ci(gl): add Gitea delivery workflows

This commit is contained in:
2026-08-15 00:50:25 +03:30
parent a54070cfad
commit 675def5fe6
7 changed files with 303 additions and 0 deletions
+62
View File
@@ -0,0 +1,62 @@
name: Deploy over SSH
description: SSH into server and update compose services
inputs:
ssh_key:
description: Private SSH key content
required: true
user:
description: SSH username
required: true
host:
description: SSH hostname or IP
required: true
compose_file:
description: Path to compose file on remote server
required: true
compose_project_name:
description: Compose project name on remote server
required: true
services:
description: Space-separated compose services
required: true
registry:
description: OCI registry hostname
required: false
default: oci.reg.darano.ir
registry_username:
description: OCI registry username
required: false
default: admin
registry_password:
description: OCI registry password
required: true
runs:
using: composite
steps:
- name: Deploy over SSH
shell: bash
env:
SSH_KEY: ${{ inputs.ssh_key }}
REMOTE_USER: ${{ inputs.user }}
REMOTE_HOST: ${{ inputs.host }}
COMPOSE_FILE: ${{ inputs.compose_file }}
COMPOSE_PROJECT_NAME: ${{ inputs.compose_project_name }}
SERVICES: ${{ inputs.services }}
REGISTRY: ${{ inputs.registry }}
REGISTRY_USERNAME: ${{ inputs.registry_username }}
REGISTRY_PASSWORD: ${{ inputs.registry_password }}
run: |
mkdir -p ~/.ssh
chmod 700 ~/.ssh
echo "$SSH_KEY" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
printf '%s' "$REGISTRY_PASSWORD" | ssh -i ~/.ssh/deploy_key \
-o StrictHostKeyChecking=no \
-o UserKnownHostsFile=/dev/null \
"$REMOTE_USER@$REMOTE_HOST" \
"docker login '$REGISTRY' -u '$REGISTRY_USERNAME' --password-stdin && \
export COMPOSE_PROJECT_NAME='$COMPOSE_PROJECT_NAME' && \
docker compose -f '$COMPOSE_FILE' up $SERVICES -d --pull=always; \
rc=\$?; \
docker logout '$REGISTRY'; \
exit \$rc"
@@ -0,0 +1,31 @@
name: Docker Build
description: Build image and load it into the local Docker daemon
inputs:
image:
description: Full image name without a tag
required: true
branch:
description: Branch tag
required: true
commit_sha:
description: Commit SHA tag
required: true
runs:
using: composite
steps:
- name: Build
shell: bash
env:
IMAGE: ${{ inputs.image }}
BRANCH: ${{ inputs.branch }}
COMMIT_SHA: ${{ inputs.commit_sha }}
run: |
set -euo pipefail
docker buildx build \
-f build/Dockerfile \
--build-arg "GO_PROXY=https://go.reg.darano.ir" \
--load \
-t "$IMAGE:$BRANCH" \
-t "$IMAGE:$COMMIT_SHA" \
.
+25
View File
@@ -0,0 +1,25 @@
name: Docker Login
description: Login to OCI registry
inputs:
registry:
description: Registry hostname
required: false
default: oci.reg.darano.ir
username:
description: Registry username
required: false
default: admin
password:
description: Registry password
required: true
runs:
using: composite
steps:
- name: Login to registry
shell: bash
env:
REG_USER: ${{ inputs.username }}
REG_PASS: ${{ inputs.password }}
REGISTRY: ${{ inputs.registry }}
run: |
echo "$REG_PASS" | docker login "$REGISTRY" -u "$REG_USER" --password-stdin
+38
View File
@@ -0,0 +1,38 @@
name: Notify Telegram
description: Send CI/CD status message via Bale bot
inputs:
bot_token:
description: Bale bot token
required: true
chat_id:
description: Target chat ID
required: true
status:
description: Job status
required: true
repository:
description: Repository name
required: true
sha:
description: Commit SHA
required: true
runs:
using: composite
steps:
- name: Send notification
shell: bash
env:
BOT_TOKEN: ${{ inputs.bot_token }}
CHAT_ID: ${{ inputs.chat_id }}
STATUS: ${{ inputs.status }}
REPO: ${{ inputs.repository }}
SHA: ${{ inputs.sha }}
run: |
if [ "$STATUS" = "success" ]; then
