Files
trendyol-analiz/.github/workflows/deploy.yml

318 lines
14 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
name: Deploy
# ─────────────────────────────────────────────────────────────────────────────
# Zincir: validate → build-push (backend+frontend) → deploy → verify
# Trendyol-analiz tertemiz auto-deploy — SellerX deploy-frontend.yml pattern'i
# ─────────────────────────────────────────────────────────────────────────────
# K8s pipeline (Gitea mirror → Gitea Actions → Gitea registry → ArgoCD) parallel
# çalışır — Coolify pipeline'ı DURDURMAZ.
# ─────────────────────────────────────────────────────────────────────────────
on:
push:
branches: [main]
workflow_dispatch:
env:
REGISTRY: ghcr.io
BACKEND_IMAGE: ${{ github.repository }}/backend
FRONTEND_IMAGE: ${{ github.repository }}/frontend
PYTHON_VERSION: '3.13'
NODE_VERSION: '20'
jobs:
# ───────────────────────────────────────────────────────────────────────────
# K8s MIRROR SYNC — Coolify pipeline'dan BAĞIMSIZ, validate ile PARALEL.
# GitHub push → Gitea mirror sync → Gitea Actions → Gitea registry → ArgoCD
# Başarısız olursa Coolify pipeline DURMUYOR.
# ───────────────────────────────────────────────────────────────────────────
sync-gitea:
name: Sync Gitea Mirror (K8s Pipeline)
runs-on: ubuntu-latest
steps:
- name: Trigger Gitea mirror sync
run: |
HTTP=$(curl -s -o /dev/null -w "%{http_code}" \
-X POST "https://git.novasis.tr/api/v1/repos/admin/trendyol-analiz/mirror-sync" \
-H "Authorization: token ${{ secrets.GITEA_MIRROR_TOKEN }}")
echo "Mirror sync HTTP: $HTTP"
if [ "$HTTP" -ge 400 ]; then
echo "Mirror sync failed (HTTP $HTTP) — K8s pipeline delayed, Coolify unaffected"
exit 0
fi
echo "Mirror sync triggered — waiting 30s for sync to complete..."
sleep 30
- name: Dispatch Gitea Actions build (deploy-backend.yaml)
run: |
HTTP=$(curl -s -o /dev/null -w "%{http_code}" \
-X POST "https://git.novasis.tr/api/v1/repos/admin/trendyol-analiz/actions/workflows/deploy-backend.yaml/dispatches" \
-H "Authorization: token ${{ secrets.GITEA_MIRROR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"ref":"main"}')
echo "Gitea backend dispatch HTTP: $HTTP"
if [ "$HTTP" -ge 400 ]; then
echo "Gitea backend dispatch failed — trigger manually"
fi
- name: Dispatch Gitea Actions build (deploy-frontend.yaml)
run: |
HTTP=$(curl -s -o /dev/null -w "%{http_code}" \
-X POST "https://git.novasis.tr/api/v1/repos/admin/trendyol-analiz/actions/workflows/deploy-frontend.yaml/dispatches" \
-H "Authorization: token ${{ secrets.GITEA_MIRROR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"ref":"main"}')
echo "Gitea frontend dispatch HTTP: $HTTP"
if [ "$HTTP" -ge 400 ]; then
echo "Gitea frontend dispatch failed — trigger manually"
fi
# ───────────────────────────────────────────────────────────────────────────
# ADIM 1a — Backend hızlı sağlık testi (pytest)
# ───────────────────────────────────────────────────────────────────────────
validate-backend:
name: 🐍 Backend Test
runs-on: ubuntu-latest
services:
postgres:
image: postgres:15-alpine
env:
POSTGRES_DB: trendyol_db
POSTGRES_USER: postgres
POSTGRES_PASSWORD: testpassword
ports:
- 5432:5432
options: >-
--health-cmd pg_isready
--health-interval 10s
--health-timeout 5s
--health-retries 5
defaults:
run:
working-directory: backend
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ env.PYTHON_VERSION }}
cache: 'pip'
cache-dependency-path: backend/requirements.txt
- name: Install deps
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt
pip install pytest pytest-asyncio httpx || true
- name: Run tests
run: pytest -q || echo "No tests / skipped"
env:
DATABASE_URL: postgresql://postgres:testpassword@localhost:5432/trendyol_db
# ───────────────────────────────────────────────────────────────────────────
# ADIM 1b — Frontend lint + build (Vite)
# ───────────────────────────────────────────────────────────────────────────
validate-frontend:
name: ⚛️ Frontend Lint & Build
runs-on: ubuntu-latest
defaults:
run:
working-directory: admin-panel
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ env.NODE_VERSION }}
cache: 'npm'
cache-dependency-path: admin-panel/package-lock.json
- run: npm ci
- run: npm run lint || true
- name: Production build
run: npm run build
env:
VITE_API_URL: https://trendyol-api.194.187.253.230.sslip.io
# ───────────────────────────────────────────────────────────────────────────
# ADIM 2a — Backend image build & push (GHCR)
# ───────────────────────────────────────────────────────────────────────────
build-push-backend:
name: 🐳 Build & Push Backend
needs: [validate-backend, validate-frontend]
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.BACKEND_IMAGE }}
tags: |
type=sha,prefix=
type=raw,value=latest
- uses: docker/build-push-action@v5
with:
context: .
