seed: devroadmap-demo — self-hosted CI loop
Some checks failed
build-and-deploy / build-deploy (push) Failing after 49s
Some checks failed
build-and-deploy / build-deploy (push) Failing after 49s
This commit is contained in:
commit
04461a10e5
7 changed files with 213 additions and 0 deletions
56
.forgejo/workflows/ci.yml
Normal file
56
.forgejo/workflows/ci.yml
Normal file
|
|
@ -0,0 +1,56 @@
|
||||||
|
name: build-and-deploy
|
||||||
|
|
||||||
|
# Build the image, push to Harbor, bump the deploy tag, push back → ArgoCD deploys.
|
||||||
|
# paths-ignore avoids an infinite loop: the tag-bump commit only touches deploy/.
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
paths-ignore:
|
||||||
|
- "deploy/**"
|
||||||
|
- "**.md"
|
||||||
|
|
||||||
|
env:
|
||||||
|
IMAGE: harbor.devroadmap.ru/homelab/devroadmap-demo
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build-deploy:
|
||||||
|
runs-on: k8s-arm64 # act_runner label → docker:27-cli, DinD at localhost:2375
|
||||||
|
env:
|
||||||
|
DOCKER_HOST: tcp://localhost:2375
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
|
||||||
|
- name: Short SHA
|
||||||
|
id: sha
|
||||||
|
run: echo "value=${GITHUB_SHA::7}" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
- name: Login to Harbor
|
||||||
|
run: |
|
||||||
|
echo "${{ secrets.HARBOR_ROBOT_PASSWORD }}" \
|
||||||
|
| docker login harbor.devroadmap.ru -u "${{ secrets.HARBOR_ROBOT_USER }}" --password-stdin
|
||||||
|
|
||||||
|
- name: Build and push (native arm64)
|
||||||
|
run: |
|
||||||
|
docker build \
|
||||||
|
--build-arg GIT_SHA="${{ steps.sha.outputs.value }}" \
|
||||||
|
--build-arg BUILD_DATE="$(date -u +%Y-%m-%dT%H:%M:%SZ)" \
|
||||||
|
-t "$IMAGE:${{ steps.sha.outputs.value }}" \
|
||||||
|
-t "$IMAGE:latest" .
|
||||||
|
docker push "$IMAGE:${{ steps.sha.outputs.value }}"
|
||||||
|
docker push "$IMAGE:latest"
|
||||||
|
|
||||||
|
- name: Bump deploy tag (GitOps) and push back
|
||||||
|
run: |
|
||||||
|
sed -i "s#newTag:.*#newTag: \"${{ steps.sha.outputs.value }}\"#" deploy/kustomization.yaml
|
||||||
|
git config user.name "forgejo-ci"
|
||||||
|
git config user.email "ci@git.devroadmap.ru"
|
||||||
|
git add deploy/kustomization.yaml
|
||||||
|
git commit -m "ci: deploy ${{ steps.sha.outputs.value }} [skip ci]" || { echo "no change"; exit 0; }
|
||||||
|
git push "http://ci:${{ secrets.FORGEJO_TOKEN }}@forgejo.forgejo.svc/${{ github.repository }}.git" HEAD:main
|
||||||
|
|
||||||
|
- name: Summary
|
||||||
|
run: |
|
||||||
|
echo "Built $IMAGE:${{ steps.sha.outputs.value }} → Harbor; deploy/ bumped → ArgoCD will sync." >> "$GITHUB_STEP_SUMMARY"
