Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
80 changes: 51 additions & 29 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,60 +3,82 @@ updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"
target-branch: "develop"
interval: "weekly"
open-pull-requests-limit: 5
commit-message:
prefix: "(deps:github-actions)"
labels:
- "dependencies"
- "automated pr"
assignees:
- "ukwhatn"
reviewers:
- "ukwhatn"
# github-actions/dockerはsemver別cooldown非対応のためdefault-daysのみ
cooldown:
default-days: 3
groups:
github-actions-all:
applies-to: version-updates
patterns:
- "*"
github-actions-security:
applies-to: security-updates
patterns:
- "*"

- package-ecosystem: "pip"
# discord/・db/のpyproject/poetry.lockはrootへのsymlinkのため"/"のみで全依存をカバー
directory: "/"
schedule:
interval: "daily"
target-branch: "develop"
interval: "weekly"
versioning-strategy: increase-if-necessary
open-pull-requests-limit: 10
commit-message:
prefix: "(deps:pip)"
labels:
- "dependencies"
- "automated pr"
assignees:
- "ukwhatn"
reviewers:
- "ukwhatn"
cooldown:
default-days: 3
semver-patch-days: 1
groups:
pip-all:
applies-to: version-updates
patterns:
- "*"
pip-security:
applies-to: security-updates
patterns:
- "*"

- package-ecosystem: "docker"
directory: "/db"
directories:
- "/db"
- "/discord"
schedule:
interval: "daily"
target-branch: "develop"
interval: "weekly"
open-pull-requests-limit: 5
# pyprojectのpython = "3.12.*" 制約と揃えるため、patch更新のみ許可
ignore:
- dependency-name: "python"
update-types: ["version-update:semver-major", "version-update:semver-minor"]
commit-message:
prefix: "(deps:dockerfile-db)"
prefix: "(deps:docker)"
labels:
- "dependencies"
- "automated pr"
assignees:
- "ukwhatn"
reviewers:
- "ukwhatn"

- package-ecosystem: "docker"
directory: "/discord"
schedule:
interval: "daily"
target-branch: "develop"
commit-message:
prefix: "(deps:dockerfile-bot)"
labels:
- "dependencies"
- "automated pr"
assignees:
- "ukwhatn"
reviewers:
- "ukwhatn"
# github-actions/dockerはsemver別cooldown非対応のためdefault-daysのみ
cooldown:
default-days: 3
groups:
docker-all:
applies-to: version-updates
patterns:
- "*"
docker-security:
applies-to: security-updates
patterns:
- "*"
78 changes: 38 additions & 40 deletions .github/workflows/check_healthy.yml
Original file line number Diff line number Diff line change
@@ -1,63 +1,61 @@
name: Check services healthy

# NOTE: pull_request_target は base ブランチのコードを checkout するため
# PR の変更が検証されない(かつ head checkout に変えると secrets 窃取の危険がある)。
# PR のコードを検証する CI として pull_request を使う。
on:
pull_request_target:
pull_request:
branches:
- main
- develop

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: true

permissions:
contents: read

jobs:
check_healthy:
runs-on: ubuntu-latest
timeout-minutes: 20

steps:
- uses: actions/checkout@v7
with:
persist-credentials: false

- name: Setup environment
run: |
make envs:setup
sed -i 's/DISCORD_BOT_TOKEN=""/DISCORD_BOT_TOKEN="${{ secrets.CIBOT_TOKEN }}"/' envs/discord.env

- name: Build and start services
run: make up
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Build images (GHA layer cache)
uses: docker/bake-action@v7
with:
files: compose.dev.yml
load: true
# GHA cacheのscopeはデフォルトで全ターゲット共通になり上書きし合うため、
# ターゲットごとに分離する
set: |
discord.cache-from=type=gha,scope=discord
discord.cache-to=type=gha,scope=discord,mode=max
db-migrator.cache-from=type=gha,scope=db-migrator
db-migrator.cache-to=type=gha,scope=db-migrator,mode=max

