Skip to content
Snippets Groups Projects
.gitlab-ci.yml 4.98 KiB
Newer Older
Nico Vermaas's avatar
Nico Vermaas committed
stages:
Mattia Mancini's avatar
Mattia Mancini committed
  - test
Nico Vermaas's avatar
Nico Vermaas committed
  - build
  - deploy_to_test
  - deploy_to_production

Mattia Mancini's avatar
Mattia Mancini committed
workflow:
  rules:
    - if: $CI_COMMIT_REF_NAME == $CI_DEFAULT_BRANCH
      variables:
        DOCKER_BUILD_IMAGE_TAG: ":stable"
Mattia Mancini's avatar
Mattia Mancini committed
        DOCKER_IMAGE_TAG: ":latest"
Mattia Mancini's avatar
Mattia Mancini committed
    - if: $CI_COMMIT_REF_NAME != $CI_DEFAULT_BRANCH
      variables:
        DOCKER_BUILD_IMAGE_TAG: ":latest"
Mattia Mancini's avatar
Mattia Mancini committed
        DOCKER_IMAGE_TAG: ":$CI_COMMIT_REF_NAME"
Mattia Mancini's avatar
Mattia Mancini committed

test-code:
  image: python:3.10
  stage: test
  services:
    - postgres:11.0
  variables:
    POSTGRES_DB: ldv-spec-db
    POSTGRES_USER: postgres
    POSTGRES_PASSWORD: "atdb123"
  script:
    - cd ldvspec
    - pip install -r requirements/dev.txt
    - python manage.py migrate --settings ldvspec.settings.ci
    - python manage.py test --settings ldvspec.settings.ci

docker-test-build:
  variables:
    if: main
  # Official docker image.
  image: docker$DOCKER_BUILD_IMAGE_TAG
  before_script:
    - docker login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" $CI_REGISTRY
Mattia Mancini's avatar
Mattia Mancini committed
  stage: build
  services:
    - docker:dind
  script:
Mattia Mancini's avatar
Mattia Mancini committed
    - docker build --pull -t "$CI_REGISTRY_IMAGE$DOCKER_IMAGE_TAG" ldvspec
Mattia Mancini's avatar
Mattia Mancini committed
    - docker push $CI_REGISTRY_IMAGE$DOCKER_IMAGE_TAG
Nico Vermaas's avatar
Nico Vermaas committed
docker-build-master:
  # Official docker image.
Mattia Mancini's avatar
Mattia Mancini committed
  image: docker$DOCKER_BUILD_IMAGE_TAG
Nico Vermaas's avatar
Nico Vermaas committed
  stage: build
  services:
    - docker:dind
  before_script:
    - docker login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" $CI_REGISTRY
  script:
    - docker build --pull -t "$CI_REGISTRY_IMAGE" ldvspec
    - docker push "$CI_REGISTRY_IMAGE"
  only:
    - main


