fix deploy: use gitea:3000 for registry, retag for compose, add README.md
- Change buildx repo/registry from localhost:3000 to gitea:3000 (reachable on CI network; localhost resolves to container loopback) - Add pull+retag step in deploy so fhirworx/* compose images exist - Copy README.md in API Dockerfile (uv build needs it from pyproject)
This commit is contained in:
@@ -5,8 +5,8 @@
|
|||||||
# Only runs on pushes to main (i.e. after PR merge).
|
# Only runs on pushes to main (i.e. after PR merge).
|
||||||
#
|
#
|
||||||
# Image naming:
|
# Image naming:
|
||||||
# localhost:3000/homelab/<service>:sha-<8chars> (registry)
|
# gitea:3000/homelab/<service>:sha-<8chars> (registry)
|
||||||
# localhost:3000/homelab/<service>:latest (registry)
|
# gitea:3000/homelab/<service>:latest (registry)
|
||||||
#
|
#
|
||||||
# The deploy step writes COMMIT_SHA=sha-<short> into .env so
|
# The deploy step writes COMMIT_SHA=sha-<short> into .env so
|
||||||
# compose.yml resolves the exact image just built.
|
# compose.yml resolves the exact image just built.
|
||||||
@@ -41,8 +41,8 @@ steps:
|
|||||||
- name: build-push-notebooks
|
- name: build-push-notebooks
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/notebooks
|
repo: gitea:3000/homelab/notebooks
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: notebooks/Dockerfile
|
dockerfile: notebooks/Dockerfile
|
||||||
context: notebooks/
|
context: notebooks/
|
||||||
tags:
|
tags:
|
||||||
@@ -60,7 +60,7 @@ steps:
|
|||||||
- name: scan-notebooks
|
- name: scan-notebooks
|
||||||
image: woodpeckerci/plugin-trivy
|
image: woodpeckerci/plugin-trivy
|
||||||
settings:
|
settings:
|
||||||
image_ref: "localhost:3000/homelab/notebooks:sha-${CI_COMMIT_SHA:0:8}"
|
image_ref: "gitea:3000/homelab/notebooks:sha-${CI_COMMIT_SHA:0:8}"
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
exit_code: 0
|
exit_code: 0
|
||||||
output: notebooks-scan.json
|
output: notebooks-scan.json
|
||||||
@@ -74,8 +74,8 @@ steps:
|
|||||||
- name: build-push-zotero
|
- name: build-push-zotero
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/zotero
|
repo: gitea:3000/homelab/zotero
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: zotero/Dockerfile
|
dockerfile: zotero/Dockerfile
|
||||||
context: zotero/
|
context: zotero/
|
||||||
tags:
|
tags:
|
||||||
@@ -93,7 +93,7 @@ steps:
|
|||||||
- name: scan-zotero
|
- name: scan-zotero
|
||||||
image: woodpeckerci/plugin-trivy
|
image: woodpeckerci/plugin-trivy
|
||||||
settings:
|
settings:
|
||||||
image_ref: "localhost:3000/homelab/zotero:sha-${CI_COMMIT_SHA:0:8}"
|
image_ref: "gitea:3000/homelab/zotero:sha-${CI_COMMIT_SHA:0:8}"
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
exit_code: 0
|
exit_code: 0
|
||||||
output: zotero-scan.json
|
output: zotero-scan.json
|
||||||
@@ -116,8 +116,8 @@ steps:
|
|||||||
- name: build-push-docs
|
- name: build-push-docs
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/docs
|
repo: gitea:3000/homelab/docs
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: docs/Dockerfile
|
dockerfile: docs/Dockerfile
|
||||||
context: .
|
context: .
|
||||||
tags:
|
tags:
|
||||||
@@ -137,7 +137,7 @@ steps:
|
|||||||
- name: scan-docs
|
- name: scan-docs
|
||||||
image: woodpeckerci/plugin-trivy
|
image: woodpeckerci/plugin-trivy
|
||||||
settings:
|
settings:
|
||||||
image_ref: "localhost:3000/homelab/docs:sha-${CI_COMMIT_SHA:0:8}"
|
image_ref: "gitea:3000/homelab/docs:sha-${CI_COMMIT_SHA:0:8}"
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
exit_code: 0
|
exit_code: 0
|
||||||
output: docs-scan.json
|
output: docs-scan.json
|
||||||
@@ -151,8 +151,8 @@ steps:
|
|||||||
- name: build-push-api
|
- name: build-push-api
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/api
|
repo: gitea:3000/homelab/api
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: api/Dockerfile
|
dockerfile: api/Dockerfile
|
||||||
context: .
