Skip to content

fix: Unify immich db secrets #183

fix: Unify immich db secrets

fix: Unify immich db secrets #183

---
# yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json
name: "Pre-pull Images"
on:
pull_request:
branches: ["main"]
paths: ["kubernetes/main/**"]
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}
cancel-in-progress: true
jobs:
pre-job:
name: Pre-pull Images Pre-Job
runs-on: ubuntu-latest
outputs:
any_changed: ${{ steps.changed-files.outputs.any_changed }}
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
- name: Get Changed Files
id: changed-files
uses: tj-actions/changed-files@dcc7a0cba800f454d79fff4b993e8c3555bcc0a8 # v45
with:
files: kubernetes/main/**
extract-images:
name: Extract Images
needs: pre-job
runs-on: ubuntu-latest
if: ${{ needs.pre-job.outputs.any_changed == 'true' }}
strategy:
matrix:
branches: ["default", "pull"]
fail-fast: false
outputs:
default: ${{ steps.extract-images.outputs.default }}
pull: ${{ steps.extract-images.outputs.pull }}
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
with:
ref: "${{ matrix.branches == 'default' && github.event.repository.default_branch || '' }}"
- name: Gather Images
uses: docker://ghcr.io/allenporter/flux-local:v7.2.0@sha256:892796649505f52f9ad0c4247416b3b161e0f4f49e55a1a73626c98d3def978c
with:
args: >-
get cluster
--all-namespaces
--path /github/workspace/kubernetes/main/cluster/config
--enable-images
--only-images
--output json
--output-file images.json
- name: Output Images
id: extract-images
# shellcheck disable=SC2086
run: echo "${{ matrix.branches }}=$(jq --compact-output '.' images.json)" >> $GITHUB_OUTPUT
compare-images:
name: Compare Images
runs-on: ubuntu-latest
needs: ["pre-job", "extract-images"]
outputs:
images: ${{ steps.compare-images.outputs.images }}
if: ${{ needs.pre-job.outputs.any_changed == 'true' && needs.extract-images.outputs.default != needs.extract-images.outputs.pull }}
steps:
- name: Compare Images
id: compare-images
run: |
images=$(jq --compact-output --null-input \
--argjson f1 '${{ needs.extract-images.outputs.default }}' \
--argjson f2 '${{ needs.extract-images.outputs.pull }}' \
'$f2 - $f1' \
)
echo "images=${images}" >> "${GITHUB_OUTPUT}"
pre-pull-images:
name: Pre-pull Images
runs-on: ["k8s-homelab-runner"]
needs: ["pre-job", "compare-images"]
strategy:
matrix:
images: ${{ fromJSON(needs.compare-images.outputs.images) }}
max-parallel: 4
fail-fast: false
if: ${{ needs.pre-job.outputs.any_changed == 'true' && needs.compare-images.outputs.images != '[]' }}
steps:
- name: Install talosctl
run: curl -fsSL https://talos.dev/install | sh
- name: Pre-pull Image
run: talosctl -n "${NODE_IP}" image pull ${{ matrix.images }}
pre-pull-images-status:
needs: pre-pull-images
name: Pre-pull Images Success
runs-on: ubuntu-latest
if: ${{ always() }}
steps:
- name: Any jobs failed?
if: ${{ contains(needs.*.result, 'failure') }}
run: exit 1
- name: All jobs passed or skipped?
if: ${{ !(contains(needs.*.result, 'failure')) }}
run: echo "All jobs passed or skipped" && echo "${{ toJSON(needs.*.result) }}"