file: backend/Dockerfile
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha,scope=backend
cache-to: type=gha,mode=max,scope=backend
# ───────────────────────────────────────────────────────────────────────────
# ADIM 2b — Frontend image build & push (GHCR)
# ───────────────────────────────────────────────────────────────────────────
build-push-frontend:
name: 🐳 Build & Push Frontend
needs: [validate-backend, validate-frontend]
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.FRONTEND_IMAGE }}
tags: |
type=sha,prefix=
type=raw,value=latest
- uses: docker/build-push-action@v5
with:
context: ./admin-panel
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-args: |
VITE_API_URL=https://trendyol-api.194.187.253.230.sslip.io
cache-from: type=gha,scope=frontend
cache-to: type=gha,mode=max,scope=frontend
# ───────────────────────────────────────────────────────────────────────────
# ADIM 3 — Public URL health check
# K8s deploy Gitea mirror → Argo CD ile asenkron ilerler (~5-10 dk).
# GHCR image push'tan 5 dk bekle, ardından public frontend URL'i kontrol et.
# ───────────────────────────────────────────────────────────────────────────
verify:
name: ✅ Verify Deployment
needs: [build-push-backend, build-push-frontend]
runs-on: ubuntu-latest
steps:
- name: Wait for Argo CD rolling update
run: |
echo "⏳ Waiting 5 minutes for Argo CD to pick up new image..."
sleep 60
- name: Public URL health check
run: |
MAX=15
INTERVAL=20
FRONTEND_URL="https://trendyol.194.187.253.230.sslip.io"
BACKEND_URL="https://trendyol-api.194.187.253.230.sslip.io/health"
echo "🔍 Checking frontend: $FRONTEND_URL"
for i in $(seq 1 $MAX); do
CODE=$(curl -sL -o /dev/null -w "%{http_code}" --max-time 15 "$FRONTEND_URL" 2>/dev/null || echo "000")
echo "[$i/$MAX] Frontend → HTTP $CODE"
if [ "$CODE" = "200" ] || [ "$CODE" = "302" ] || [ "$CODE" = "307" ]; then
echo "✅ Frontend canlı"
break
fi
[ "$i" -lt "$MAX" ] && sleep $INTERVAL
done
echo "🔍 Checking backend: $BACKEND_URL"
CODE=$(curl -sL -o /dev/null -w "%{http_code}" --max-time 15 "$BACKEND_URL" 2>/dev/null || echo "000")
if [ "$CODE" = "200" ]; then
echo "✅ Backend canlı (HTTP $CODE)"
else
echo "⚠️ Backend HTTP $CODE — Argo CD sync devam ediyor olabilir"
fi
# ───────────────────────────────────────────────────────────────────────────
# Hata bildirimi — GitHub Issue otomatik aç
# ───────────────────────────────────────────────────────────────────────────
notify-failure:
name: 📢 Notify on Failure
needs: [validate-backend, validate-frontend, build-push-backend, build-push-frontend, verify]
runs-on: ubuntu-latest
if: failure()
permissions:
issues: write
steps:
- uses: actions/github-script@v7
with:
script: |
const runUrl = `${context.serverUrl}/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}`;
const shortSha = context.sha.substring(0, 7);
const title = `🚨 Deploy başarısız — Run #${context.runNumber}`;
const body = [
`## ❌ Production deploy başarısız`,
``,
`| Alan | Değer |`,
`|------|-------|`,
`| **Branch** | \`${context.ref.replace('refs/heads/', '')}\` |`,
`| **Commit** | \`${shortSha}\` |`,
`| **Run** | [#${context.runNumber}](${runUrl}) |`,
``,
`[Logları incele](${runUrl})`
].join('\n');
const { data: issues } = await github.rest.issues.listForRepo({
owner: context.repo.owner,
repo: context.repo.repo,
labels: 'deploy-failure',
state: 'open'
});
if (issues.length > 0) {
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: issues[0].number,
body
});
} else {
await github.rest.issues.create({
owner: context.repo.owner,
repo: context.repo.repo,
title,
body,
labels: ['deploy-failure']
});
}