b29abf75f82be9e40f59c91c455e8040ed006739

Author
Ayman Bagabas <ayman.bagabas@gmail.com>
Committer
Ayman Bagabas <ayman.bagabas@gmail.com>
Date

Message

Auto-deploy smoothie

- Use GoReleaser
- Add Dockerfile based on Alpine:latest
- Publish docker images to our private ghcr.io registry
- Run build and test using GH Actions (ci.yml)
- Deploy AWS ECS Docker instance to our AWS infrastructure using GH
  Actions (cd.yml)

  Note: repository secrets are used to make the auto-deploy work. All
  the secrets used are in our Gopass repository. `GITHUB_TOKEN` is a
  reserved GH Actions secret with basic permissions like pushing to
  organization registries.

Diff

This diff is truncated to protect this page.

  1diff --git a/.github/workflows/cd.yml b/.github/workflows/cd.yml
  2new file mode 100644
  3index 0000000000000000000000000000000000000000..b40ccfd0337673a6cca423b5def1faefd7184869
  4--- /dev/null
  5+++ b/.github/workflows/cd.yml
  6@@ -0,0 +1,156 @@
  7+name: CD
  8+
  9+on:
 10+  push:
 11+    branches:
 12+      - main
 13+  pull_request:
 14+    
 15+
 16+jobs:
 17+  cd:
 18+    strategy:
 19+      matrix:
 20+        go-version: [~1.16]
 21+    runs-on: ubuntu-latest
 22+    env:
 23+      GO111MODULE: "on"
 24+      CONTAINER_REPO: "ghcr.io/${{ github.repository }}"
 25+      ENVIRONMENT: development
 26+      AWS_DEFAULT_REGION: us-east-1
 27+      AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
 28+      AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
 29+
 30+    steps:
 31+    - name: Install Go
 32+      uses: actions/setup-go@v1
 33+      with:
 34+        go-version: ${{ matrix.go-version }}
 35+
 36+    - name: Checkout code
 37+      uses: actions/checkout@v2
 38+      with:
 39+        fetch-depth: 0
 40+
 41+    # Remove this later
 42+    - name: Clone internal repositories
 43+      run: |
 44+        git clone -b release https://${{ secrets.ACCESS_TOKEN }}@github.com/charmbracelet/charm-internal ../charm
 45+        git clone -b master https://${{ secrets.ACCESS_TOKEN }}@github.com/charmbracelet/bubbletea-internal ../bubbletea
 46+
 47+    - name: Login to GitHub Container Registry
 48+      uses: docker/login-action@v1
 49+      if: github.event_name == 'push'
 50+      with:
 51+        registry: ghcr.io
 52+        username: ${{ github.repository_owner }}
 53+        password: ${{ secrets.GITHUB_TOKEN }}
 54+
 55+    - name: Build Docker images using GoReleaser
 56+      uses: goreleaser/goreleaser-action@master
 57+      if: github.event_name == 'push'
 58+      with:
 59+        version: latest
 60+        # https://github.com/goreleaser/goreleaser/discussions/1534
 61+        args: -f .goreleaser.yml --snapshot
 62+
 63+    - name: Push Docker images
 64+      if: github.event_name == 'push'
 65+      run: |
 66+        docker push $CONTAINER_REPO:snapshot
 67+        docker push $CONTAINER_REPO:$GITHUB_SHA-snapshot
 68+
 69+    - name: Setup Terraform
 70+      uses: hashicorp/setup-terraform@v1
 71+      with:
 72+        # terraform_version: 0.13.0
 73+        cli_config_credentials_token: ${{ secrets.TF_API_TOKEN }}
 74+
 75+    - name: Terraform Variables
 76+      id: tfvars
 77+      run: |
 78+        TF_VARS=$(cat <<EOF
 79+          -var "environment=$ENVIRONMENT" \
 80+          -var "aws_region=$AWS_DEFAULT_REGION" \
 81+          -var "app_image=$CONTAINER_REPO:$GITHUB_SHA-snapshot"
 82+        EOF
 83+        )
 84+        echo "::set-output name=vars::$TF_VARS"
 85+
 86+    - name: Terraform Format
 87+      id: fmt
 88+      run: terraform fmt -check
 89+
 90+    - name: Terraform Init
 91+      id: init
 92+      run: terraform init
 93+
 94+    - name: Terraform Validate
 95+      id: validate
 96+      run: terraform validate -no-color
 97+
 98+    - name: Terraform Plan
 99+      id: plan
100+      if: github.event_name == 'pull_request'
101+      run: terraform plan -no-color ${{ steps.tfvars.outputs.vars }}
102+      continue-on-error: true
103+
104+    - name: Find Comment
105+      if: github.event_name == 'pull_request'
106diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
107new file mode 100644
108index 0000000000000000000000000000000000000000..9470cf6f8746fc3c1ff963f52706daaef0329831
109--- /dev/null
110+++ b/.github/workflows/ci.yml
111@@ -0,0 +1,33 @@
112+name: CI
113+
114+on:
115+  push:
116+    branches: [ main ]
117+  pull_request:
118+
119+jobs:
120+
121+  build:
122+    strategy:
123+      matrix:
124+        go-version: [~1.16]
125+    runs-on: ubuntu-latest
126+    steps:
