118 lines
3.7 KiB
YAML
118 lines
3.7 KiB
YAML
name: 02 - Deploy Infrastructure and Stack
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
env:
|
|
TF_VAR_gcp_project: ${{ secrets.GCP_PROJECT }}
|
|
TF_VAR_gcp_region: ${{ vars.GCP_REGION }}
|
|
TF_VAR_gcp_zone: ${{ vars.GCP_ZONE }}
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Prepare SSH key for provisioning
|
|
shell: bash
|
|
run: |
|
|
install -m 700 -d "${HOME}/.ssh"
|
|
printf '%s\n' "${{ secrets.SSH_PRIVATE_KEY }}" > "${HOME}/.ssh/id_ed25519"
|
|
chmod 600 "${HOME}/.ssh/id_ed25519"
|
|
{
|
|
echo "TF_VAR_admin_ssh_public_key<<EOF"
|
|
ssh-keygen -y -f "${HOME}/.ssh/id_ed25519"
|
|
echo "EOF"
|
|
} >> "${GITHUB_ENV}"
|
|
|
|
- name: Prepare Google credentials file
|
|
shell: bash
|
|
run: |
|
|
credentials_file="${RUNNER_TEMP}/gcp-service-account.json"
|
|
printf '%s' "${{ secrets.GCP_SA_KEY }}" > "${credentials_file}"
|
|
chmod 600 "${credentials_file}"
|
|
echo "GOOGLE_APPLICATION_CREDENTIALS=${credentials_file}" >> "${GITHUB_ENV}"
|
|
|
|
- name: Setup OpenTofu
|
|
uses: opentofu/setup-opentofu@v1
|
|
|
|
- name: Write OpenTofu backend config
|
|
working-directory: ./tofu
|
|
shell: bash
|
|
run: |
|
|
cat > backend.hcl <<EOF
|
|
key = "webrtc-relay/terraform.tfstate"
|
|
endpoints = {
|
|
s3 = ${{ secrets.R2_ENDPOINT_URL }}
|
|
}
|
|
access_key = "${{ secrets.R2_ACCESS_KEY_ID }}"
|
|
secret_key = "${{ secrets.R2_SECRET_ACCESS_KEY }}"
|
|
EOF
|
|
|
|
- name: Tofu init and apply
|
|
id: tofu
|
|
working-directory: ./tofu
|
|
shell: bash
|
|
run: |
|
|
tofu init -backend-config=backend.hcl
|
|
tofu apply -auto-approve -input=false
|
|
echo "${{ secrets.STATIC_IP }}=$(tofu output -raw relay_ip)" >> "${GITHUB_ENV}"
|
|
|
|
- name: Wait for SSH
|
|
shell: bash
|
|
run: |
|
|
for attempt in {1..30}; do
|
|
if nc -z -w 5 "${${{ secrets.STATIC_IP }}}" 22; then
|
|
exit 0
|
|
fi
|
|
sleep 10
|
|
done
|
|
echo "SSH did not become reachable on ${${{ secrets.STATIC_IP }}}" >&2
|
|
exit 1
|
|
|
|
- name: Run Ansible Playbook
|
|
uses: dawidd6/action-ansible-playbook@v2
|
|
with:
|
|
playbook: setup_host.yml
|
|
directory: ./ansible
|
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
|
inventory: |
|
|
[turn_nodes]
|
|
${{ secrets.STATIC_IP }} ansible_user=ubuntu
|
|
options: --ssh-common-args='-o StrictHostKeyChecking=no'
|
|
|
|
- name: SCP compose and config files
|
|
uses: appleboy/scp-action@v0.1.7
|
|
with:
|
|
host: ${{ secrets.STATIC_IP }}
|
|
username: ubuntu
|
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
|
source: "compose/*"
|
|
target: "/opt/stoat-turn"
|
|
strip_components: 1
|
|
|
|
- name: Deploy Podman compose stack
|
|
uses: appleboy/ssh-action@v1.0.3
|
|
with:
|
|
host: ${{ secrets.STATIC_IP }}
|
|
username: ubuntu
|
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
|
script: |
|
|
set -eu
|
|
cd /opt/stoat-turn
|
|
cat > .env <<EOF
|
|
STATIC_IP = ${{ secrets.STATIC_IP }}
|
|
GITHUB_REPOSITORY_OWNER=${{ github.repository_owner }}
|
|
TURN_REALM=${{ secrets.TURN_REALM }}
|
|
TURN_SHARED_SECRET=${{ secrets.TURN_SHARED_SECRET }}
|
|
CADDY_EMAIL=${{ secrets.CADDY_EMAIL }}
|
|
EOF
|
|
|
|
printf '%s\n' "${{ secrets.GITHUB_TOKEN }}" | podman login ghcr.io -u "${{ github.actor }}" --password-stdin
|
|
podman compose pull
|
|
podman compose up -d
|