# deploy test/dev version on 'sdc-dev.astron.nl'
docker-deploy-main-test:
Nico Vermaas's avatar
Nico Vermaas committed
  stage: deploy_to_test
Mattia Mancini's avatar
Mattia Mancini committed
  image: centos:7
Nico Vermaas's avatar
Nico Vermaas committed
  before_script:
Nico Vermaas's avatar
Nico Vermaas committed
    ##
    ## Install ssh-agent if not already installed, it is required by Docker.
    ## (change apt-get to yum if you use an RPM-based image)
    ##
Mattia Mancini's avatar
Mattia Mancini committed
    - 'command -v ssh-agent >/dev/null || ( yum install -y openssh-client rsync )'
Nico Vermaas's avatar
Nico Vermaas committed
    ##
    ## Run ssh-agent (inside the build environment)
    ##
Nico Vermaas's avatar
Nico Vermaas committed
    - eval $(ssh-agent -s)
Nico Vermaas's avatar
Nico Vermaas committed
    ##
    ## Add the SSH key stored in SSH_PRIVATE_KEY variable to the agent store
    ## We're using tr to fix line endings which makes ed25519 keys work
    ## without extra base64 encoding.
    ## https://gitlab.com/gitlab-examples/ssh-private-key/issues/1#note_48526556
    ##
    ##
    ## Create the SSH directory and give it the right permissions
    ##
Nico Vermaas's avatar
Nico Vermaas committed
    - echo "$SSH_PRIVATE_KEY_USER_SDC" | tr -d '\r' | ssh-add -
    - mkdir -p ~/.ssh
    - chmod 700 ~/.ssh
    - ssh-keyscan dop814.astron.nl >> ~/.ssh/known_hosts
    - ssh-keyscan sdc-dev.astron.nl >> ~/.ssh/known_hosts
    - chmod 644 ~/.ssh/known_hosts
  script:
    ## deploy the docker-compose file and use it to spin up the containers
    - scp -o StrictHostKeyChecking=no ldvspec/docker/docker-compose-dev-cd.yml sdc@dop814.astron.nl:/docker_compose/ldvspec/docker-compose-dev-cd.yml
    - ssh -o StrictHostKeyChecking=no sdc@dop814.astron.nl "echo $CI_REGISTRY_PASSWORD | docker login -u $CI_REGISTRY_USER --password-stdin $CI_REGISTRY"
    - ssh -o StrictHostKeyChecking=no sdc@dop814.astron.nl "docker pull "$CI_REGISTRY_IMAGE""
    - ssh -o StrictHostKeyChecking=no sdc@dop814.astron.nl "docker-compose -p ldvspec -f /docker_compose/ldvspec/docker-compose-dev-cd.yml up -d"
    - echo "Application deployed"
Nico Vermaas's avatar
Nico Vermaas committed
  when: manual
  only:
    - main

docker-deploy-main-production:
Mattia Mancini's avatar
Mattia Mancini committed
  #  image: docker:latest
Nico Vermaas's avatar
Nico Vermaas committed
  stage: deploy_to_production
Mattia Mancini's avatar
Mattia Mancini committed
  image: centos:7
Nico Vermaas's avatar
Nico Vermaas committed
  before_script:
    ##
    ## Install ssh-agent if not already installed, it is required by Docker.
    ## (change apt-get to yum if you use an RPM-based image)
    ##
Mattia Mancini's avatar
Mattia Mancini committed
    - 'command -v ssh-agent >/dev/null || ( yum install -y openssh-client rsync )'
    ##
    ## Run ssh-agent (inside the build environment)
    ##
Nico Vermaas's avatar
Nico Vermaas committed
    - eval $(ssh-agent -s)
    ##
    ## Add the SSH key stored in SSH_PRIVATE_KEY variable to the agent store
    ## We're using tr to fix line endings which makes ed25519 keys work
    ## without extra base64 encoding.
    ## https://gitlab.com/gitlab-examples/ssh-private-key/issues/1#note_48526556
    ##
    ##
    ## Create the SSH directory and give it the right permissions
    ##
    - echo "$SSH_PRIVATE_KEY_USER_SDC" | tr -d '\r' | ssh-add -
Nico Vermaas's avatar
Nico Vermaas committed
    - mkdir -p ~/.ssh
    - chmod 700 ~/.ssh
    - ssh-keyscan dop821.astron.nl >> ~/.ssh/known_hosts
    - ssh-keyscan sdc.astron.nl >> ~/.ssh/known_hosts
Nico Vermaas's avatar
Nico Vermaas committed
    - chmod 644 ~/.ssh/known_hosts
  script:
    ## deploy the docker-compose file and use it to spin up the containers
    - scp -o StrictHostKeyChecking=no ldvspec/docker/docker-compose-production-cd.yml sdco@dop821.astron.nl:/opt/dockercompose/ldvspec/docker-compose-production-cd.yml
Nico Vermaas's avatar
Nico Vermaas committed
    - ssh -o StrictHostKeyChecking=no sdco@dop821.astron.nl "echo $CI_REGISTRY_PASSWORD | docker login -u $CI_REGISTRY_USER --password-stdin $CI_REGISTRY"
    - ssh -o StrictHostKeyChecking=no sdco@dop821.astron.nl "docker pull "$CI_REGISTRY_IMAGE""
    - ssh -o StrictHostKeyChecking=no sdco@dop821.astron.nl "docker-compose -p ldvspec -f /opt/dockercompose/ldvspec/docker-compose-production-cd.yml up -d"
    - echo "Application deployed"
Nico Vermaas's avatar
Nico Vermaas committed
  when: manual
  only: