name: CI on: push: branches: ['**'] tags: ['v*'] pull_request: branches: ['**'] jobs: typecheck: name: TypeScript — type-check runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: '20' cache: 'npm' - name: Install run: npm ci - name: Type-check (tsc) run: npx tsc --noEmit publish: name: Publish — build & push image runs-on: ubuntu-latest needs: [typecheck] if: github.ref == 'refs/heads/main' && github.event_name == 'push' steps: - uses: actions/checkout@v4 - name: Login to registry run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.netork.io -u "${{ secrets.REGISTRY_USER }}" --password-stdin - name: Build & push run: | SHA=$(git rev-parse --short HEAD) docker build \ -t registry.netork.io/netork/website:latest \ -t registry.netork.io/netork/website:main-${SHA} \ . docker push registry.netork.io/netork/website:latest docker push registry.netork.io/netork/website:main-${SHA} - name: Logout if: always() run: docker logout registry.netork.io deploy: name: Deploy — pull & restart on host runs-on: build needs: [publish] steps: - uses: actions/checkout@v4 - name: Login to registry run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.netork.io -u "${{ secrets.REGISTRY_USER }}" --password-stdin - name: Deploy run: | mkdir -p /opt/netork-website cp docker-compose.yml /opt/netork-website/docker-compose.yml cd /opt/netork-website docker compose pull docker compose up -d --remove-orphans - name: Logout if: always() run: docker logout registry.netork.io