Skip to content

Provide hmac keys on the napi (#1450) #311

Provide hmac keys on the napi (#1450)

Provide hmac keys on the napi (#1450) #311

name: Deploy Validation Service Image
on:
push:
branches:
- main
workflow_dispatch:
jobs:
push_to_registry:
name: Push Docker Image to GitHub Packages
runs-on: warp-ubuntu-latest-x64-16x
permissions:
contents: read
packages: write
outputs:
digest: ${{ steps.push.outputs.digest }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Log in to the container registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/${{ github.repository_owner }}/mls-validation-service
- name: Build and push Docker image
uses: docker/build-push-action@v6
id: push
with:
context: .
file: ./dev/validation_service/Dockerfile
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
deploy:
name: Deploy new images to infra
runs-on: warp-ubuntu-latest-x64-16x
needs: push_to_registry
strategy:
matrix:
environment: [ dev, production, testnet-staging ]
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Deploy to ${{ matrix.environment }}
uses: xmtp-labs/terraform-deployer@v1
with:
terraform-token: ${{ secrets.TERRAFORM_TOKEN }}
terraform-org: xmtp
terraform-workspace: ${{ matrix.environment }}
variable-name: validation_service_image
variable-value: "ghcr.io/xmtp/mls-validation-service@${{ needs.push_to_registry.outputs.digest }}"
variable-value-required-prefix: "ghcr.io/xmtp/mls-validation-service@sha256:"