feat: 서브모듈 최신화 (#371) #63
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: backend-push | |
| on: | |
| push: | |
| branches: [ "develop" ] | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| shell: bash | |
| working-directory: . | |
| permissions: | |
| contents: read | |
| services: | |
| mysql: | |
| image: mysql:latest | |
| ports: | |
| - 3306:3306 | |
| env: | |
| MYSQL_DATABASE: testdb | |
| MYSQL_ROOT_PASSWORD: testdb | |
| options: >- | |
| --health-cmd="mysqladmin ping -h 127.0.0.1 -uroot -ptesdb --silent" | |
| --health-interval=10s | |
| --health-timeout=5s | |
| --health-retries=3 | |
| steps: | |
| - name: CheckOut | |
| uses: actions/checkout@v4 | |
| with: | |
| token: ${{secrets.CONFIG_SUBMODULE_TOKEN}} | |
| submodules: true | |
| - name: Set up JDK 17 | |
| uses: actions/setup-java@v4 | |
| with: | |
| java-version: '17' | |
| distribution: 'temurin' | |
| - name: Setup Gradle | |
| uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0 | |
| - name: Grant execute permission for gradlew | |
| run: chmod +x gradlew | |
| - name: Test with Gradle Wrapper | |
| run: ./gradlew clean build | |
| - name: Login to Docker Hub | |
| uses: docker/login-action@v3 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_PASSWORD }} | |
| - name: Set up Docker BuildX | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Build and push | |
| run: | | |
| docker buildx build \ | |
| --platform linux/amd64,linux/arm64 \ | |
| -t ${{ secrets.DOCKER_USERNAME }}/${{ secrets.DOCKER_IMAGE_BE_PROD }} \ | |
| --push \ | |
| . | |
| deploy: | |
| needs: build | |
| runs-on: self-hosted # self-hosted 러너에서만 실행 | |
| steps: | |
| - name: Create Docker network if not exists | |
| run: | | |
| NETWORK_NAME="kurum_network" | |
| if ! sudo docker network ls --format '{{.Name}}' | grep -w "$NETWORK_NAME" > /dev/null 2>&1; then | |
| echo "Creating Docker network $NETWORK_NAME..." | |
| sudo docker network create $NETWORK_NAME | |
| else | |
| echo "Docker network $NETWORK_NAME already exists." | |
| fi | |
| - name: Docker Image pull | |
| run: sudo docker pull ${{ secrets.DOCKER_USERNAME }}/${{ secrets.DOCKER_IMAGE_BE_PROD }} | |
| - name: Check running container and determine the next port | |
| id: check-port | |
| run: | | |
| echo "Checking if any container is running on ports 8080 or 8081..." | |
| CURRENT_PORT=$(sudo docker ps --format "{{.Names}}" | grep "kurum-backend" | grep -o '8080\|8081' || echo "") | |
| echo "CURRENT_PORT on port $CURRENT_PORT." | |
| if [ "$CURRENT_PORT" == "8081" ]; then | |
| NEXT_PORT=8080 | |
| else | |
| NEXT_PORT=8081 | |
| fi | |
| echo "Next container will run on port $NEXT_PORT." | |
| echo "NEXT_PORT=$NEXT_PORT" >> $GITHUB_ENV | |
| echo "CURRENT_PORT=$CURRENT_PORT" >> $GITHUB_ENV | |
| - name: Run new container on the alternate port | |
| run: | | |
| NETWORK_NAME="kurum_network" | |
| echo "Running new container on port $NEXT_PORT..." | |
| sudo docker run -d \ | |
| --name kurum-backend-$NEXT_PORT \ | |
| --network $NETWORK_NAME \ | |
| -p $NEXT_PORT:8080 \ | |
| -e SPRING_PROFILES_ACTIVE=prod \ | |
| -v log-volume:/app/logs \ | |
| ${{ secrets.DOCKER_USERNAME }}/${{ secrets.DOCKER_IMAGE_BE_PROD }} | |
| - name: Update or create Nginx container to point to new container port | |
| run: | | |
| NGINX_CONTAINER_NAME="nginx-proxy" | |
| NETWORK_NAME="kurum_network" | |
| echo "Next port is $NEXT_PORT" | |
| mkdir -p ./nginx-conf | |
| mkdir -p ./certbot/conf ./certbot/www | |
| cat > ./nginx-conf/default.conf <<EOF | |
| server { | |
| listen 80; | |
| server_name kuroom.shop www.kuroom.shop; | |
| location /.well-known/acme-challenge/ { | |
| root /var/www/certbot; | |
| } | |
| location / { | |
| return 301 https://\$host\$request_uri; | |
| } | |
| } | |
| server { | |
| listen 443 ssl; | |
| server_name kuroom.shop www.kuroom.shop; | |
| ssl_certificate /etc/letsencrypt/live/kuroom.shop/fullchain.pem; | |
| ssl_certificate_key /etc/letsencrypt/live/kuroom.shop/privkey.pem; | |
| location / { | |
| proxy_pass http://kurum-backend-$NEXT_PORT:8080; | |
| proxy_set_header Host \$host; | |
| proxy_set_header X-Real-IP \$remote_addr; | |
| proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; | |
| proxy_set_header X-Forwarded-Proto \$scheme; | |
| client_max_body_size 300M; | |
| } | |
| } | |
| EOF | |
| if sudo docker ps --filter "name=$NGINX_CONTAINER_NAME" --filter "status=running" --format "{{.Names}}" | grep -w $NGINX_CONTAINER_NAME; then | |
| echo "Reloading Nginx config..." | |
| sudo docker cp ./nginx-conf/default.conf $NGINX_CONTAINER_NAME:/etc/nginx/conf.d/default.conf | |
| sudo docker exec $NGINX_CONTAINER_NAME nginx -s reload | |
| else | |
| echo "Starting new Nginx container with HTTPS support..." | |
| sudo docker run -d \ | |
| --name $NGINX_CONTAINER_NAME \ | |
| --network $NETWORK_NAME \ | |
| -p 80:80 -p 443:443 \ | |
| -v $(pwd)/nginx-conf:/etc/nginx/conf.d \ | |
| -v $(pwd)/certbot/conf:/etc/letsencrypt \ | |
| -v $(pwd)/certbot/www:/var/www/certbot \ | |
| nginx | |
| fi | |
| - name: Stop and remove the old container | |
| run: | | |
| CURRENT_PORT=$CURRENT_PORT | |
| if [ -n "$CURRENT_PORT" ]; then | |
| echo "Stopping on port $CURRENT_PORT..." | |
| sudo docker ps --filter "publish=$CURRENT_PORT" --format "{{.ID}}" | xargs sudo docker stop | |
| echo "Sleeping on port $CURRENT_PORT..." | |
| sleep 15 | |
| echo "Removing on port $CURRENT_PORT..." | |
| sudo docker ps -a --format "{{.Names}}" | grep "kurum-backend-$CURRENT_PORT" | xargs sudo docker rm | |
| else | |
| echo "No container to stop and remove." | |
| fi | |
| - name: Remove unused Docker images | |
| run: | | |
| echo "Removing unused Docker images..." | |
| sudo docker image prune -af --filter "until=24h" | |
| echo "Unused Docker images older than 24 hours have been removed." |