Skip to content

workflows: bump github/codeql-action from 3.28.1 to 3.28.2 #942

workflows: bump github/codeql-action from 3.28.1 to 3.28.2

workflows: bump github/codeql-action from 3.28.1 to 3.28.2 #942

Workflow file for this run

name: Test and deploy to GKE
on:
push:
branches:
- main
pull_request:
permissions:
contents: read
jobs:
checks:
runs-on: ubuntu-latest
env:
BUNDLE_WITH: development
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false
- name: Set up Ruby
uses: ruby/setup-ruby@4a9ddd6f338a97768b8006bf671dfbad383215f4 # v1.207.0
with:
bundler-cache: true
- name: Check Tapioca excludes
run: bundle exec ./.github/scripts/tapioca-exclude-check.rb
- name: Check RBI shims
run: bundle exec tapioca check-shims
- name: Run Sorbet typecheck
run: bundle exec srb tc
- name: Run RuboCop
run: bundle exec rubocop
- name: Build Docker image
run: docker build --build-arg RUBY_VERSION="$(<.ruby-version)" .
deploy:
needs: checks
if: github.repository_owner == 'Homebrew' && github.event_name == 'push'
runs-on: ubuntu-latest
environment: production
concurrency: production
env:
IMAGE: us-central1-docker.pkg.dev/${{ secrets.GCP_PROJECT_ID }}/homebrew-docker/ci-orchestrator:${{ github.sha }}
permissions:
contents: read
id-token: write
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false
- name: Authenticate to Google Cloud
id: gcloud-auth
uses: google-github-actions/auth@6fc4af4b145ae7821d527454aa9bd537d1f2dc5f # v2.1.7
with:
token_format: access_token
workload_identity_provider: projects/${{ secrets.GCP_PROJECT_NUM }}/locations/global/workloadIdentityPools/ci-orchestrator-deploy/providers/github-actions
service_account: ci-orchestrator-deploy@${{ secrets.GCP_PROJECT_ID }}.iam.gserviceaccount.com
- name: Configure Docker
env:
GCLOUD_ACCESS_TOKEN: ${{ steps.gcloud-auth.outputs.access_token }}
run: |-
echo "$GCLOUD_ACCESS_TOKEN" | docker login -u oauth2accesstoken --password-stdin https://us-central1-docker.pkg.dev
- name: Build Docker image
run: |-
docker build --tag "$IMAGE" --build-arg RUBY_VERSION="$(<.ruby-version)" .
- name: Publish Docker image
run: |-
docker push "$IMAGE"
- name: Get GKE credentials
uses: google-github-actions/get-gke-credentials@9025e8f90f2d8e0c3dafc3128cc705a26d992a6a # v2.3.0
with:
cluster_name: ci-orchestrator
location: us-central1-c
- name: Deploy Kubernetes
working-directory: deployment
env:
CERTBOT_EMAIL: ${{ secrets.CERTBOT_EMAIL }}
DOMAIN: ${{ secrets.DOMAIN }}
PUBLIC_IP: ${{ secrets.PUBLIC_IP }}
ORKA_BASE_URL: ${{ secrets.ORKA_BASE_URL }}
GITHUB_CLIENT_ID: ${{ secrets.GITHUBCLIENT_ID }}
GITHUB_ORGANISATION: ${{ github.repository_owner }}
GITHUB_INSTALLATION_ID: ${{ secrets.GITHUBAPP_INSTALLATION_ID }}
run: |-
sed -f /dev/stdin deployment.yml.in > deployment.yml <<SED_SCRIPT
s|@IMAGE@|$IMAGE|g
s|@CERTBOT_EMAIL@|$CERTBOT_EMAIL|g
SED_SCRIPT
sed -f /dev/stdin config.yml.in > config.yml <<SED_SCRIPT
s|@DOMAIN@|$DOMAIN|g
s|@PUBLIC_IP@|$PUBLIC_IP|g
s|@ORKA_BASE_URL@|$ORKA_BASE_URL|g
s|@GITHUB_CLIENT_ID@|$GITHUB_CLIENT_ID|g
s|@GITHUB_ORGANISATION@|$GITHUB_ORGANISATION|g
s|@GITHUB_INSTALLATION_ID@|$GITHUB_INSTALLATION_ID|g
SED_SCRIPT
kubectl apply -f .
kubectl rollout status statefulset/ci-orchestrator