- name: Start services and wait until healthy
run: make up:ci

- name: Wait for services to be ready and check health
- name: Show service status and logs
if: always()
run: |
max_retries=5
retry_interval=5

for i in $(seq 1 $max_retries)
do
service_status=$(make ps)
if echo "$service_status" | grep -qiE "(starting|restarting|unhealthy)"; then
echo "Services are still initializing or unhealthy... (Attempt $i/$max_retries)"
echo "$service_status"

if [ $i -eq $max_retries ]; then
echo "Services did not stabilize within the allocated time."
make logs:once
exit 1
fi

sleep $retry_interval
else
echo "All services have stabilized!"
break
fi
done

# Final health check
service_status=$(make ps)
if echo "$service_status" | grep -qiE "(unhealthy|exited|dead)"; then
echo "Some services are in an unhealthy state:"
echo "$service_status"
make logs:once
exit 1
else
echo "All services are healthy!"
echo "$service_status"
make logs:once
fi
make ps
make logs:once

- name: Clean up
run: make down
if: always()
run: make down
14 changes: 12 additions & 2 deletions .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,15 @@
#file: noinspection YAMLSchemaValidation
name: Deploy
on:
push:
branches: [ main ]
release:
types: [ published ]
concurrency:
group: deploy
cancel-in-progress: false
jobs:
build:
# pre-releaseではデプロイしない(deployはneedsで連動してskipされる)
if: ${{ !github.event.release.prerelease }}
runs-on: ubuntu-latest
permissions:
contents: read
Expand All @@ -28,6 +30,11 @@ jobs:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Sanitize release tag for image tag
id: meta
env:
RELEASE_TAG: ${{ github.event.release.tag_name }}
run: echo "release_tag=$(printf '%s' "$RELEASE_TAG" | tr -c 'a-zA-Z0-9_.-' '-')" >> "$GITHUB_OUTPUT"
- name: Build and push
uses: docker/build-push-action@v6
with:
Expand All @@ -37,6 +44,7 @@ jobs:
tags: |
ghcr.io/act-kithub/kithubsys/${{ matrix.service }}:latest
ghcr.io/act-kithub/kithubsys/${{ matrix.service }}:${{ github.sha }}
ghcr.io/act-kithub/kithubsys/${{ matrix.service }}:${{ steps.meta.outputs.release_tag }}
cache-from: type=gha,scope=${{ matrix.service }}
cache-to: type=gha,mode=max,scope=${{ matrix.service }}

Expand All @@ -63,6 +71,8 @@ jobs:
git diff --quiet
git diff --cached --quiet
git fetch origin
# mainに含まれないcommitのreleaseはデプロイしない
git merge-base --is-ancestor ${{ github.sha }} origin/main
git checkout -B main ${{ github.sha }}
export IMAGE_TAG=${{ github.sha }}
make deploy:prod ENV=prod
5 changes: 4 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,9 @@ build\:no-cache:
up:
docker compose -f $(COMPOSE_YML) up --build -d

up\:ci:
docker compose -f $(COMPOSE_YML) up -d --wait --wait-timeout 180

down:
docker compose -f $(COMPOSE_YML) down

Expand Down Expand Up @@ -84,4 +87,4 @@ envs\:setup:
cp envs/db.env.example envs/db.env
cp envs/sentry.env.example envs/sentry.env

PHONY: build up down logs ps pull pr\:create deploy\:prod poetry\:install poetry\:add poetry\:lock poetry\:update poetry\:reset dev\:setup db\:revision\:create db\:migrate envs\:init
.PHONY: build up up\:ci down logs ps pull pr\:create deploy\:prod poetry\:install poetry\:add poetry\:lock poetry\:update poetry\:reset dev\:setup db\:revision\:create db\:migrate envs\:init
2 changes: 2 additions & 0 deletions compose.dev.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
services:
discord:
image: kithubsys-discord:dev
build:
context: .
dockerfile: discord/Dockerfile
Expand Down Expand Up @@ -63,6 +64,7 @@ services:
- db

db-migrator:
image: kithubsys-db-migrator:dev
build:
context: .
dockerfile: ./db/Dockerfile
Expand Down
2 changes: 1 addition & 1 deletion db/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM python:3.15.0b4-slim
FROM python:3.12.13-slim

# set workdir
WORKDIR /app
Expand Down
2 changes: 1 addition & 1 deletion discord/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM python:3.15.0b4-slim
FROM python:3.12.13-slim

WORKDIR /app

Expand Down
Loading