-
Notifications
You must be signed in to change notification settings - Fork 0
191 lines (187 loc) · 7.74 KB
/
Copy pathdeploy-pr.yaml
File metadata and controls
191 lines (187 loc) · 7.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
# Copyright 2020 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
name: "Deploy Staging - Pull Request"
on:
workflow_run:
workflows: ["Continuous Integration - Pull Request"]
types:
- completed
# Prevent concurrent deployments for the same PR
concurrency:
group: ${{ github.workflow }}-${{ github.event.workflow_run.pull_requests[0].number || github.event.workflow_run.id }}
cancel-in-progress: true
jobs:
deployment-tests:
runs-on: ubuntu-24.04
if: ${{ github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'pull_request' }}
environment: gke-staging
permissions:
contents: read
id-token: write
pull-requests: write
statuses: write
strategy:
matrix:
profile: ["local-code"]
fail-fast: true
steps:
- uses: actions/checkout@v7
with:
repository: ${{ github.event.workflow_run.head_repository.full_name }}
ref: ${{ github.event.workflow_run.head_sha }}
allow-unsafe-pr-checkout: true
- name: Download PR Number Artifact
uses: actions/download-artifact@v4
with:
name: pr_number
run-id: ${{ github.event.workflow_run.id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
path: .pr
- name: Resolve PR Number
run: |
if [[ -f .pr/PR_NUMBER ]]; then
PR_NUMBER=$(cat .pr/PR_NUMBER)
else
PR_NUMBER="${{ github.event.workflow_run.pull_requests[0].number }}"
fi
if [[ -z "$PR_NUMBER" || "$PR_NUMBER" == "null" ]]; then
echo "Error: Unable to resolve PR_NUMBER"
exit 1
fi
echo "PR_NUMBER=$PR_NUMBER" >> $GITHUB_ENV
echo "Resolved PR_NUMBER=$PR_NUMBER"
- name: Report Status (Pending)
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh api "/repos/${{ github.repository }}/statuses/${{ github.event.workflow_run.head_sha }}" \
-f state="pending" \
-f target_url="https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}" \
-f description="Deploying to GKE staging..." \
-f context="Deploy Staging / GKE"
- id: auth
uses: google-github-actions/auth@v3
with:
workload_identity_provider: 'projects/816257685787/locations/global/workloadIdentityPools/github-actions-pool/providers/github-provider'
service_account: 'github-action-runner@online-boutique-ci.iam.gserviceaccount.com'
- uses: google-github-actions/setup-gcloud@v2
with:
install_components: 'gke-gcloud-auth-plugin'
- name: Set up QEMU
uses: docker/setup-qemu-action@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Install Skaffold
run: |
curl -Lo skaffold https://storage.googleapis.com/skaffold/releases/latest/skaffold-linux-amd64
chmod +x skaffold
sudo mv skaffold /usr/local/bin
- name: Cache Skaffold cache
uses: actions/cache@v4
with:
path: ~/.skaffold/cache
key: skaffold-${{ runner.os }}-${{ github.workflow }}-${{ github.run_id }}
restore-keys: |
skaffold-${{ runner.os }}-${{ github.workflow }}-
- name: Build + Deploy PR images to GKE
timeout-minutes: 20
run: |
NAMESPACE="pr${PR_NUMBER}"
echo "NAMESPACE=$NAMESPACE" >> $GITHUB_ENV
yes | gcloud auth configure-docker us-docker.pkg.dev
gcloud container clusters get-credentials $PR_CLUSTER --region $REGION --project $PROJECT_ID
cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Namespace
metadata:
name: $NAMESPACE
EOF
echo Deploying application
skaffold config set --global local-cluster false
skaffold run --default-repo=us-docker.pkg.dev/$PROJECT_ID/refs/pull/$PR_NUMBER --tag=$PR_NUMBER --namespace=$NAMESPACE -p network-policies
env:
PROJECT_ID: "online-boutique-ci"
PR_CLUSTER: "prs-gke-cluster"
REGION: "us-central1"
- name: Wait For Pods
timeout-minutes: 20
run: |
set -x
kubectl config set-context --current --namespace=$NAMESPACE
kubectl wait --for=condition=available --timeout=1000s deployment/redis-cart
kubectl wait --for=condition=available --timeout=1000s deployment/adservice
kubectl wait --for=condition=available --timeout=1000s deployment/cartservice
kubectl wait --for=condition=available --timeout=1000s deployment/checkoutservice
kubectl wait --for=condition=available --timeout=1000s deployment/currencyservice
kubectl wait --for=condition=available --timeout=1000s deployment/emailservice
kubectl wait --for=condition=available --timeout=1000s deployment/frontend
kubectl wait --for=condition=available --timeout=1000s deployment/loadgenerator
kubectl wait --for=condition=available --timeout=1000s deployment/paymentservice
kubectl wait --for=condition=available --timeout=1000s deployment/productcatalogservice
kubectl wait --for=condition=available --timeout=1000s deployment/recommendationservice
kubectl wait --for=condition=available --timeout=1000s deployment/shippingservice
- name: Query EXTERNAL_IP for staging
timeout-minutes: 5
run: |
set -x
NAMESPACE="pr${PR_NUMBER}"
get_externalIP() {
kubectl get service frontend-external --namespace $NAMESPACE -o jsonpath='{.status.loadBalancer.ingress[0].ip}'
}
until [[ -n "$(get_externalIP)" ]]; do
echo "Querying for external IP for frontend-external on namespace: $NAMESPACE{}"
sleep 3
done
EXTERNAL_IP=$(get_externalIP)
echo "EXTERNAL_IP=$EXTERNAL_IP" >> $GITHUB_ENV
- name: Smoke Test
timeout-minutes: 5
run: |
set -x
# start fresh loadgenerator pod
kubectl delete pod -l app=loadgenerator
# wait for requests to come in
REQUEST_COUNT="0"
while [[ "$REQUEST_COUNT" -lt "50" ]]; do
sleep 5
REQUEST_COUNT=$(kubectl logs -l app=loadgenerator | grep Aggregated | awk '{print $2}')
done
# ensure there are no errors hitting endpoints
ERROR_COUNT=$(kubectl logs -l app=loadgenerator | grep Aggregated | awk '{print $3}' | sed "s/[(][^)]*[)]//g")
if [[ "$ERROR_COUNT" -gt "0" ]]; then
exit 1
fi
- name: Comment EXTERNAL_IP
timeout-minutes: 5
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
if [[ -n "$PR_NUMBER" && -n "$EXTERNAL_IP" ]]; then
gh pr comment "$PR_NUMBER" --repo "${{ github.repository }}" --body "🚲 PR staged at http://${EXTERNAL_IP}"
fi
sleep 60
- name: Report Status (Final)
if: always()
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
STATE="success"
if [[ "${{ job.status }}" != "success" ]]; then
STATE="failure"
fi
gh api "/repos/${{ github.repository }}/statuses/${{ github.event.workflow_run.head_sha }}" \
-f state="$STATE" \
-f target_url="https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}" \
-f description="Staging deployment $STATE" \
-f context="Deploy Staging / GKE"