
# Merge PRs using merge group
merge_group:
types: [checks_requested]
branches:
- main
# Manual trigger
workflow_dispatch:
inputs:
version:
required: false
description: Provide the OpenRemote version
type: string
is_release:
required: false
description: Whether a new extensions release is created
type: boolean
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: write
jobs:
build:
name: CI/CD
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Checkout main repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: openremote/openremote
path: openremote
ref: master
sparse-checkout: profile
sparse-checkout-cone-mode: false
- name: Set up JDK 21 and gradle cache
id: java
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
with:
distribution: "temurin"
java-version: "21"
cache: "gradle"
- name: Check if this is a publish event
id: is_publish_event
run: |
echo "value=${{ github.repository == 'openremote/extensions' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') }}" >> "$GITHUB_OUTPUT"
- name: Run Spotless check
if: ${{ inputs.is_release != true }}
timeout-minutes: 10
run: ./gradlew spotlessCheck
- name: Run installDist
timeout-minutes: 20
run: ./gradlew installDist
- name: Run integration tests
if: ${{ inputs.is_release != true }}
timeout-minutes: 20
run: |
# Run build
# Make temp dir with 777 mask as docker seems to run as root
mkdir -pm 777 tmp
# Start the dev-testing stack
docker compose -f openremote/profile/dev-testing.yml up -d --no-build
./gradlew test
- name: Login to DockerHub
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
if: ${{ steps.is_publish_event.outputs.value == 'true' }}
with:
username: ${{ secrets._TEMP_DOCKERHUB_USER }}
password: ${{ secrets._TEMP_DOCKERHUB_PASSWORD }}
- name: Install QEMU
if: ${{ steps.is_publish_event.outputs.value == 'true' }}
uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0
with:
platforms: linux/amd64,linux/aarch64
- name: Install Buildx
if: ${{ steps.is_publish_event.outputs.value == 'true' }}
uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0
- name: Build develop image
if: ${{ steps.is_publish_event.outputs.value == 'true' && inputs.is_release != true }}
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
timeout-minutes: 20
with:
context: deployment/build
platforms: linux/amd64,linux/aarch64
load: false
push: true
tags: openremote/manager:develop
build-args: |
GIT_COMMIT=${{ github.sha }}
QUALIFIER=develop
env:
DOCKER_BUILD_SUMMARY: false
DOCKER_BUILD_RECORD_UPLOAD: false
- name: Build manager image
if: ${{ steps.is_publish_event.outputs.value == 'true' && inputs.is_release == true }}
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
timeout-minutes: 20
with:
context: deployment/build
platforms: linux/amd64,linux/aarch64
load: false
push: true
tags: |
openremote/manager:${{ inputs.version }}
openremote/manager:latest
build-args: |
GIT_COMMIT=${{ github.sha }}
QUALIFIER=latest
env:
DOCKER_BUILD_SUMMARY: false
DOCKER_BUILD_RECORD_UPLOAD: false
- name: Publish to Maven Sonatype
if: ${{ steps.is_publish_event.outputs.value == 'true' }}
timeout-minutes: 20
run: ./gradlew publishToSonatype -PsigningKey=$MAVEN_SIGNING_KEY -PsigningPassword=$MAVEN_SIGNING_PASSWORD -PpublishUsername=$MAVEN_USERNAME -PpublishPassword=$MAVEN_PASSWORD
env:
MAVEN_SIGNING_KEY: ${{ secrets._TEMP_MAVEN_SIGNING_KEY }}
MAVEN_SIGNING_PASSWORD: ${{ secrets._TEMP_MAVEN_SIGNING_PASSWORD }}
MAVEN_USERNAME: ${{ secrets._TEMP_MAVEN_USERNAME }}
MAVEN_PASSWORD: ${{ secrets._TEMP_MAVEN_PASSWORD }}
- name: Close and Verify Staging Repository
if: ${{ inputs.is_release }}
# This will poll the Sonatype API and wait until all validation rules pass.
run: ./gradlew findSonatypeStagingRepository closeSonatypeStagingRepository -PpublishUsername=${{ secrets._TEMP_MAVEN_USERNAME }} -PpublishPassword=${{ secrets._TEMP_MAVEN_PASSWORD }}
- name: Release to Maven Central Sonatype
if: ${{ inputs.is_release }}
run: ./gradlew findSonatypeStagingRepository releaseSonatypeStagingRepository -PpublishUsername=${{ secrets._TEMP_MAVEN_USERNAME }} -PpublishPassword=${{ secrets._TEMP_MAVEN_PASSWORD }}
- name: Create OpenRemote deployment token
id: deployment-token
if: ${{ steps.is_publish_event.outputs.value == 'true' }}
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ secrets._TEMP_CI_AUTOMATION_APP_CLIENT_ID }}
private-key: ${{ secrets._TEMP_CI_AUTOMATION_APP_PRIVATE_KEY }}
owner: openremote
repositories: openremote
permission-actions: write
- name: Run deployment
if: ${{ steps.is_publish_event.outputs.value == 'true' }}
run: |
if [ "$IS_RELEASE" == true ]; then
gh workflow run deploy.yml -R openremote/openremote -f ENVIRONMENT="demo" -f MANAGER_TAG="latest" -f CLEAN_INSTALL="true"
else
gh workflow run deploy.yml -R openremote/openremote -f ENVIRONMENT="staging" -f MANAGER_TAG="develop" -f CLEAN_INSTALL="true"
fi
env:
GH_TOKEN: ${{ steps.deployment-token.outputs.token }}
IS_RELEASE: ${{ inputs.is_release }}
- name: Archive test results
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: test-results
path: "**/build/reports/tests"
- name: Archive coverage report
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: coverage-report
path: "**/build/reports/jacoco/test/html"