-
Notifications
You must be signed in to change notification settings - Fork 18
70 lines (64 loc) · 2.56 KB
/
devnet_deploy_chain.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
name: Deploy Devnet chain
on: workflow_dispatch
jobs:
chain-build-deploy:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
context: app
ref: arsen/build-devnet
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v1
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: us-east-1
- name: Login to Amazon ECR
id: login-ecr
uses: aws-actions/amazon-ecr-login@v1
with:
mask-password: 'true'
- name: Chain build, tag, and push image to Amazon ECR
id: build-image
env:
ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }}
ECR_REPOSITORY_CHAIN: ${{ secrets.ECR_REPOSITORY_CHAIN }}
CLOUDFLARE_TOKEN_HTTP: ${{ secrets.CLOUDFLARE_TOKEN_HTTP }}
CLOUDFLARE_TOKEN_WS: ${{ secrets.CLOUDFLARE_TOKEN_WS }}
ADMIN_ADDRESS: ${{ secrets.ADMIN_ADDRESS }}
run: |
docker build \
-t $ECR_REPOSITORY_CHAIN \
-f ./docker/chain/Dockerfile \
--build-arg="admin_address=${ADMIN_ADDRESS}" \
--build-arg="expose_via=cloudflare" \
--build-arg="cloudflare_token_http=${CLOUDFLARE_TOKEN_HTTP}"\
--build-arg="cloudflare_token_ws=${CLOUDFLARE_TOKEN_WS}"\
.
docker tag $ECR_REPOSITORY_CHAIN:latest $ECR_REGISTRY/$ECR_REPOSITORY_CHAIN:latest
docker push $ECR_REGISTRY/$ECR_REPOSITORY_CHAIN:latest
- name: Chain deploy to EC2 instance
uses: appleboy/ssh-action@master
env:
ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }}
ECR_REPOSITORY_CHAIN: ${{ secrets.ECR_REPOSITORY_CHAIN }}
with:
host: ${{ secrets.EC2_HOST_CHAIN }}
username: ${{ secrets.EC2_USERNAME_CHAIN }}
key: ${{ secrets.EC2_PRIVATE_KEY_CHAIN }}
envs: ECR_REGISTRY, ECR_REPOSITORY_CHAIN
script_stop: true
script: |
docker stop chain || true
docker rm chain || true
aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin $ECR_REGISTRY
docker system prune -af
docker pull $ECR_REGISTRY/$ECR_REPOSITORY_CHAIN:latest
docker run \
-d \
--privileged \
--restart always \
--name chain \
$ECR_REGISTRY/$ECR_REPOSITORY_CHAIN:latest