-
Notifications
You must be signed in to change notification settings - Fork 41
57 lines (47 loc) · 1.68 KB
/
deploy-prod.yml
File metadata and controls
57 lines (47 loc) · 1.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
name: Deploy application with Ansible
# Controls when the action will run.
on:
# Triggers the workflow on tagged commits
push:
tags:
- '[0-9]+.[0-9]+.[0-9]+'
# A workflow run is made up of one or more jobs that can run sequentially or in parallel
jobs:
# This workflow contains a single job called "build"
build:
# The type of runner that the job will run on
runs-on: ubuntu-latest
# Steps represent a sequence of tasks that will be executed as part of the job
steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
- uses: actions/checkout@v2
- name: Install Ansible
run: |
sudo apt update -y
sudo apt install software-properties-common -y
sudo apt-add-repository --yes --update ppa:ansible/ansible
sudo apt install ansible -y
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v2
with:
version: latest
args: release --rm-dist
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Set Execute command to bash script
run: chmod +x ./.github/scripts/decrypt.sh
# Runs a single command using the runners shell
- name: Decrypt large secret
run: ./.github/scripts/decrypt.sh
env:
LARGE_SECRET_PASSPHRASE: ${{ secrets.LARGE_SECRET_PASSPHRASE }}
- name: Escalate Private Key Permissions
run: chmod 400 ~/.sshkey
- name: Run ansible command
run: |
cd ./scripts/ansible
ansible-playbook -i ./inventory main.yml
env:
ANSIBLE_CONFIG: ./ansible.cfg
- name: Clean Key
run: rm -rf ~/.privkey