From 9dbf472906e2cec5f0731a02b3e738e64fa062f2 Mon Sep 17 00:00:00 2001 From: vchikalkin Date: Wed, 8 Oct 2025 17:46:37 +0300 Subject: [PATCH] Update Docker Compose and GitHub Actions for environment variable management and conditional builds - Added new environment files (.cache-proxy.env, .web.env, .bot.env) to Docker Compose for better separation of configuration. - Enhanced GitHub Actions workflow to include conditional builds and deployments based on changed paths, improving efficiency. - Introduced steps to create and copy environment files for project tags, ensuring only necessary files are transferred during deployment. --- .github/workflows/deploy.yml | 83 +++++++++++++++++++++++++++++++++--- docker-compose.yml | 3 ++ 2 files changed, 81 insertions(+), 5 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index bd05c65..2f1c84b 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -13,10 +13,29 @@ jobs: web_tag: ${{ steps.vars.outputs.web_tag }} bot_tag: ${{ steps.vars.outputs.bot_tag }} cache_proxy_tag: ${{ steps.vars.outputs.cache_proxy_tag }} + # Добавляем output-ы для отслеживания, какие проекты были собраны + web_built: ${{ steps.filter.outputs.web }} + bot_built: ${{ steps.filter.outputs.bot }} + cache_proxy_built: ${{ steps.filter.outputs.cache_proxy }} steps: - name: Checkout code uses: actions/checkout@v3 + # --- НОВОЕ: Шаг 1: dorny/paths-filter для условной сборки --- + - name: Filter changed paths + uses: dorny/paths-filter@v2 + id: filter + with: + filters: | + web: + - 'apps/web/**' + - 'packages/**' + bot: + - 'apps/bot/**' + - 'packages/**' + cache_proxy: + - 'apps/cache-proxy/**' + # ----------------------------------------------------------- - name: Create fake .env file for build run: | echo "BOT_TOKEN=fake" > .env @@ -42,29 +61,37 @@ jobs: - name: Login to Docker Hub run: echo "${{ secrets.DOCKERHUB_TOKEN }}" | docker login -u "${{ secrets.DOCKERHUB_USERNAME }}" --password-stdin + # --- ИЗМЕНЕНО: Условное выполнение Build/Push --- - name: Build web image + if: steps.filter.outputs.web == 'true' run: | docker build -t ${{ secrets.DOCKERHUB_USERNAME }}/zapishis-web:${{ steps.vars.outputs.web_tag }} -f ./apps/web/Dockerfile . - name: Push web image to Docker Hub + if: steps.filter.outputs.web == 'true' run: | docker push ${{ secrets.DOCKERHUB_USERNAME }}/zapishis-web:${{ steps.vars.outputs.web_tag }} - name: Build bot image + if: steps.filter.outputs.bot == 'true' run: | docker build -t ${{ secrets.DOCKERHUB_USERNAME }}/zapishis-bot:${{ steps.vars.outputs.bot_tag }} -f ./apps/bot/Dockerfile . - name: Push bot image to Docker Hub + if: steps.filter.outputs.bot == 'true' run: | docker push ${{ secrets.DOCKERHUB_USERNAME }}/zapishis-bot:${{ steps.vars.outputs.bot_tag }} - name: Build cache-proxy image + if: steps.filter.outputs.cache_proxy == 'true' run: | docker build -t ${{ secrets.DOCKERHUB_USERNAME }}/zapishis-cache-proxy:${{ steps.vars.outputs.cache_proxy_tag }} -f ./apps/cache-proxy/Dockerfile . - name: Push cache-proxy image to Docker Hub + if: steps.filter.outputs.cache_proxy == 'true' run: | docker push ${{ secrets.DOCKERHUB_USERNAME }}/zapishis-cache-proxy:${{ steps.vars.outputs.cache_proxy_tag }} + # ------------------------------------------------- deploy: name: Deploy to VPS @@ -86,8 +113,10 @@ jobs: run: | ssh -i ~/.ssh/id_rsa -p ${{ secrets.VPS_PORT }} -o StrictHostKeyChecking=no ${{ secrets.VPS_USER }}@${{ secrets.VPS_HOST }} "mkdir -p /home/${{ secrets.VPS_USER }}/zapishis" - - name: Create real .env file for production + # --- НОВОЕ: Шаг 2: Создание основного .env БЕЗ ТЕГОВ --- + - name: Create real .env file (No Tags) run: | + # Включаем все секреты, КРОМЕ тегов