mirror of
https://github.com/Tria-plc/emaui.git
synced 2026-08-26 19:12:50 +00:00
3
.github/workflows/deploy.yml
vendored
3
.github/workflows/deploy.yml
vendored
@@ -33,6 +33,7 @@ jobs:
|
||||
BUILD_ENV_FILE: ${{ matrix.build_env_file }}
|
||||
DOCKER_BUILDKIT: "1"
|
||||
COMPOSE_DOCKER_CLI_BUILD: "1"
|
||||
ENV_MANAGER_TOKEN: ${{ secrets.ENV_MANAGER_TOKEN }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
@@ -40,7 +41,7 @@ jobs:
|
||||
- name: Sync environment from server
|
||||
run: |
|
||||
chmod +x scripts/deploy/*.sh
|
||||
./scripts/deploy/sync-env-from-server.sh "${{ matrix.service }}"
|
||||
./scripts/deploy/sync-env-from-env-manager.sh "${{ matrix.service }}"
|
||||
|
||||
- name: Set compose project name
|
||||
run: |
|
||||
|
||||
80
scripts/deploy/sync-env-from-env-manager.sh
Normal file
80
scripts/deploy/sync-env-from-env-manager.sh
Normal file
@@ -0,0 +1,80 @@
|
||||
#!/usr/bin/env bash
|
||||
# Sync .env files from the Env Manager API into the repo.
|
||||
#
|
||||
# Usage:
|
||||
# ENV_MANAGER_TOKEN=xxx ./scripts/deploy/sync-env-from-server.sh freight-api freight-portal freight-backoffice
|
||||
#
|
||||
# You normally only need to pass the token via the action secret, and BRANCH
|
||||
# via the job-level env (e.g. `BRANCH: ${{ github.ref_name }}` in the workflow):
|
||||
# env:
|
||||
# BRANCH: ${{ github.ref_name }}
|
||||
# ENV_MANAGER_TOKEN: ${{ secrets.ENV_MANAGER_TOKEN }}
|
||||
#
|
||||
# API layout (one endpoint per service):
|
||||
# GET https://env.smart.aaca.gov.et/api/env/edr/<branch>/<service>?format=dotenv
|
||||
# Header: Authorization: Bearer <ENV_MANAGER_TOKEN>
|
||||
set -euo pipefail
|
||||
|
||||
PROJECT="ema"
|
||||
ENV_MANAGER_URL="https://env.smart.aaca.gov.et"
|
||||
BRANCH="${BRANCH:?BRANCH is required}"
|
||||
ENV_MANAGER_TOKEN="${ENV_MANAGER_TOKEN:?ENV_MANAGER_TOKEN is required}"
|
||||
|
||||
declare -A SERVICE_ENV_TARGET=(
|
||||
["ema_portal"]="apps/portal/.env"
|
||||
["ema_backoffice"]="apps/backoffice/.env"
|
||||
)
|
||||
|
||||
for service in "$@"; do
|
||||
branch_api_name="${BRANCH//-/_}"
|
||||
service_api_name="${service//-/_}"
|
||||
dest="${SERVICE_ENV_TARGET[${service_api_name}]:-}"
|
||||
if [[ -z "${dest}" ]]; then
|
||||
echo "Unknown service: ${service}" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
url="${ENV_MANAGER_URL}/api/env/${PROJECT}/${branch_api_name}/${service_api_name}?format=dotenv"
|
||||
mkdir -p "$(dirname "${dest}")"
|
||||
|
||||
tmp_file="$(mktemp)"
|
||||
trap 'rm -f "${tmp_file}"' RETURN 2>/dev/null || true
|
||||
|
||||
http_status=$(curl -fsS -o "${tmp_file}" -w "%{http_code}" \
|
||||
-H "Authorization: Bearer ${ENV_MANAGER_TOKEN}" \
|
||||
"${url}") || {
|
||||
echo "Failed to fetch env for '${service}' from ${url}" >&2
|
||||
rm -f "${tmp_file}"
|
||||
exit 1
|
||||
}
|
||||
|
||||
if [[ "${http_status}" != "200" ]]; then
|
||||
echo "Env Manager returned HTTP ${http_status} for '${service}' (${url})" >&2
|
||||
rm -f "${tmp_file}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [[ ! -s "${tmp_file}" ]]; then
|
||||
echo "Env Manager returned an empty response for '${service}' (${url})" >&2
|
||||
rm -f "${tmp_file}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
mv "${tmp_file}" "${dest}"
|
||||
echo "Synced ${url} -> ${dest}"
|
||||
|
||||
port_value=$(sed -n -E 's/^[[:space:]]*PORT[[:space:]]*=[[:space:]]*"?([^"#]+)"?[[:space:]]*(#.*)?$/\1/p' "${dest}" | head -n1 | tr -d '[:space:]')
|
||||
if [[ -z "${port_value}" ]]; then
|
||||
echo "Missing required PORT in env file for '${service}' (${dest})" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [[ -n "${GITHUB_ENV:-}" ]]; then
|
||||
service_var=$(echo "${service}" | tr '[:lower:]-' '[:upper:]_')
|
||||
echo "${service_var}_PORT=${port_value}" >> "${GITHUB_ENV}"
|
||||
echo "Exported ${service_var}_PORT from ${dest}"
|
||||
# Forward NEXT_PUBLIC_* and VITE_* vars so docker compose build can inject them as build args.
|
||||
grep -E '^[[:space:]]*(NEXT_PUBLIC_|VITE_)[A-Za-z0-9_]+=' "${dest}" \
|
||||
| sed -E 's/^[[:space:]]*//' >> "${GITHUB_ENV}" || true
|
||||
fi
|
||||
done
|
||||
Reference in New Issue
Block a user