51 lines
1.6 KiB
YAML
51 lines
1.6 KiB
YAML
name: Build and Deploy
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: nix
|
|
env:
|
|
GIT_SSH_COMMAND: "ssh -i /run/agenix/ci-deploy-key -o StrictHostKeyChecking=no"
|
|
steps:
|
|
- uses: https://github.com/actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Build NixOS configuration
|
|
run: |
|
|
nix build .#nixosConfigurations.muffin.config.system.build.toplevel -L
|
|
|
|
- name: Deploy via deploy-rs
|
|
run: |
|
|
eval $(ssh-agent -s)
|
|
ssh-add /run/agenix/ci-deploy-key
|
|
nix run github:serokell/deploy-rs -- .#muffin --ssh-opts="-o StrictHostKeyChecking=no"
|
|
|
|
- name: Health check
|
|
run: |
|
|
sleep 10
|
|
ssh -i /run/agenix/ci-deploy-key -o StrictHostKeyChecking=no root@server-public \
|
|
"systemctl is-active gitea && systemctl is-active caddy && systemctl is-active continuwuity && systemctl is-active coturn"
|
|
|
|
- name: Notify success
|
|
if: success()
|
|
run: |
|
|
curl -sf -X POST \
|
|
"https://ntfy.sigkill.computer/deployments" \
|
|
-H "Title: [muffin] Deploy succeeded" \
|
|
-H "Priority: default" \
|
|
-H "Tags: white_check_mark" \
|
|
-d "server-config deployed from commit ${GITHUB_SHA::8}"
|
|
|
|
- name: Notify failure
|
|
if: failure()
|
|
run: |
|
|
curl -sf -X POST \
|
|
"https://ntfy.sigkill.computer/deployments" \
|
|
-H "Title: [muffin] Deploy FAILED" \
|
|
-H "Priority: urgent" \
|
|
-H "Tags: rotating_light" \
|
|
-d "server-config deploy failed at commit ${GITHUB_SHA::8}"
|