The deployed compose (SELinux :Z, TZ, healthcheck, watchtower label) now lives in the repo as the source of truth, and CI asks the VPS Watchtower API to deploy immediately after pushing instead of waiting for the nightly sweep.
44 lines
1.5 KiB
YAML
44 lines
1.5 KiB
YAML
name: Build and Push agentchat Image
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
quality:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: oven-sh/setup-bun@v2
|
|
with:
|
|
bun-version: 1.3.14
|
|
- run: bun install --frozen-lockfile
|
|
- name: Typecheck and test
|
|
run: |
|
|
bun run typecheck
|
|
bun test
|
|
|
|
build-image:
|
|
needs: [quality]
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Log in to container registry
|
|
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login git.gbrown.org -u "${{ secrets.REGISTRY_USER }}" --password-stdin
|
|
- name: Build image
|
|
run: docker build -f docker/Dockerfile -t agentchat:latest .
|
|
- name: Tag and push
|
|
run: |
|
|
docker tag agentchat:latest git.gbrown.org/gib/agentchat:${{ gitea.sha }}
|
|
docker tag agentchat:latest git.gbrown.org/gib/agentchat:latest
|
|
docker push git.gbrown.org/gib/agentchat:${{ gitea.sha }}
|
|
docker push git.gbrown.org/gib/agentchat:latest
|
|
|
|
# Watchtower on the VPS updates labelled containers nightly at 04:30; this
|
|
# asks it to do so immediately. Non-fatal: the sweep still catches it.
|
|
- name: Trigger immediate deploy via Watchtower API
|
|
run: |
|
|
curl -fsS -X POST -H "Authorization: Bearer ${{ secrets.WATCHTOWER_TOKEN }}" \
|
|
http://192.168.2.2:8080/v1/update \
|
|
|| echo "::warning::watchtower trigger failed; nightly sweep will deploy instead"
|