|
||||||
17
Dockerfile
Normal file
17
Dockerfile
Normal file
|
|
@ -0,0 +1,17 @@
|
||||||
|
# Trimmed devroadmap demo — a static landing served by nginx. Deliberately light
|
||||||
|
# so the arm64 in-cluster build is fast/reliable (the demo is the CI/CD LOOP, not
|
||||||
|
# a heavy build). Swap in the full Astro SSR build (node:22-alpine + pnpm, RU npm
|
||||||
|
# mirror registry.npmmirror.com) later — the pipeline stays identical.
|
||||||
|
FROM docker.io/library/nginx:1.27-alpine
|
||||||
|
|
||||||
|
ARG GIT_SHA=dev
|
||||||
|
ARG BUILD_DATE=unknown
|
||||||
|
|
||||||
|
COPY site/ /usr/share/nginx/html/
|
||||||
|
|
||||||
|
# "build" step: stamp the commit + date into the page so every deploy is visibly
|
||||||
|
# different — proves the loop end-to-end from the browser.
|
||||||
|
RUN sed -i "s/__GIT_SHA__/${GIT_SHA}/g; s/__BUILD_DATE__/${BUILD_DATE}/g" \
|
||||||
|
/usr/share/nginx/html/index.html
|
||||||
|
|
||||||
|
EXPOSE 80
|
||||||
27
README.md
Normal file
27
README.md
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
# devroadmap-demo — self-hosted CI/CD loop demo
|
||||||
|
|
||||||
|
Seed for the Forgejo repo `devroadmap-demo`. It demonstrates a **fully
|
||||||
|
self-hosted** build→deploy loop with no GitHub in the path:
|
||||||
|
|
||||||
|
```
|
||||||
|
push to Forgejo → Forgejo Actions (act_runner + DinD) build arm64 image
|
||||||
|
→ push to Harbor (harbor.devroadmap.ru) → bump deploy/ image tag → push back
|
||||||
|
→ ArgoCD (watching this repo) syncs → live in k3s (ns devroadmap-demo, VIP .233)
|
||||||
|
```
|
||||||
|
|
||||||
|
This is a **trimmed** derivative of the `developer-roadmap` project: a static
|
||||||
|
landing served by nginx, kept light so the in-cluster arm64 build is fast and
|
||||||
|
reliable. The point is the pipeline, not the build weight — swap in the full
|
||||||
|
Astro SSR build (Node 22 + pnpm, RU npm mirror) later by replacing the Dockerfile.
|
||||||
|
|
||||||
|
## Layout
|
||||||
|
- `Dockerfile` — nginx:alpine; stamps the commit SHA + build date into the page.
|
||||||
|
- `site/` — the static site.
|
||||||
|
- `.forgejo/workflows/ci.yml` — the loop (build → Harbor → tag bump → push).
|
||||||
|
- `deploy/` — the k8s manifests ArgoCD renders (`kustomization` + `deployment` + `service`).
|
||||||
|
|
||||||
|
## Bootstrap
|
||||||
|
This repo is created and pushed during the Forgejo bring-up — see
|
||||||
|
`homelab-gitops/docs/forgejo.md` for the full runbook (repo secrets
|
||||||
|
`HARBOR_ROBOT_USER`/`HARBOR_ROBOT_PASSWORD`/`FORGEJO_TOKEN`, the runner, and the
|
||||||
|
ArgoCD Application that watches this repo).
|
||||||
34
deploy/deployment.yaml
Normal file
34
deploy/deployment.yaml
Normal file
|
|
@ -0,0 +1,34 @@
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: devroadmap-demo
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
kubernetes.io/arch: arm64 # image built native arm64 on the runner
|
||||||
|
containers:
|
||||||
|
- name: web
|
||||||
|
image: harbor.devroadmap.ru/homelab/devroadmap-demo:bootstrap
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: 80
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: 3
|
||||||
|
periodSeconds: 10
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 20
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 16Mi
|
||||||
|
limits:
