fix: Dockerfile, main.yml buildx 세팅 #7
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: api-gateway CI/CD | |
on: [push, pull_request] | |
jobs: | |
build: | |
name: CI | |
runs-on: ubuntu-latest | |
# environment: production | |
steps: | |
# add ssh key | |
- name: Add ssh file | |
run: | | |
mkdir -p ~/.ssh | |
echo "${{ secrets.API_GATEWAY_SSH }}" > ~/.ssh/id_rsa | |
chmod 400 ~/.ssh/id_rsa | |
- name: Checkout | |
uses: actions/checkout@v3 | |
with: | |
submodules: recursive | |
token: ${{ secrets.ACTION_TOKEN }} # personal token | |
- name: Configure AWS credentials | |
uses: aws-actions/configure-aws-credentials@v1 | |
with: | |
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | |
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
aws-region: ${{ secrets.AWS_REGION }} | |
- name: Get Github Actions IP | |
id: ip | |
uses: haythem/[email protected] | |
- name: Add Github Actions IP to Security group | |
run: | | |
aws ec2 authorize-security-group-ingress --group-id ${{ secrets.AWS_SG_ID }} --protocol tcp --port 22 --cidr ${{ steps.ip.outputs.ipv4 }}/32 | |
- name: Login to Amazon ECR | |
id: login-ecr | |
uses: aws-actions/amazon-ecr-login@v1 | |
- name: Docker build, tag, and push image to Amazon ECR | |
id: build-image | |
# run: | | |
# export DOCKER_CLI_EXPERIMENTAL=enabled | |
# aws ecr get-login-password --region ${{ secrets.AWS_REGION }} | docker login --username AWS --password-stdin ${{ secrets.AWS_ACCOUNT_ID }}.dkr.ecr.${{ secrets.AWS_REGION }}.amazonaws.com | |
# docker buildx create --use --name multi-arch-builder | |
# docker buildx build -t ${{ secrets.AWS_ACCOUNT_ID }}.dkr.ecr.${{ secrets.AWS_REGION }}.amazonaws.com/${{ secrets.ECR_REPOSITORY }}:${{ secrets.ECR_IMAGE_TAG }} --platform linux/arm64 . --push | |
run: | | |
docker buildx create --use --name arm64-my-builder | |
docker buildx --platform linux/arm64/v8 -t ${{ secrets.ECR_REGISTRY }}/${{ secrets.ECR_REPOSITORY }}:${{ secrets.ECR_IMAGE_TAG }} . | |
docker push ${{ secrets.ECR_REGISTRY }}/${{ secrets.ECR_REPOSITORY }}:${{ secrets.ECR_IMAGE_TAG }} | |
deploy: | |
needs: build | |
name: CD | |
runs-on: self-hosted | |
if: github.ref == 'refs/heads/main' | |
steps: | |
- name: Configure AWS credentials | |
uses: aws-actions/configure-aws-credentials@v1 | |
with: | |
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | |
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
aws-region: ap-northeast-2 | |
# - name: Access to AWS EC2 | |
# uses: appleboy/ssh-action@master | |
# with: | |
# host: ${{ secrets.AWS_HOST }} | |
# username: ${{ secrets.AWS_USERNAME }} | |
# key: ${{ secrets.AWS_PRIVATE_KEY }} | |
- name: Login to Amazon ECR | |
id: login-ecr | |
uses: aws-actions/amazon-ecr-login@v1 | |
- name: Stop and Delete container | |
run: | | |
cd ~/api-gateway | |
docker-compose down --rmi all | |
docker volume rm $(docker volume ls -q) | |
- name: Pull image from Amazon ECR | |
run: | | |
docker pull ${{ env.ECR_REGISTRY }}/${{ env.ECR_REPOSITORY }}:${{ env.IMAGE_TAG }} | |
- name: Restart container | |
run: | | |
docker-compose up -d |