diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 7f147ee..d6ed462 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -78,19 +78,13 @@ jobs: uses: azure/setup-kubectl@v4 - name: Configure kubectl - run: | - kubectl config set-cluster buzz --server=https://100.75.220.33:6443 --insecure-skip-tls-verify=true - kubectl config set-credentials ci-deployer --token=${{ secrets.KUBE_TOKEN }} - kubectl config set-context buzz --cluster=buzz --user=ci-deployer --namespace=buzz - kubectl config use-context buzz - - - name: Migrate, then roll out the immutable revision env: KUBE_CONFIG_B64: ${{ secrets.KUBE_CONFIG_B64 }} - REVISION: ${{ gitea.sha }} - shell: bash run: | - set -Eeuo pipefail + if [ -z "$KUBE_CONFIG_B64" ]; then + echo "Missing KUBE_CONFIG_B64 secret for the CI deploy identity" >&2 + exit 1 + fi kube_dir="$RUNNER_TEMP/buzz-sheet-kube" mkdir -p "$kube_dir" @@ -99,6 +93,24 @@ jobs: printf '%s' "$KUBE_CONFIG_B64" | base64 --decode >"$KUBECONFIG" chmod 600 "$KUBECONFIG" + env_file="${GITEA_ENV_FILE:-${GITHUB_ENV:-}}" + if [ -n "$env_file" ]; then + printf '%s\n' "KUBECONFIG=$KUBECONFIG" >> "$env_file" + fi + + - name: Migrate, then roll out the immutable revision + env: + REVISION: ${{ gitea.sha }} + shell: bash + run: | + set -Eeuo pipefail + + export KUBECONFIG="${KUBECONFIG:-$RUNNER_TEMP/buzz-sheet-kube/config}" + if [ ! -s "$KUBECONFIG" ]; then + echo "Kubeconfig was not created from KUBE_CONFIG_B64" >&2 + exit 1 + fi + revision_short="${REVISION:0:12}" migration_dir="$RUNNER_TEMP/buzz-sheet-migration-$revision_short" migration_manifest="$RUNNER_TEMP/buzz-sheet-migration-$revision_short.yaml"