-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathcloudbuild-github-app.yaml
More file actions
80 lines (72 loc) · 3.11 KB
/
Copy pathcloudbuild-github-app.yaml
File metadata and controls
80 lines (72 loc) · 3.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
# ─────────────────────────────────────────────────────────────────────────────
# LEGACY — retired; see the maintainer runbook.
# Redstring now ships via Cloudflare Pages. This Cloud Build config deploys a
# public (--allow-unauthenticated) Cloud Run service. Its first step fails
# unless the build is submitted with --substitutions=_ALLOW_LEGACY_GCP=1.
# ─────────────────────────────────────────────────────────────────────────────
# Google Cloud Build Configuration for Redstring GitHub App OAuth Server
# Builds and deploys OAuth server with GitHub App support to Cloud Run
steps:
# Refuse to run unless explicitly opted in (retired infrastructure).
- name: 'bash'
entrypoint: 'bash'
args: ['-c', 'if [ "$_ALLOW_LEGACY_GCP" != "1" ]; then echo "Refusing: retired GCP deployment. See the maintainer runbook" >&2; exit 1; fi']
id: 'legacy-guard'
# Step 1: Build GitHub App OAuth Server Docker image
- name: 'gcr.io/cloud-builders/docker'
args:
- 'build'
- '-f'
- 'deployment/docker/oauth-app.Dockerfile'
- '-t'
- 'gcr.io/$PROJECT_ID/redstring-oauth-app:$BUILD_ID'
- '-t'
- 'gcr.io/$PROJECT_ID/redstring-oauth-app:latest'
- '.'
id: 'build-oauth-image'
# Step 2: Push to Container Registry
- name: 'gcr.io/cloud-builders/docker'
args: ['push', 'gcr.io/$PROJECT_ID/redstring-oauth-app:$BUILD_ID']
id: 'push-oauth-image'
waitFor: ['build-oauth-image']
# Step 3: Deploy OAuth Server to Cloud Run (Production)
- name: 'gcr.io/google.com/cloudsdktool/cloud-sdk'
entrypoint: 'gcloud'
args:
- 'run'
- 'deploy'
- 'redstring-oauth-prod'
- '--image'
- 'gcr.io/$PROJECT_ID/redstring-oauth-app:$BUILD_ID'
- '--region'
- '${_REGION}'
- '--platform'
- 'managed'
- '--allow-unauthenticated'
- '--port'
- '3002'
- '--memory'
- '512Mi'
- '--cpu'
- '1'
- '--concurrency'
- '50'
- '--max-instances'
- '10'
- '--set-env-vars'
- 'NODE_ENV=production,OAUTH_PORT=3002'
- '--set-secrets'
- 'GITHUB_CLIENT_ID=github-client-id:latest,GITHUB_CLIENT_SECRET=github-client-secret:latest,GITHUB_APP_ID=github-app-id:latest,GITHUB_APP_CLIENT_ID=github-app-client-id:latest,GITHUB_APP_CLIENT_SECRET=github-app-client-secret:latest,GITHUB_APP_PRIVATE_KEY=github-app-private-key:latest,GITHUB_APP_WEBHOOK_SECRET=github-app-webhook-secret:latest'
id: 'deploy-oauth-prod'
waitFor: ['push-oauth-image']
# Substitution variables (set these in Cloud Build trigger)
substitutions:
_ALLOW_LEGACY_GCP: '0'
_REGION: 'us-central1'
# Build timeout
timeout: '1200s'
# Log to Cloud Logging
logsBucket: 'gs://${PROJECT_ID}-build-logs'
images:
- 'gcr.io/$PROJECT_ID/redstring-oauth-app:$BUILD_ID'
- 'gcr.io/$PROJECT_ID/redstring-oauth-app:latest'