deploy prod from main, remove preview and old test domains #18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: AKS Prod | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| env: | |
| ACR_NAME: corecontainers | |
| IMAGE_NAME: core-frontend-dashboard | |
| RESOURCE_GROUP: core-frontend | |
| AKS_CLUSTER_NAME: core-frontend-kubernetes-cluster | |
| NAMESPACE: core-frontend | |
| DEPLOYMENT_NAME: core-frontend-dashboard | |
| APP_ENV: production | |
| KUBE_DIR: kube/prod | |
| SENTRY_DSN: https://d116b39bd427449799cdd1516f6f97a1@sentry.io/2091955 | |
| jobs: | |
| build-and-deploy: | |
| runs-on: ubuntu-24.04-arm | |
| environment: azure | |
| permissions: | |
| id-token: write | |
| contents: read | |
| outputs: | |
| release: ${{ steps.image.outputs.release }} | |
| sha: ${{ github.sha }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Set image reference | |
| id: image | |
| run: | | |
| TAG=$(echo ${{ github.sha }} | cut -c1-7) | |
| echo "ref=${{ env.ACR_NAME }}.azurecr.io/aks-${{ env.IMAGE_NAME }}:$TAG" >> $GITHUB_OUTPUT | |
| echo "release=$TAG" >> $GITHUB_OUTPUT | |
| - name: Azure Login | |
| uses: azure/login@v2 | |
| with: | |
| client-id: ${{ secrets.AZURE_CLIENT_ID }} | |
| tenant-id: ${{ secrets.AZURE_TENANT_ID }} | |
| subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }} | |
| - name: Docker ACR Login | |
| run: az acr login --name ${{ env.ACR_NAME }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Docker build and push | |
| run: | | |
| docker buildx build \ | |
| --platform linux/arm64 \ | |
| --push \ | |
| --build-arg APP_ENV=${{ env.APP_ENV }} \ | |
| --build-arg SENTRY_DSN=${{ env.SENTRY_DSN }} \ | |
| --build-arg SENTRY_AUTH_TOKEN=${{ secrets.SENTRY_AUTH_TOKEN }} \ | |
| --build-arg GA_TRACKING_CODE=${{ secrets.GA_TRACKING_CODE }} \ | |
| --build-arg NPM_TOKEN=${{ secrets.NPM_TOKEN }} \ | |
| --build-arg API_KEY=${{ secrets.API_KEY }} \ | |
| --build-arg SENTRY_RELEASE=${{ steps.image.outputs.release }} \ | |
| -t ${{ steps.image.outputs.ref }} . | |
| - name: Get AKS credentials | |
| run: | | |
| az aks get-credentials \ | |
| --resource-group ${{ env.RESOURCE_GROUP }} \ | |
| --name ${{ env.AKS_CLUSTER_NAME }} \ | |
| --admin \ | |
| --overwrite-existing | |
| - name: Sync secrets to AKS | |
| run: | | |
| kubectl create secret generic core-frontend-dashboard-secrets \ | |
| --namespace ${{ env.NAMESPACE }} \ | |
| --from-literal=SENTRY_DSN="${{ env.SENTRY_DSN }}" \ | |
| --from-literal=SENTRY_AUTH_TOKEN="${{ secrets.SENTRY_AUTH_TOKEN }}" \ | |
| --from-literal=GA_TRACKING_CODE="${{ secrets.GA_TRACKING_CODE }}" \ | |
| --from-literal=API_KEY="${{ secrets.API_KEY }}" \ | |
| --dry-run=client -o yaml | kubectl apply -f - | |
| - name: Apply Service and HTTPRoute | |
| run: | | |
| kubectl apply -f ${{ env.KUBE_DIR }}/service.yaml | |
| kubectl apply -f ${{ env.KUBE_DIR }}/httproute.yaml | |
| - name: Deploy to AKS | |
| run: | | |
| export IMAGE="${{ steps.image.outputs.ref }}" | |
| envsubst < ${{ env.KUBE_DIR }}/deployment.yaml | kubectl apply -f - | |
| - name: Wait for rollout | |
| run: | | |
| kubectl rollout status deployment/${{ env.DEPLOYMENT_NAME }} \ | |
| --namespace ${{ env.NAMESPACE }} \ | |
| --timeout=300s | |
| upload-sentry-sourcemaps: | |
| name: Upload Sentry sourcemaps (prod) | |
| needs: [build-and-deploy] | |
| runs-on: ubuntu-latest | |
| environment: azure | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| ref: ${{ needs.build-and-deploy.outputs.sha }} | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v4 | |
| with: | |
| version: 9 | |
| - name: Setup Node | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: 24 | |
| cache: pnpm | |
| - name: Configure npm auth for @oacore | |
| run: | | |
| printf "@oacore:registry=https://npm.pkg.github.com\n//npm.pkg.github.com/:_authToken=%s\n" "${{ secrets.NPM_TOKEN }}" > .npmrc | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Remove npm auth | |
| if: always() | |
| run: rm -f .npmrc | |
| - name: Build web app | |
| run: pnpm run build:${{ env.APP_ENV }} | |
| env: | |
| NODE_OPTIONS: --max-old-space-size=4096 | |
| SENTRY_DSN: ${{ env.SENTRY_DSN }} | |
| SENTRY_RELEASE: ${{ needs.build-and-deploy.outputs.release }} | |
| GA_TRACKING_CODE: ${{ secrets.GA_TRACKING_CODE }} | |
| API_KEY: ${{ secrets.API_KEY }} | |
| - name: Create Sentry release | |
| uses: getsentry/action-release@v3 | |
| env: | |
| SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} | |
| SENTRY_ORG: oacore | |
| SENTRY_PROJECT: dashboard-pk | |
| with: | |
| environment: production | |
| release: ${{ needs.build-and-deploy.outputs.release }} | |
| sourcemaps: ./dist/assets | |
| url_prefix: '~/assets' |