|
context: .
|
||||||
tags:
|
tags:
|
||||||
@@ -170,7 +170,7 @@ steps:
|
|||||||
- name: scan-api
|
- name: scan-api
|
||||||
image: woodpeckerci/plugin-trivy
|
image: woodpeckerci/plugin-trivy
|
||||||
settings:
|
settings:
|
||||||
image_ref: "localhost:3000/homelab/api:sha-${CI_COMMIT_SHA:0:8}"
|
image_ref: "gitea:3000/homelab/api:sha-${CI_COMMIT_SHA:0:8}"
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
exit_code: 0
|
exit_code: 0
|
||||||
output: api-scan.json
|
output: api-scan.json
|
||||||
@@ -184,8 +184,8 @@ steps:
|
|||||||
- name: build-push-mc
|
- name: build-push-mc
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/mc
|
repo: gitea:3000/homelab/mc
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: rustfs/Dockerfile.mc
|
dockerfile: rustfs/Dockerfile.mc
|
||||||
context: rustfs/
|
context: rustfs/
|
||||||
tags:
|
tags:
|
||||||
@@ -274,8 +274,12 @@ steps:
|
|||||||
- git fetch http://gitea:3000/homelab/stack.git main
|
- git fetch http://gitea:3000/homelab/stack.git main
|
||||||
- git reset --hard FETCH_HEAD
|
- git reset --hard FETCH_HEAD
|
||||||
- cp .env.bak .env 2>/dev/null || true
|
- cp .env.bak .env 2>/dev/null || true
|
||||||
# Pin compose to the exact images just built
|
# Pull from Gitea registry and retag for compose
|
||||||
- TAG=sha-${CI_COMMIT_SHA:0:8}
|
- TAG=sha-${CI_COMMIT_SHA:0:8}
|
||||||
|
- for SVC in notebooks zotero docs api mc; do
|
||||||
|
docker pull gitea:3000/homelab/$SVC:$TAG &&
|
||||||
|
docker tag gitea:3000/homelab/$SVC:$TAG fhirworx/$SVC:$TAG;
|
||||||
|
done
|
||||||
- sed -i "s/^COMMIT_SHA=.*/COMMIT_SHA=$TAG/" .env 2>/dev/null || echo "COMMIT_SHA=$TAG" >> .env
|
- sed -i "s/^COMMIT_SHA=.*/COMMIT_SHA=$TAG/" .env 2>/dev/null || echo "COMMIT_SHA=$TAG" >> .env
|
||||||
- docker compose up -d --remove-orphans
|
- docker compose up -d --remove-orphans
|
||||||
depends_on:
|
depends_on:
|
||||||
|
|||||||
@@ -5,8 +5,8 @@ steps:
|
|||||||
- name: build-push-notebooks
|
- name: build-push-notebooks
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/notebooks
|
repo: gitea:3000/homelab/notebooks
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: notebooks/Dockerfile
|
dockerfile: notebooks/Dockerfile
|
||||||
context: notebooks/
|
context: notebooks/
|
||||||
tags:
|
tags:
|
||||||
@@ -24,8 +24,8 @@ steps:
|
|||||||
- name: build-push-zotero
|
- name: build-push-zotero
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/zotero
|
repo: gitea:3000/homelab/zotero
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: zotero/Dockerfile
|
dockerfile: zotero/Dockerfile
|
||||||
context: zotero/
|
context: zotero/
|
||||||
tags:
|
tags:
|
||||||
@@ -51,8 +51,8 @@ steps:
|
|||||||
- name: build-push-docs
|
- name: build-push-docs
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/docs
|
repo: gitea:3000/homelab/docs
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: docs/Dockerfile
|
dockerfile: docs/Dockerfile
|
||||||
context: .
|
context: .
|
||||||
tags:
|
tags:
|
||||||
@@ -72,8 +72,8 @@ steps:
|
|||||||
- name: build-push-api
|
- name: build-push-api
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/api
|
repo: gitea:3000/homelab/api
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: api/Dockerfile
|
dockerfile: api/Dockerfile
|
||||||
context: .
