Deploy Kaapi staging to EC2 #108
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy Kaapi staging to EC2 | |
| on: | |
| workflow_run: | |
| workflows: ["Kaapi CI"] | |
| branches: [main] | |
| types: [completed] | |
| workflow_dispatch: | |
| concurrency: | |
| group: staging-ec2-deploy | |
| cancel-in-progress: false | |
| jobs: | |
| deploy: | |
| runs-on: ubuntu-latest | |
| environment: AWS_STAGING_ENV | |
| # workflow_dispatch runs unconditionally; workflow_run only on a green CI. | |
| if: >- | |
| ${{ github.event_name == 'workflow_dispatch' || | |
| github.event.workflow_run.conclusion == 'success' }} | |
| permissions: | |
| id-token: write | |
| contents: read | |
| steps: | |
| - name: Configure AWS credentials | |
| uses: aws-actions/configure-aws-credentials@v6 | |
| with: | |
| role-to-assume: ${{ secrets.STAGING_EC2_DEPLOY_ROLE_ARN }} | |
| aws-region: ap-south-1 | |
| - name: Trigger deploy on EC2 via SSM | |
| id: ssm | |
| env: | |
| INSTANCE_ID: ${{ secrets.STAGING_EC2_INSTANCE_ID }} | |
| SECRET_ID: ${{ vars.STAGING_SECRET_ID }} | |
| run: | | |
| CMD_ID=$(aws ssm send-command \ | |
| --instance-ids "$INSTANCE_ID" \ | |
| --document-name "AWS-RunShellScript" \ | |
| --comment "Deploy kaapi-backend kaapi-staging" \ | |
| --parameters commands='["set -eux","chown -R ubuntu:ubuntu /data/kaapi-backend","sudo -iu ubuntu bash -lc \"cd /data/kaapi-backend && git fetch --all && git pull origin main && SECRET_ID='"$SECRET_ID"' sh scripts/fetch-secrets.sh && docker compose -f docker-compose.staging.yml build && docker compose -f docker-compose.staging.yml --profile migrate run --rm migrate && docker compose -f docker-compose.staging.yml up -d --wait --remove-orphans && docker image prune -f\""]' \ | |
| --cloud-watch-output-config CloudWatchOutputEnabled=true \ | |
| --query "Command.CommandId" --output text) | |
| echo "cmd_id=$CMD_ID" >> "$GITHUB_OUTPUT" | |
| echo "Sent SSM command: $CMD_ID" | |
| - name: Wait for SSM command to finish | |
| timeout-minutes: 10 | |
| env: | |
| INSTANCE_ID: ${{ secrets.STAGING_EC2_INSTANCE_ID }} | |
| CMD_ID: ${{ steps.ssm.outputs.cmd_id }} | |
| run: | | |
| while true; do | |
| if aws ssm wait command-executed \ | |
| --command-id "$CMD_ID" \ | |
| --instance-id "$INSTANCE_ID"; then | |
| break # waiter succeeds only on Status == Success | |
| fi | |
| STATUS=$(aws ssm get-command-invocation \ | |
| --command-id "$CMD_ID" \ | |
| --instance-id "$INSTANCE_ID" \ | |
| --query "Status" --output text 2>/dev/null || echo "Pending") | |
| case "$STATUS" in | |
| Success) break ;; | |
| Failed|Cancelled|Cancelling|TimedOut) | |
| echo "Deployment ended with status: $STATUS" | |
| aws ssm get-command-invocation \ | |
| --command-id "$CMD_ID" \ | |
| --instance-id "$INSTANCE_ID" \ | |
| --query '{Status:Status,Stdout:StandardOutputContent,Stderr:StandardErrorContent}' \ | |
| --output json | |
| exit 1 ;; | |
| *) echo "Still running (status: $STATUS) — waiter capped out, re-waiting" ;; | |
| esac | |
| done | |
| echo "Deployment completed successfully." | |
| aws ssm get-command-invocation \ | |
| --command-id "$CMD_ID" \ | |
| --instance-id "$INSTANCE_ID" \ | |
| --query '{Status:Status,Stdout:StandardOutputContent,Stderr:StandardErrorContent}' \ | |
| --output json |