-
Notifications
You must be signed in to change notification settings - Fork 0
185 lines (162 loc) · 4.77 KB
/
Copy pathci.yml
File metadata and controls
185 lines (162 loc) · 4.77 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
name: CI/CD Pipeline
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
env:
REGISTRY: ghcr.io
BACKEND_IMAGE: ${{ github.repository }}-backend
FRONTEND_IMAGE: ${{ github.repository }}-frontend
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Run OWASP Dependency Check
uses: dependency-check/Dependency-Check_Action@main
with:
project: 'Product Management'
path: '.'
format: 'HTML'
out: 'reports'
build-backend:
needs: security
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Set up JDK 17
uses: actions/setup-java@v3
with:
java-version: '17'
distribution: 'temurin'
- name: Build with Maven
run: ./mvnw clean package
- name: Run tests
run: ./mvnw test
- name: Upload test results
uses: actions/upload-artifact@v3
with:
name: test-results
path: backend/target/surefire-reports
build-frontend:
needs: security
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Set up Node.js
uses: actions/setup-node@v3
with:
node-version: '18'
- name: Install dependencies
run: cd frontend && npm ci
- name: Run tests
run: cd frontend && npm test
- name: Build
run: cd frontend && npm run build
- name: Upload build artifacts
uses: actions/upload-artifact@v3
with:
name: frontend-build
path: frontend/dist
build-and-test:
needs: [build-backend, build-frontend]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up JDK 17
uses: actions/setup-java@v4
with:
java-version: '17'
distribution: 'temurin'
cache: maven
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: '18'
cache: 'npm'
- name: Build and Test Backend
run: |
cd backend
./mvnw clean verify
- name: Install Frontend Dependencies
run: |
cd frontend
npm ci
- name: Lint Frontend
run: |
cd frontend
npm run lint
- name: Test Frontend
run: |
cd frontend
npm run test -- --watch=false
build-and-push:
needs: build-and-test
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and Push Backend Image
uses: docker/build-push-action@v5
with:
context: ./backend
push: true
tags: |
${{ env.REGISTRY }}/${{ env.BACKEND_IMAGE }}:latest
${{ env.REGISTRY }}/${{ env.BACKEND_IMAGE }}:${{ github.sha }}
- name: Build and Push Frontend Image
uses: docker/build-push-action@v5
with:
context: ./frontend
push: true
tags: |
${{ env.REGISTRY }}/${{ env.FRONTEND_IMAGE }}:latest
${{ env.REGISTRY }}/${{ env.FRONTEND_IMAGE }}:${{ github.sha }}
deploy-staging:
needs: build-and-push
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
environment: staging
steps:
- uses: actions/checkout@v4
- name: Deploy to Staging
uses: appleboy/ssh-action@v1.0.3
with:
host: ${{ secrets.STAGING_HOST }}
username: ${{ secrets.STAGING_USER }}
key: ${{ secrets.STAGING_SSH_KEY }}
script: |
cd /opt/app
echo "DB_USER=${{ secrets.DB_USER }}" > .env
echo "DB_PASSWORD=${{ secrets.DB_PASSWORD }}" >> .env
docker compose pull
docker compose up -d
deploy-production:
needs: build-and-push
if: startsWith(github.ref, 'refs/tags/')
runs-on: ubuntu-latest
environment: production
steps:
- uses: actions/checkout@v4
- name: Deploy to Production
uses: appleboy/ssh-action@v1.0.3
with:
host: ${{ secrets.PROD_HOST }}
username: ${{ secrets.PROD_USER }}
key: ${{ secrets.PROD_SSH_KEY }}
script: |
cd /opt/app
echo "DB_USER=${{ secrets.DB_USER }}" > .env
echo "DB_PASSWORD=${{ secrets.DB_PASSWORD }}" >> .env
docker compose pull
docker compose up -d