|
context: .
|
||||||
tags:
|
tags:
|
||||||
@@ -91,8 +91,8 @@ steps:
|
|||||||
- name: build-push-mc
|
- name: build-push-mc
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: woodpeckerci/plugin-docker-buildx
|
||||||
settings:
|
settings:
|
||||||
repo: localhost:3000/homelab/mc
|
repo: gitea:3000/homelab/mc
|
||||||
registry: localhost:3000
|
registry: gitea:3000
|
||||||
dockerfile: rustfs/Dockerfile.mc
|
dockerfile: rustfs/Dockerfile.mc
|
||||||
context: rustfs/
|
context: rustfs/
|
||||||
tags:
|
tags:
|
||||||
@@ -110,7 +110,7 @@ steps:
|
|||||||
- name: scan-notebooks
|
- name: scan-notebooks
|
||||||
image: woodpeckerci/plugin-trivy
|
image: woodpeckerci/plugin-trivy
|
||||||
settings:
|
settings:
|
||||||
image_ref: "localhost:3000/homelab/notebooks:sha-${CI_COMMIT_SHA:0:8}"
|
image_ref: "gitea:3000/homelab/notebooks:sha-${CI_COMMIT_SHA:0:8}"
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
exit_code: 0
|
exit_code: 0
|
||||||
volumes:
|
volumes:
|
||||||
@@ -121,7 +121,7 @@ steps:
|
|||||||
- name: scan-zotero
|
- name: scan-zotero
|
||||||
image: woodpeckerci/plugin-trivy
|
image: woodpeckerci/plugin-trivy
|
||||||
settings:
|
settings:
|
||||||
image_ref: "localhost:3000/homelab/zotero:sha-${CI_COMMIT_SHA:0:8}"
|
image_ref: "gitea:3000/homelab/zotero:sha-${CI_COMMIT_SHA:0:8}"
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
exit_code: 0
|
exit_code: 0
|
||||||
volumes:
|
volumes:
|
||||||
@@ -132,7 +132,7 @@ steps:
|
|||||||
- name: scan-api
|
- name: scan-api
|
||||||
image: woodpeckerci/plugin-trivy
|
image: woodpeckerci/plugin-trivy
|
||||||
settings:
|
settings:
|
||||||
image_ref: "localhost:3000/homelab/api:sha-${CI_COMMIT_SHA:0:8}"
|
image_ref: "gitea:3000/homelab/api:sha-${CI_COMMIT_SHA:0:8}"
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
exit_code: 0
|
exit_code: 0
|
||||||
volumes:
|
volumes:
|
||||||
@@ -148,6 +148,10 @@ steps:
|
|||||||
commands:
|
commands:
|
||||||
- cd /home/kert/stack
|
- cd /home/kert/stack
|
||||||
- TAG=sha-${CI_COMMIT_SHA:0:8}
|
- TAG=sha-${CI_COMMIT_SHA:0:8}
|
||||||
|
- for SVC in notebooks zotero docs api mc; do
|
||||||
|
docker pull gitea:3000/homelab/$SVC:$TAG &&
|
||||||
|
docker tag gitea:3000/homelab/$SVC:$TAG fhirworx/$SVC:$TAG;
|
||||||
|
done
|
||||||
- sed -i "s/^COMMIT_SHA=.*/COMMIT_SHA=$TAG/" .env 2>/dev/null || echo "COMMIT_SHA=$TAG" >> .env
|
- sed -i "s/^COMMIT_SHA=.*/COMMIT_SHA=$TAG/" .env 2>/dev/null || echo "COMMIT_SHA=$TAG" >> .env
|
||||||
- docker compose up -d --remove-orphans
|
- docker compose up -d --remove-orphans
|
||||||
depends_on:
|
depends_on:
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ FROM ghcr.io/astral-sh/uv:python3.13-bookworm-slim
|
|||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
# Copy project files for install
|
# Copy project files for install
|
||||||
COPY pyproject.toml uv.lock ./
|
COPY pyproject.toml uv.lock README.md ./
|
||||||
COPY src/ src/
|
COPY src/ src/
|
||||||
|
|
||||||
# Install the package (no dev deps)
|
# Install the package (no dev deps)
|
||||||
|
|||||||
Reference in New Issue
Block a user