mirror of
https://github.com/coder/coder.git
synced 2026-06-02 20:48:20 +00:00
f947a34103
Co-authored-by: github-actions[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: M Atif Ali <atif@coder.com> Co-authored-by: Ethan Dickson <ethan@coder.com>
187 lines
6.6 KiB
YAML
187 lines
6.6 KiB
YAML
name: dogfood
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
paths:
|
|
- "dogfood/**"
|
|
- ".github/workflows/dogfood.yaml"
|
|
- "flake.lock"
|
|
- "flake.nix"
|
|
pull_request:
|
|
paths:
|
|
- "dogfood/**"
|
|
- ".github/workflows/dogfood.yaml"
|
|
- "flake.lock"
|
|
- "flake.nix"
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build_image:
|
|
if: github.actor != 'dependabot[bot]' # Skip Dependabot PRs
|
|
runs-on: ${{ github.repository_owner == 'coder' && 'depot-ubuntu-22.04-4' || 'ubuntu-latest' }}
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Nix
|
|
uses: nixbuild/nix-quick-install-action@1f095fee853b33114486cfdeae62fa099cda35a9 # v33
|
|
with:
|
|
# Pinning to 2.28 here, as Nix gets a "error: [json.exception.type_error.302] type must be array, but is string"
|
|
# on version 2.29 and above.
|
|
nix_version: "2.28.4"
|
|
|
|
- uses: nix-community/cache-nix-action@135667ec418502fa5a3598af6fb9eb733888ce6a # v6.1.3
|
|
with:
|
|
# restore and save a cache using this key
|
|
primary-key: nix-${{ runner.os }}-${{ hashFiles('**/*.nix', '**/flake.lock') }}
|
|
# if there's no cache hit, restore a cache by this prefix
|
|
restore-prefixes-first-match: nix-${{ runner.os }}-
|
|
# collect garbage until Nix store size (in bytes) is at most this number
|
|
# before trying to save a new cache
|
|
# 1G = 1073741824
|
|
gc-max-store-size-linux: 5G
|
|
# do purge caches
|
|
purge: true
|
|
# purge all versions of the cache
|
|
purge-prefixes: nix-${{ runner.os }}-
|
|
# created more than this number of seconds ago relative to the start of the `Post Restore` phase
|
|
purge-created: 0
|
|
# except the version with the `primary-key`, if it exists
|
|
purge-primary-key: never
|
|
|
|
- name: Get branch name
|
|
id: branch-name
|
|
uses: tj-actions/branch-names@5250492686b253f06fa55861556d1027b067aeb5 # v9.0.2
|
|
|
|
- name: "Branch name to Docker tag name"
|
|
id: docker-tag-name
|
|
run: |
|
|
# Replace / with --, e.g. user/feature => user--feature.
|
|
tag=${BRANCH_NAME//\//--}
|
|
echo "tag=${tag}" >> "$GITHUB_OUTPUT"
|
|
env:
|
|
BRANCH_NAME: ${{ steps.branch-name.outputs.current_branch }}
|
|
|
|
- name: Set up Depot CLI
|
|
uses: depot/setup-action@b0b1ea4f69e92ebf5dea3f8713a1b0c37b2126a5 # v1.6.0
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
|
|
|
|
- name: Login to DockerHub
|
|
if: github.ref == 'refs/heads/main'
|
|
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
|
|
|
- name: Build and push Non-Nix image
|
|
uses: depot/build-push-action@9785b135c3c76c33db102e45be96a25ab55cd507 # v1.16.2
|
|
with:
|
|
project: b4q6ltmpzh
|
|
token: ${{ secrets.DEPOT_TOKEN }}
|
|
buildx-fallback: true
|
|
context: "{{defaultContext}}:dogfood/coder"
|
|
pull: true
|
|
save: true
|
|
push: ${{ github.ref == 'refs/heads/main' }}
|
|
tags: "codercom/oss-dogfood:${{ steps.docker-tag-name.outputs.tag }},codercom/oss-dogfood:latest"
|
|
|
|
- name: Build Nix image
|
|
run: nix build .#dev_image
|
|
|
|
- name: Push Nix image
|
|
if: github.ref == 'refs/heads/main'
|
|
run: |
|
|
docker load -i result
|
|
|
|
CURRENT_SYSTEM=$(nix eval --impure --raw --expr 'builtins.currentSystem')
|
|
|
|
docker image tag "codercom/oss-dogfood-nix:latest-$CURRENT_SYSTEM" "codercom/oss-dogfood-nix:${DOCKER_TAG}"
|
|
docker image push "codercom/oss-dogfood-nix:${DOCKER_TAG}"
|
|
|
|
docker image tag "codercom/oss-dogfood-nix:latest-$CURRENT_SYSTEM" "codercom/oss-dogfood-nix:latest"
|
|
docker image push "codercom/oss-dogfood-nix:latest"
|
|
env:
|
|
DOCKER_TAG: ${{ steps.docker-tag-name.outputs.tag }}
|
|
|
|
deploy_template:
|
|
needs: build_image
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
# Necessary for GCP authentication (https://github.com/google-github-actions/setup-gcloud#usage)
|
|
id-token: write
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Terraform
|
|
uses: ./.github/actions/setup-tf
|
|
|
|
- name: Authenticate to Google Cloud
|
|
uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093 # v3.0.0
|
|
with:
|
|
workload_identity_provider: ${{ vars.GCP_WORKLOAD_ID_PROVIDER }}
|
|
service_account: ${{ vars.GCP_SERVICE_ACCOUNT }}
|
|
|
|
- name: Terraform init and validate
|
|
run: |
|
|
pushd dogfood/
|
|
terraform init
|
|
terraform validate
|
|
popd
|
|
pushd dogfood/coder
|
|
terraform init
|
|
terraform validate
|
|
popd
|
|
pushd dogfood/coder-envbuilder
|
|
terraform init
|
|
terraform validate
|
|
popd
|
|
|
|
- name: Get short commit SHA
|
|
if: github.ref == 'refs/heads/main'
|
|
id: vars
|
|
run: echo "sha_short=$(git rev-parse --short HEAD)" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Get latest commit title
|
|
if: github.ref == 'refs/heads/main'
|
|
id: message
|
|
run: echo "pr_title=$(git log --format=%s -n 1 ${{ github.sha }})" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: "Push template"
|
|
if: github.ref == 'refs/heads/main'
|
|
run: |
|
|
cd dogfood
|
|
terraform apply -auto-approve
|
|
env:
|
|
# Consumed by coderd provider
|
|
CODER_URL: https://dev.coder.com
|
|
CODER_SESSION_TOKEN: ${{ secrets.CODER_SESSION_TOKEN }}
|
|
# Template source & details
|
|
TF_VAR_CODER_DOGFOOD_ANTHROPIC_API_KEY: ${{ secrets.CODER_DOGFOOD_ANTHROPIC_API_KEY }}
|
|
TF_VAR_CODER_TEMPLATE_NAME: ${{ secrets.CODER_TEMPLATE_NAME }}
|
|
TF_VAR_CODER_TEMPLATE_VERSION: ${{ steps.vars.outputs.sha_short }}
|
|
TF_VAR_CODER_TEMPLATE_DIR: ./coder
|
|
TF_VAR_CODER_TEMPLATE_MESSAGE: ${{ steps.message.outputs.pr_title }}
|
|
TF_LOG: info
|