name: Build & Push CFTunnels run-name: CF Build started by ${{ gitea.actor }} on: push: branches: - test # → PATCH bump, build & tag as test - main # → MINOR bump, promote test→prod workflow_dispatch: jobs: version: runs-on: ubuntu-latest outputs: new_version: ${{ steps.semver.outputs.new_version }} target_env: ${{ steps.env.outputs.target_env }} steps: - uses: actions/checkout@v4 with: fetch-depth: 0 - name: Determine environment id: env run: | [[ "${{ github.ref_name }}" == "main" ]] && ENV="prod" || ENV="${{ github.ref_name }}" if [[ "$ENV" != "test" && "$ENV" != "prod" ]]; then echo "→ Invalid environment: $ENV. Must be 'test' or 'prod'." exit 1 fi echo "target_env=$ENV" >> $GITHUB_OUTPUT - name: Calculate semver bump id: semver run: | VERSION=$(git describe --tags --match "cf-*" --abbrev=0 2>/dev/null || echo "cf-0.0.0") echo "Latest tag: ${VERSION}" # Strip cf- prefix VERSION=${VERSION#cf-} MAJOR=$(echo ${VERSION} | cut -d "." -f 1) MINOR=$(echo ${VERSION} | cut -d "." -f 2) PATCH=$(echo ${VERSION} | cut -d "." -f 3) if [[ "${{ steps.env.outputs.target_env }}" == "prod" ]]; then # MINOR bump, reset PATCH NEW_MINOR=$((MINOR + 1)) NEW_VERSION="${MAJOR}.${NEW_MINOR}.0" echo "Production → minor bump: ${NEW_VERSION}" else # test → PATCH bump NEW_PATCH=$((PATCH + 1)) NEW_VERSION="${MAJOR}.${MINOR}.${NEW_PATCH}" echo "Test → patch bump: ${NEW_VERSION}" fi echo "new_version=cf-${NEW_VERSION}" >> $GITHUB_OUTPUT build-and-push: runs-on: ubuntu-latest needs: version container: image: 192.168.0.100:8928/hithomelabs/ci-runner:1.0.0 steps: - uses: actions/checkout@v4 with: fetch-depth: 0 - name: Install JDK (Alpine package) run: | apk add --no-cache openjdk17-jdk echo "JAVA_HOME=/usr/lib/jvm/java-17-openjdk" >> "$GITHUB_ENV" - name: Validate Gradle Wrapper (offline checksum) run: | sha256sum --check gradle/wrapper/gradle-wrapper.jar.sha256 - name: Create and push git tag run: | echo "New version: ${{ needs.version.outputs.new_version }}" git config --global user.name "${{ gitea.actor }}" git config --global user.email "${{ gitea.actor }}@users.noreply.github.com" git tag -a "${{ needs.version.outputs.new_version }}" \ -m "Push CF version ${{ needs.version.outputs.new_version }}" git push origin "${{ needs.version.outputs.new_version }}" - name: Log in to Gitea Docker Registry uses: docker/login-action@v3 with: registry: 'http://192.168.0.100:8928' username: hitanshu password: ${{ secrets.TOKEN }} - name: Build image (test) or promote (prod) run: | ENV="${{ needs.version.outputs.target_env }}" VER="${{ needs.version.outputs.new_version }}" REG="192.168.0.100:8928/hithomelabs/cftunnels" if [[ "$ENV" == "test" ]]; then echo "→ Building fresh image for test" ./gradlew :cftunnels-service:bootBuildImage --imageName="${REG}:${VER}" docker tag "${REG}:${VER}" "${REG}:test" docker push "${REG}:test" docker push "${REG}:${VER}" else echo "→ Promoting test image to prod" docker pull "${REG}:test" docker tag "${REG}:test" "${REG}:${VER}" docker tag "${REG}:${VER}" "${REG}:prod" docker push "${REG}:prod" docker push "${REG}:${VER}" fi - name: Set Portainer deploy variables id: portainer-vars run: | ENV="${{ needs.version.outputs.target_env }}" if [[ "$ENV" == "prod" ]]; then echo "url=http://192.168.0.100:8082" >> $GITHUB_OUTPUT echo "stack=${{ vars.CFTUNNELS_PROD_STACK_ID }}" >> $GITHUB_OUTPUT echo "key=${{ secrets.PORTAINER_SERVICE_API_KEY_PROD }}" >> $GITHUB_OUTPUT else echo "url=http://192.168.0.100:8081" >> $GITHUB_OUTPUT echo "stack=${{ vars.CFTUNNELS_DEV_STACK_ID }}" >> $GITHUB_OUTPUT echo "key=${{ secrets.PORTAINER_SERVICE_API_KEY }}" >> $GITHUB_OUTPUT fi - name: Trigger Portainer Redeploy if: success() env: PORTAINER_AUTOMATION_URL: ${{ steps.portainer-vars.outputs.url }} STACK_ID: ${{ steps.portainer-vars.outputs.stack }} API_KEY: ${{ steps.portainer-vars.outputs.key }} run: | wget -q --no-check-certificate --timeout=30 \ --post-data= \ --header="X-API-Key: $API_KEY" \ -O - \ "$PORTAINER_AUTOMATION_URL/api/deploy/$STACK_ID" 2>&1 \ || echo "Deploy trigger failed (non-fatal)"