ci: switch registry host
This commit is contained in:
+13
-13
@@ -36,11 +36,11 @@ jobs:
|
||||
- run: |
|
||||
TAG=${{ gitea.sha }}
|
||||
docker build \
|
||||
-t mts.dgnr.us:5000/${{ gitea.repository }}:frontend \
|
||||
-t mts.dgnr.us:5000/${{ gitea.repository }}:frontend-$TAG \
|
||||
-t registry.neko-piranha.ts.net/${{ gitea.repository }}:frontend \
|
||||
-t registry.neko-piranha.ts.net/${{ gitea.repository }}:frontend-$TAG \
|
||||
.
|
||||
docker build --target migration \
|
||||
-t mts.dgnr.us:5000/${{ gitea.repository }}:migration \
|
||||
-t registry.neko-piranha.ts.net/${{ gitea.repository }}:migration \
|
||||
.
|
||||
|
||||
build-backend:
|
||||
@@ -72,8 +72,8 @@ jobs:
|
||||
TAG=${{ gitea.sha }}
|
||||
docker build \
|
||||
-f backend.dockerfile \
|
||||
-t mts.dgnr.us:5000/${{ gitea.repository }}:backend \
|
||||
-t mts.dgnr.us:5000/${{ gitea.repository }}:backend-$TAG \
|
||||
-t registry.neko-piranha.ts.net/${{ gitea.repository }}:backend \
|
||||
-t registry.neko-piranha.ts.net/${{ gitea.repository }}:backend-$TAG \
|
||||
.
|
||||
|
||||
push:
|
||||
@@ -82,11 +82,11 @@ jobs:
|
||||
steps:
|
||||
- run: |
|
||||
TAG=${{ gitea.sha }}
|
||||
docker push mts.dgnr.us:5000/${{ gitea.repository }}:backend &
|
||||
docker push mts.dgnr.us:5000/${{ gitea.repository }}:backend-$TAG &
|
||||
docker push mts.dgnr.us:5000/${{ gitea.repository }}:frontend &
|
||||
docker push mts.dgnr.us:5000/${{ gitea.repository }}:frontend-$TAG &
|
||||
docker push mts.dgnr.us:5000/${{ gitea.repository }}:migration &
|
||||
docker push registry.neko-piranha.ts.net/${{ gitea.repository }}:backend &
|
||||
docker push registry.neko-piranha.ts.net/${{ gitea.repository }}:backend-$TAG &
|
||||
docker push registry.neko-piranha.ts.net/${{ gitea.repository }}:frontend &
|
||||
docker push registry.neko-piranha.ts.net/${{ gitea.repository }}:frontend-$TAG &
|
||||
docker push registry.neko-piranha.ts.net/${{ gitea.repository }}:migration &
|
||||
wait
|
||||
|
||||
- name: Install kubectl
|
||||
@@ -110,7 +110,7 @@ jobs:
|
||||
# DB migration
|
||||
kubectl delete job db-migrate -n buzz --ignore-not-found
|
||||
kubectl create job db-migrate \
|
||||
--image=mts.dgnr.us:5000/${{ gitea.repository }}:migration \
|
||||
--image=registry.neko-piranha.ts.net/${{ gitea.repository }}:migration \
|
||||
-n buzz \
|
||||
--dry-run=client -o json \
|
||||
-- bun dr push | \
|
||||
@@ -118,8 +118,8 @@ jobs:
|
||||
kubectl apply -f -
|
||||
|
||||
# Roll app & backend
|
||||
kubectl set image deployment/app app=mts.dgnr.us:5000/${{ gitea.repository }}:frontend-$TAG -n buzz
|
||||
kubectl set image deployment/backend backend=mts.dgnr.us:5000/${{ gitea.repository }}:backend-$TAG -n buzz
|
||||
kubectl set image deployment/app app=registry.neko-piranha.ts.net/${{ gitea.repository }}:frontend-$TAG -n buzz
|
||||
kubectl set image deployment/backend backend=registry.neko-piranha.ts.net/${{ gitea.repository }}:backend-$TAG -n buzz
|
||||
kubectl rollout status deployment/app -n buzz --timeout=180s &
|
||||
kubectl rollout status deployment/backend -n buzz --timeout=180s &
|
||||
kubectl wait --for=condition=complete job/db-migrate -n buzz --timeout=600s &
|
||||
|
||||
@@ -100,7 +100,7 @@ graph TB
|
||||
subgraph Infra["Infrastructure — Docker Swarm"]
|
||||
Nginx["Nginx Reverse Proxy<br/>(SSE: buffering off, 200s timeout)"]:::infra
|
||||
GiteaCI["Gitea Actions CI/CD"]:::infra
|
||||
Registry["Private Registry<br/>mts.dgnr.us:5000"]:::infra
|
||||
Registry["Private Registry<br/>registry.neko-piranha.ts.net"]:::infra
|
||||
AppService["App Service<br/>2 replicas · 1 CPU / 1 GB"]:::infra
|
||||
BackendService["Backend Service<br/>1 replica · 1 CPU / 512 MB"]:::infra
|
||||
end
|
||||
@@ -397,7 +397,7 @@ Push to `main` or `dev` triggers `.github/workflows/build.yml`:
|
||||
|
||||
1. Build frontend Docker image (multi-stage: deps → drizzle push → builder → runner)
|
||||
2. Build backend Docker image (compiled to Bun bytecode via `bun build --target bun --bytecode`)
|
||||
3. Push both images to private registry at `mts.dgnr.us:5000`
|
||||
3. Push both images to private registry at `registry.neko-piranha.ts.net`
|
||||
4. Rolling update of Docker Swarm services (`buzz_app`, `buzz_backend`)
|
||||
|
||||
### Production stack (Docker Swarm)
|
||||
@@ -412,7 +412,7 @@ Infrastructure dependencies:
|
||||
- PostgreSQL database (managed externally)
|
||||
- Redis instance for SSE pub/sub and caching
|
||||
- Nginx reverse proxy with SSE optimizations (buffering off, 200s read timeout)
|
||||
- Private Docker registry at `mts.dgnr.us:5000`
|
||||
- Private Docker registry at `registry.neko-piranha.ts.net`
|
||||
|
||||
### Environment
|
||||
|
||||
|
||||
+2
-2
@@ -2,7 +2,7 @@ version: "3.9"
|
||||
|
||||
services:
|
||||
app:
|
||||
image: mts.dgnr.us:5000/astral/buzz:frontend
|
||||
image: registry.neko-piranha.ts.net/astral/buzz:frontend
|
||||
deploy:
|
||||
replicas: 2
|
||||
resources:
|
||||
@@ -26,7 +26,7 @@ services:
|
||||
- buzz
|
||||
|
||||
backend:
|
||||
image: mts.dgnr.us:5000/astral/buzz:backend
|
||||
image: registry.neko-piranha.ts.net/astral/buzz:backend
|
||||
environment:
|
||||
NO_AUTH_CHECK: "true"
|
||||
deploy:
|
||||
|
||||
+5
-6
@@ -55,7 +55,7 @@
|
||||
- **ServiceAccount `ci-deployer`** in namespace `buzz`.
|
||||
- RBAC Role grants: Deployments (get/list/watch/update/patch), Pods (get/list/watch), Jobs (full CRUD), Services/Ingresses/Middlewares (get/list/watch/create/update/patch).
|
||||
- Token for the runner: `kubectl create token ci-deployer -n buzz` (or use a long-lived token from a Secret tied to the SA).
|
||||
- The runner also needs `docker` login access to `mts.dgnr.us:5000` (same as today).
|
||||
- The runner also needs `docker` login access to `registry.neko-piranha.ts.net` (same as today).
|
||||
|
||||
### Replicated Stateful Services (external to buzz namespace)
|
||||
|
||||
@@ -65,8 +65,7 @@
|
||||
### Container Registry
|
||||
|
||||
- **Zot** running in-cluster (namespace `registry`), exposed via ServiceLB on host port 5000.
|
||||
- All k3s nodes have `/etc/rancher/k3s/registries.yaml` mirroring `mts.dgnr.us:5000` → `http://localhost:5000` (svclb binds host port 5000). k3s must be restarted after writing this file.
|
||||
- CI runner pushes to `mts.dgnr.us:5000` (Tailscale → `100.75.220.33` → svclb → zot pod).
|
||||
- CI runner pushes to `registry.neko-piranha.ts.net` (Tailscale → `100.75.220.33` → svclb → zot pod).
|
||||
|
||||
### Resource Limits
|
||||
|
||||
@@ -111,14 +110,14 @@ kubectl config use-context buzz
|
||||
# DB migration
|
||||
kubectl delete job db-migrate -n buzz --ignore-not-found
|
||||
kubectl create job db-migrate \
|
||||
--image=mts.dgnr.us:5000/astral/buzz:frontend-$TAG \
|
||||
--image=registry.neko-piranha.ts.net/astral/buzz:frontend-$TAG \
|
||||
-n buzz \
|
||||
--command -- bun dr push
|
||||
kubectl wait --for=condition=complete job/db-migrate -n buzz --timeout=120s
|
||||
|
||||
# Roll app & backend
|
||||
kubectl set image deployment/app app=mts.dgnr.us:5000/astral/buzz:frontend-$TAG -n buzz
|
||||
kubectl set image deployment/backend backend=mts.dgnr.us:5000/astral/buzz:backend-$TAG -n buzz
|
||||
kubectl set image deployment/app app=registry.neko-piranha.ts.net/astral/buzz:frontend-$TAG -n buzz
|
||||
kubectl set image deployment/backend backend=registry.neko-piranha.ts.net/astral/buzz:backend-$TAG -n buzz
|
||||
```
|
||||
|
||||
CI runner needs Gitea secret `KUBE_TOKEN` containing the `ci-deployer` SA token. Rotate via:
|
||||
|
||||
@@ -36,7 +36,7 @@ spec:
|
||||
terminationGracePeriodSeconds: 5
|
||||
containers:
|
||||
- name: app
|
||||
image: mts.dgnr.us:5000/astral/buzz:frontend
|
||||
image: registry.neko-piranha.ts.net/astral/buzz:frontend
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
protocol: TCP
|
||||
|
||||
@@ -26,7 +26,7 @@ spec:
|
||||
terminationGracePeriodSeconds: 5
|
||||
containers:
|
||||
- name: backend
|
||||
image: mts.dgnr.us:5000/astral/buzz:backend
|
||||
image: registry.neko-piranha.ts.net/astral/buzz:backend
|
||||
env:
|
||||
- name: NO_AUTH_CHECK
|
||||
value: "true"
|
||||
|
||||
Reference in New Issue
Block a user