echo "BOT_TOKEN=${{ secrets.BOT_TOKEN }}" > .env echo "LOGIN_GRAPHQL=${{ secrets.LOGIN_GRAPHQL }}" >> .env echo "PASSWORD_GRAPHQL=${{ secrets.PASSWORD_GRAPHQL }}" >> .env @@ -95,9 +124,6 @@ jobs: echo "EMAIL_GRAPHQL=${{ secrets.EMAIL_GRAPHQL }}" >> .env echo "NEXTAUTH_SECRET=${{ secrets.NEXTAUTH_SECRET }}" >> .env echo "BOT_URL=${{ secrets.BOT_URL }}" >> .env - echo "WEB_IMAGE_TAG=${{ needs.build-and-push.outputs.web_tag }}" >> .env - echo "BOT_IMAGE_TAG=${{ needs.build-and-push.outputs.bot_tag }}" >> .env - echo "CACHE_PROXY_IMAGE_TAG=${{ needs.build-and-push.outputs.cache_proxy_tag }}" >> .env echo "DOCKERHUB_USERNAME=${{ secrets.DOCKERHUB_USERNAME }}" >> .env echo "REDIS_PASSWORD=${{ secrets.REDIS_PASSWORD }}" >> .env echo "BOT_PROVIDER_TOKEN=${{ secrets.BOT_PROVIDER_TOKEN }}" >> .env @@ -105,7 +131,18 @@ jobs: echo "OFFER_URL=${{ secrets.OFFER_URL }}" >> .env echo "PRIVACY_URL=${{ secrets.PRIVACY_URL }}" >> .env - - name: Copy .env to VPS via SCP + # --- НОВОЕ: Шаг 3: Создание файлов тегов (.project.env) --- + - name: Create Project Tag Env Files + run: | + # Создаем файлы, которые будут содержать только одну переменную с тегом + echo "WEB_IMAGE_TAG=${{ needs.build-and-push.outputs.web_tag }}" > .web.env + echo "BOT_IMAGE_TAG=${{ needs.build-and-push.outputs.bot_tag }}" > .bot.env + echo "CACHE_PROXY_IMAGE_TAG=${{ needs.build-and-push.outputs.cache_proxy_tag }}" > .cache-proxy.env + + # --- Шаг 4: Копирование .env и УСЛОВНОЕ копирование тегов --- + + # Копируем основной .env всегда + - name: Copy .env to VPS via SCP (Always) uses: appleboy/scp-action@master with: host: ${{ secrets.VPS_HOST }} @@ -115,6 +152,42 @@ jobs: source: '.env' target: '/home/${{ secrets.VPS_USER }}/zapishis/' + # Копируем .web.env ТОЛЬКО, если web был собран (обновляем тег на VPS) + - name: Copy .web.env to VPS + if: ${{ needs.build-and-push.outputs.web_built == 'true' }} + uses: appleboy/scp-action@master + with: + host: ${{ secrets.VPS_HOST }} + username: ${{ secrets.VPS_USER }} + key: ${{ secrets.VPS_SSH_KEY }} + port: ${{ secrets.VPS_PORT }} + source: '.web.env' + target: '/home/${{ secrets.VPS_USER }}/zapishis/' + + # Копируем .bot.env ТОЛЬКО, если bot был собран + - name: Copy .bot.env to VPS + if: ${{ needs.build-and-push.outputs.bot_built == 'true' }} + uses: appleboy/scp-action@master + with: + host: ${{ secrets.VPS_HOST }} + username: ${{ secrets.VPS_USER }} + key: ${{ secrets.VPS_SSH_KEY }} + port: ${{ secrets.VPS_PORT }} + source: '.bot.env' + target: '/home/${{ secrets.VPS_USER }}/zapishis/' + + # Копируем .cache-proxy.env ТОЛЬКО, если cache-proxy был собран + - name: Copy .cache-proxy.env to VPS + if: ${{ needs.build-and-push.outputs.cache_proxy_built == 'true' }} + uses: appleboy/scp-action@master + with: + host: ${{ secrets.VPS_HOST }} + username: ${{ secrets.VPS_USER }} + key: ${{ secrets.VPS_SSH_KEY }} + port: ${{ secrets.VPS_PORT }} + source: '.cache-proxy.env' + target: '/home/${{ secrets.VPS_USER }}/zapishis/' + - name: Copy docker-compose.yml to VPS via SCP uses: appleboy/scp-action@master with: diff --git a/docker-compose.yml b/docker-compose.yml index db4099f..f2819f5 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -3,6 +3,7 @@ services: image: ${DOCKERHUB_USERNAME}/zapishis-cache-proxy:${CACHE_PROXY_IMAGE_TAG} env_file: - .env + - .cache-proxy.env restart: always depends_on: - redis @@ -18,6 +19,7 @@ services: image: ${DOCKERHUB_USERNAME}/zapishis-web:${WEB_IMAGE_TAG} env_file: - .env + - .web.env restart: always # healthcheck: # test: ['CMD', 'curl', '-f', 'http://localhost:3000/api/health'] @@ -35,6 +37,7 @@ services: restart: always env_file: - .env + - .bot.env depends_on: - redis - cache-proxy