|
||||||
|
memory: 64Mi
|
||||||
21
deploy/kustomization.yaml
Normal file
21
deploy/kustomization.yaml
Normal file
|
|
@ -0,0 +1,21 @@
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
# Rendered by ArgoCD from THIS Forgejo repo (path: deploy). The CI pipeline bumps
|
||||||
|
# newTag on every push, then Argo syncs the new image into k3s.
|
||||||
|
|
||||||
|
namespace: devroadmap-demo
|
||||||
|
|
||||||
|
labels:
|
||||||
|
- includeSelectors: true
|
||||||
|
pairs:
|
||||||
|
app.kubernetes.io/name: devroadmap-demo
|
||||||
|
app.kubernetes.io/instance: devroadmap-demo
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- deployment.yaml
|
||||||
|
- service.yaml
|
||||||
|
|
||||||
|
images:
|
||||||
|
- name: harbor.devroadmap.ru/homelab/devroadmap-demo
|
||||||
|
newTag: "bootstrap" # bumped to the short SHA by .forgejo/workflows/ci.yml
|
||||||
14
deploy/service.yaml
Normal file
14
deploy/service.yaml
Normal file
|
|
@ -0,0 +1,14 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: devroadmap-demo
|
||||||
|
annotations:
|
||||||
|
# LAN VIP (allocation table: docs/k3s-app-standard.md). .235-.237 are argo
|
||||||
|
# metrics LBs — do not reuse.
|
||||||
|
metallb.io/loadBalancerIPs: 192.168.2.233
|
||||||
|
spec:
|
||||||
|
type: LoadBalancer
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: 80
|
||||||
|
targetPort: http
|
||||||
44
site/index.html
Normal file
44
site/index.html
Normal file
|
|
@ -0,0 +1,44 @@
|
||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||||
|
<title>devroadmap-demo · self-hosted CI/CD</title>
|
||||||
|
<style>
|
||||||
|
:root { color-scheme: dark; }
|
||||||
|
body {
|
||||||
|
margin: 0; min-height: 100vh; display: grid; place-items: center;
|
||||||
|
font: 16px/1.5 system-ui, sans-serif; color: #e6e6e6;
|
||||||
|
background: radial-gradient(circle at 30% 20%, #1b2a4a, #0b0f1a);
|
||||||
|
}
|
||||||
|
.card {
|
||||||
|
max-width: 640px; padding: 2.5rem 3rem; border-radius: 16px;
|
||||||
|
background: rgba(255, 255, 255, 0.04); border: 1px solid rgba(255, 255, 255, 0.08);
|
||||||
|
box-shadow: 0 20px 60px rgba(0, 0, 0, 0.4);
|
||||||
|
}
|
||||||
|
h1 { margin: 0 0 .25rem; font-size: 1.8rem; }
|
||||||
|
.sub { color: #8fb0ff; margin: 0 0 1.5rem; }
|
||||||
|
.flow { font-size: .95rem; color: #b9c2d0; }
|
||||||
|
.flow b { color: #fff; }
|
||||||
|
dl { display: grid; grid-template-columns: auto 1fr; gap: .35rem 1rem; margin: 1.5rem 0 0; }
|
||||||
|
dt { color: #7a8699; }
|
||||||
|
dd { margin: 0; font-family: ui-monospace, monospace; color: #9effc9; }
|
||||||
|
code { color: #ffd479; }
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<main class="card">
|
||||||
|
<h1>devroadmap-demo</h1>
|
||||||
|
<p class="sub">fully self-hosted build → deploy loop</p>
|
||||||
|
<p class="flow">
|
||||||
|
push to <b>Forgejo</b> → <b>Forgejo Actions</b> (act_runner + DinD) build
|
||||||
|
arm64 → push <b>Harbor</b> → bump tag → <b>ArgoCD</b> deploys to <b>k3s</b>.
|
||||||
|
No GitHub in the path.
|
||||||
|
</p>
|
||||||
|
<dl>
|
||||||
|
<dt>commit</dt><dd>__GIT_SHA__</dd>
|
||||||
|
<dt>built</dt><dd>__BUILD_DATE__</dd>
|
||||||
|
</dl>
|
||||||
|
</main>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
Loading…
Add table
Add a link
Reference in a new issue