127+    - uses: actions/checkout@v2
128+
129+    # Remove this later
130+    - name: Clone internal repositories
131+      run: |
132+        git clone -b release https://${{ secrets.ACCESS_TOKEN }}@github.com/charmbracelet/charm-internal ../charm
133+        git clone -b master https://${{ secrets.ACCESS_TOKEN }}@github.com/charmbracelet/bubbletea-internal ../bubbletea
134+
135+    - name: Set up Go
136+      uses: actions/setup-go@v2
137+      with:
138+        go-version: ${{ matrix.go-version }}
139+
140+    - name: Build
141+      run: go build -v ./...
142+
143+    - name: Test
144+      run: go test -v ./...
145diff --git a/.gitignore b/.gitignore
146index 53f079059244c9f29b15d896e6f955b61e7eea91..2ee7702b44ff48e73da1faf8a92fb5041644f837 100644
147--- a/.gitignore
148+++ b/.gitignore
149@@ -1,3 +1,7 @@
150 smoothie
151 .ssh
152 .repos
153+dist
154+.terraform*
155+*.tfstate*
156+*auto.tfvars
157diff --git a/.goreleaser.yml b/.goreleaser.yml
158new file mode 100644
159index 0000000000000000000000000000000000000000..89e2409bfcb266a056e27a9702f7788354d166d0
160--- /dev/null
161+++ b/.goreleaser.yml
162@@ -0,0 +1,37 @@
163+project_name: smoothie
164+
165+env:
166+  - GO111MODULE=on
167+  - CGO_ENABLED=0
168+
169+before:
170+  hooks:
171+    - go mod download
172+
173+builds:
174+  - id: "smoothie"
175+    binary: "smoothie"
176+    ldflags: -s -w -X main.Version={{ .Commit }}-snapshot -X main.CommitSHA={{ .Commit }}
177+    goos:
178+      - linux
179+    goarch:
180+      - amd64
181+
182+dockers:
183+  - image_templates:
184+      - "ghcr.io/charmbracelet/smoothie:snapshot"
185+      - "ghcr.io/charmbracelet/smoothie:{{ .Commit }}-snapshot"
186+    ids: [smoothie]
187+    goarch: amd64
188+    build_flag_templates:
189+      - --platform=linux/amd64
190+      - --label=org.opencontainers.image.title={{ .ProjectName }}
191+      - --label=org.opencontainers.image.description={{ .ProjectName }}
192+      - --label=org.opencontainers.image.url=https://github.com/charmbracelet/smoothie
193+      - --label=org.opencontainers.image.source=https://github.com/charmbracelet/smoothie
194+      - --label=org.opencontainers.image.version={{ .Commit }}-snapshot
195+      - --label=org.opencontainers.image.created={{ .Date }}
196+      - --label=org.opencontainers.image.revision={{ .FullCommit }}
197+      - --label=org.opencontainers.image.licenses=MIT
198+    dockerfile: Dockerfile
199+    use: buildx
200diff --git a/Dockerfile b/Dockerfile
201new file mode 100644
202index 0000000000000000000000000000000000000000..de9075197226fecb0d272217e36e2667315efc2c
203--- /dev/null
204+++ b/Dockerfile
205@@ -0,0 +1,22 @@
206+FROM alpine:latest
207+
208+RUN apk update && apk add --update nfs-utils git && rm -rf /var/cache/apk/*
209+
210+COPY smoothie /usr/local/bin/smoothie
211+
212+# Create directories
213+WORKDIR /smoothie
214+# Expose data volume
215+VOLUME /smoothie
216+
217+# Environment variables
218+ENV SMOOTHIE_KEY_PATH "/smoothie/ssh/smoothie_server_ed25519"
219+ENV SMOOTHIE_REPO_KEYS_PATH "/smoothie/ssh/smoothie_git_authorized_keys"
220+ENV SMOOTHIE_REPO_PATH "/smoothie/repos"
221+
222+# Expose ports
223+# SSH
224+EXPOSE 23231/tcp
225+
226+# Set the default command
227+ENTRYPOINT [ "/usr/local/bin/smoothie" ]
228diff --git a/main.tf b/main.tf
229new file mode 100644
230index 0000000000000000000000000000000000000000..a6cc616a73a28b7b30d6b8c801c9543d7e2e60f8
231--- /dev/null
232+++ b/main.tf
233@@ -0,0 +1,39 @@
234+terraform {
235+  backend "s3" {
236+    bucket = "charm-terraform-state"
237+    key    = "smoothie-development"
238+    region = "us-east-1"
239+  }
240+}
241+
242+variable "environment" {
243+  default = "development"
244+}
245+
246+variable "aws_region" {
247+  default = "us-east-1"
248+}
249+
250+variable "app_image" {
251+  default = "ghcr.io/charmbracelet/smoothie:snapshot"
252+}
253+
254+variable "force_new_deployment" {
255+  default = false
256+}
257+
258+module "smoothie" {
259+  # source = "../terraform-aws-smoothie"
260+  source  = "app.terraform.io/charm/smoothie/aws"
261+  version = "0.1.2"
262+
263+  environment                  = var.environment
264+  aws_region                   = var.aws_region
265+  ecs_task_execution_role_name = "smoothieEcsTaskExecutionRole-${var.environment}"
266+  app_image                    = var.app_image
267+  app_count                    = 2
268+  app_ssh_port                 = 23231
269+  fargate_cpu                  = "1024"
270+  fargate_memory               = "2048"
271+  force_new_deployment         = var.force_new_deployment
272+}