fix(ci): improve image selection and registry handling in deployment workflow

- Add better image selection logic with fallback handling
- Support multiple registry logins for different image sources
- