spring-petclinic/.github/workflows/ci-petclinic.yml
2025-12-06 09:42:17 +00:00

140 lines
4.7 KiB
YAML

name: CI - Petclinic EKS
# 워크플로우 전체에서 Git push 허용
permissions:
contents: write
on:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
# 공통 ENV
env:
AWS_REGION: ${{ vars.AWS_REGION || 'ap-northeast-2' }}
ECR_REPOSITORY: ${{ vars.ECR_REPOSITORY || 'eks/petclinic' }}
jobs:
# 1) Maven 빌드 + 테스트
build-test:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up JDK
uses: actions/setup-java@v4
with:
distribution: 'temurin'
java-version: '25'
cache: 'maven'
- name: Maven build & test
run: |
if [ -x "./mvnw" ]; then
./mvnw -B clean test package
else
mvn -B clean test package
fi
- name: Archive built JAR (optional)
uses: actions/upload-artifact@v4
with:
name: petclinic-jar
path: target/*.jar
# 2) Docker 이미지 빌드 + ECR Push + k8s manifest 이미지 태그/앱 버전 업데이트
build-and-push-image:
needs: build-test
runs-on: ubuntu-latest
# 이 job에서 git push도 해야 하므로 contents: write 설정
permissions:
id-token: write
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Configure AWS credentials (OIDC / Assume Role)
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_ROLE_ARN }}
aws-region: ${{ env.AWS_REGION }}
- name: Login to Amazon ECR
id: ecr-login
uses: aws-actions/amazon-ecr-login@v2
- name: Set image tag
id: vars
run: |
SHORT_SHA=${GITHUB_SHA::7}
echo "IMAGE_TAG=${SHORT_SHA}" >> "$GITHUB_ENV"
echo "IMAGE_TAG=${SHORT_SHA}"
- name: Read base version from pom.xml
run: |
POM_VERSION=$(./mvnw -q \
-Dexpression=project.version \
-DforceStdout help:evaluate)
echo "POM_VERSION=${POM_VERSION}"
# -SNAPSHOT suffix 제거
BASE_VERSION=${POM_VERSION%-SNAPSHOT}
echo "BASE_VERSION=${BASE_VERSION}"
echo "BASE_VERSION=${BASE_VERSION}" >> $GITHUB_ENV
- name: Build APP_VERSION (base + image tag)
run: |
APP_VERSION="A-${BASE_VERSION}-${IMAGE_TAG}"
echo "APP_VERSION=${APP_VERSION}"
echo "APP_VERSION=${APP_VERSION}" >> $GITHUB_ENV
- name: Update application version property
run: |
sed -i "s/^app.version=.*/app.version=${APP_VERSION}/" src/main/resources/application.properties
- name: Build Docker image
env:
DOCKER_BUILDKIT: 1
run: |
ECR_REGISTRY=${{ steps.ecr-login.outputs.registry }}
IMAGE_URI="$ECR_REGISTRY/${{ env.ECR_REPOSITORY }}:${IMAGE_TAG}"
echo "Building image: $IMAGE_URI"
docker build -t "$IMAGE_URI" .
- name: Push Docker image
run: |
ECR_REGISTRY=${{ steps.ecr-login.outputs.registry }}
IMAGE_URI="$ECR_REGISTRY/${{ env.ECR_REPOSITORY }}:${IMAGE_TAG}"
docker push "$IMAGE_URI"
- name: Tag image as latest (only on main)
if: github.ref == 'refs/heads/main'
run: |
ECR_REGISTRY=${{ steps.ecr-login.outputs.registry }}
IMAGE_BASE="$ECR_REGISTRY/${{ env.ECR_REPOSITORY }}"
docker tag "${IMAGE_BASE}:${IMAGE_TAG}" "${IMAGE_BASE}:latest"
docker push "${IMAGE_BASE}:latest"
# app.version 업데이트 (commit/push는 아래에서 한 번에)
- name: Update Kubernetes manifest image tag (only on main)
if: github.ref == 'refs/heads/main'
env:
YAML_PATH: k8s/20-petclinic-Deployments-postgre.yaml
run: |
ECR_REGISTRY=${{ steps.ecr-login.outputs.registry }}
IMAGE_BASE="$ECR_REGISTRY/${{ env.ECR_REPOSITORY }}"
NEW_IMAGE="${IMAGE_BASE}:${IMAGE_TAG}"
echo "New image: $NEW_IMAGE"
echo "Updating $YAML_PATH"
sed -i "s#^\(\s*image:\s*\).*#\1${NEW_IMAGE}#" "$YAML_PATH"
# 위 두 파일을 한 번에 commit & push
- name: Commit and push changes (only on main)
if: github.ref == 'refs/heads/main'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
git config user.name "github-actions"
git config user.email "github-actions@github.com"
git status
git add src/main/resources/application.properties k8s/20-petclinic-Deployments-postgre.yaml
git commit -m "chore: update petclinic image to ${APP_VERSION}" || echo "No changes to commit"
git push