Files
coturn-server-config/.github/workflows/deploy-stack.yml
T
2026-04-01 20:06:38 -05:00

118 lines
3.7 KiB
YAML

name: 02 - Deploy Infrastructure and Stack
on:
workflow_dispatch:
jobs:
deploy:
runs-on: ubuntu-latest
permissions:
contents: read
env:
TF_VAR_gcp_project: ${{ secrets.GCP_PROJECT }}
TF_VAR_gcp_region: ${{ vars.GCP_REGION }}
TF_VAR_gcp_zone: ${{ vars.GCP_ZONE }}
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Prepare SSH key for provisioning
shell: bash
run: |
install -m 700 -d "${HOME}/.ssh"
printf '%s\n' "${{ secrets.SSH_PRIVATE_KEY }}" > "${HOME}/.ssh/id_ed25519"
chmod 600 "${HOME}/.ssh/id_ed25519"
{
echo "TF_VAR_admin_ssh_public_key<<EOF"
ssh-keygen -y -f "${HOME}/.ssh/id_ed25519"
echo "EOF"
} >> "${GITHUB_ENV}"
- name: Prepare Google credentials file
shell: bash
run: |
credentials_file="${RUNNER_TEMP}/gcp-service-account.json"
printf '%s' "${{ secrets.GCP_SA_KEY }}" > "${credentials_file}"
chmod 600 "${credentials_file}"
echo "GOOGLE_APPLICATION_CREDENTIALS=${credentials_file}" >> "${GITHUB_ENV}"
- name: Setup OpenTofu
uses: opentofu/setup-opentofu@v1
- name: Write OpenTofu backend config
working-directory: ./tofu
shell: bash
run: |
cat > backend.hcl <<EOF
key = "webrtc-relay/terraform.tfstate"
endpoints = {
s3 = ${{ secrets.R2_ENDPOINT_URL }}
}
access_key = "${{ secrets.R2_ACCESS_KEY_ID }}"
secret_key = "${{ secrets.R2_SECRET_ACCESS_KEY }}"
EOF
- name: Tofu init and apply
id: tofu
working-directory: ./tofu
shell: bash
run: |
tofu init -backend-config=backend.hcl
tofu apply -auto-approve -input=false
echo "${{ secrets.STATIC_IP }}=$(tofu output -raw relay_ip)" >> "${GITHUB_ENV}"
- name: Wait for SSH
shell: bash
run: |
for attempt in {1..30}; do
if nc -z -w 5 "${${{ secrets.STATIC_IP }}}" 22; then
exit 0
fi
sleep 10
done
echo "SSH did not become reachable on ${${{ secrets.STATIC_IP }}}" >&2
exit 1
- name: Run Ansible Playbook
uses: dawidd6/action-ansible-playbook@v2
with:
playbook: setup_host.yml
directory: ./ansible
key: ${{ secrets.SSH_PRIVATE_KEY }}
inventory: |
[turn_nodes]
${{ secrets.STATIC_IP }} ansible_user=ubuntu
options: --ssh-common-args='-o StrictHostKeyChecking=no'
- name: SCP compose and config files
uses: appleboy/scp-action@v0.1.7
with:
host: ${{ secrets.STATIC_IP }}
username: ubuntu
key: ${{ secrets.SSH_PRIVATE_KEY }}
source: "compose/*"
target: "/opt/stoat-turn"
strip_components: 1
- name: Deploy Podman compose stack
uses: appleboy/ssh-action@v1.0.3
with:
host: ${{ secrets.STATIC_IP }}
username: ubuntu
key: ${{ secrets.SSH_PRIVATE_KEY }}
script: |
set -eu
cd /opt/stoat-turn
cat > .env <<EOF
STATIC_IP = ${{ secrets.STATIC_IP }}
GITHUB_REPOSITORY_OWNER=${{ github.repository_owner }}
TURN_REALM=${{ secrets.TURN_REALM }}
TURN_SHARED_SECRET=${{ secrets.TURN_SHARED_SECRET }}
CADDY_EMAIL=${{ secrets.CADDY_EMAIL }}
EOF
printf '%s\n' "${{ secrets.GITHUB_TOKEN }}" | podman login ghcr.io -u "${{ github.actor }}" --password-stdin
podman compose pull
podman compose up -d