MSG="✅ CI/CD passed: ${REPO}@${SHA}"
else
MSG="❌ CI/CD failed: ${REPO}@${SHA}"
fi
curl -s -X POST "https://tapi.bale.ai/bot${BOT_TOKEN}/sendMessage" \
-d chat_id="${CHAT_ID}" \
-d text="$MSG"
+49
View File
@@ -0,0 +1,49 @@
---
name: CI/CD Dev
on:
push:
branches:
- dev
jobs:
dev:
runs-on: ubuntu-latest
steps:
- name: Checkout Git
uses: https://git.darano.ir/actions/checkout@v5
with:
token: ${{ gitea.token }}
path: ./
submodules: recursive
- name: Login to registry
uses: ./.gitea/actions/docker-login
with:
password: ${{ secrets.REG_PASS }}
- name: Build
uses: ./.gitea/actions/docker-build-push
with:
image: oci.reg.darano.ir/gl/app
branch: dev
commit_sha: ${{ gitea.sha }}
- name: Push
run: |
docker push oci.reg.darano.ir/gl/app:dev
docker push oci.reg.darano.ir/gl/app:${{ gitea.sha }}
- name: Deploy
uses: ./.gitea/actions/deploy-ssh
with:
ssh_key: ${{ secrets.DEV_SERVER_KEY }}
user: ${{ secrets.DEV_SERVER_USER }}
host: ${{ secrets.DEV_SERVER_HOST }}
compose_file: /services/srv-dev/compose.yml
compose_project_name: srv-dev
services: gl
registry_password: ${{ secrets.REG_PASS }}
- name: Notify Telegram
if: always()
uses: ./.gitea/actions/notify-telegram
with:
bot_token: ${{ secrets.TELEGRAM_BOT_TOKEN }}
chat_id: ${{ secrets.TELEGRAM_CHAT_ID }}
status: ${{ job.status }}
repository: ${{ gitea.repository }}
sha: ${{ gitea.sha }}
+49
View File
@@ -0,0 +1,49 @@
---
name: CI/CD Stage
on:
push:
branches:
- stage
jobs:
stage:
runs-on: ubuntu-latest
steps:
- name: Checkout Git
uses: https://git.darano.ir/actions/checkout@v5
with:
token: ${{ gitea.token }}
path: ./
submodules: recursive
- name: Login to registry
uses: ./.gitea/actions/docker-login
with:
password: ${{ secrets.REG_PASS }}
- name: Build
uses: ./.gitea/actions/docker-build-push
with:
image: oci.reg.darano.ir/gl/app
branch: stage
commit_sha: ${{ gitea.sha }}
- name: Push
run: |
docker push oci.reg.darano.ir/gl/app:stage
docker push oci.reg.darano.ir/gl/app:${{ gitea.sha }}
- name: Deploy
uses: ./.gitea/actions/deploy-ssh
with:
ssh_key: ${{ secrets.STAGE_SERVER_KEY }}
user: ${{ secrets.STAGE_SERVER_USER }}
host: ${{ secrets.STAGE_SERVER_HOST }}
compose_file: /services/srv-stage/compose.yml
compose_project_name: srv-stage
services: gl
registry_password: ${{ secrets.REG_PASS }}
- name: Notify Telegram
if: always()
uses: ./.gitea/actions/notify-telegram
with:
bot_token: ${{ secrets.TELEGRAM_BOT_TOKEN }}
chat_id: ${{ secrets.TELEGRAM_CHAT_ID }}
status: ${{ job.status }}
repository: ${{ gitea.repository }}
sha: ${{ gitea.sha }}
+49
View File
@@ -0,0 +1,49 @@
---
name: CI/CD
on:
push:
branches:
- main
jobs:
main:
runs-on: ubuntu-latest
steps:
- name: Checkout Git
uses: https://git.darano.ir/actions/checkout@v5
with:
token: ${{ gitea.token }}
path: ./
submodules: recursive
- name: Login to registry
uses: ./.gitea/actions/docker-login
with:
password: ${{ secrets.REG_PASS }}
- name: Build
uses: ./.gitea/actions/docker-build-push
with:
image: oci.reg.darano.ir/gl/app
branch: main
commit_sha: ${{ gitea.sha }}
- name: Push
run: |
docker push oci.reg.darano.ir/gl/app:main
docker push oci.reg.darano.ir/gl/app:${{ gitea.sha }}
- name: Deploy
uses: ./.gitea/actions/deploy-ssh
with:
ssh_key: ${{ secrets.PROD_SERVER_KEY }}
user: ${{ secrets.PROD_SERVER_USER }}
host: ${{ secrets.PROD_SERVER_HOST }}
compose_file: /services/srv-main/compose.yml
compose_project_name: srv-main
services: gl
registry_password: ${{ secrets.REG_PASS }}
- name: Notify Telegram
if: always()
uses: ./.gitea/actions/notify-telegram
with:
bot_token: ${{ secrets.TELEGRAM_BOT_TOKEN }}
chat_id: ${{ secrets.TELEGRAM_CHAT_ID }}
status: ${{ job.status }}
repository: ${{ gitea.repository }}
sha: ${{ gitea.sha }}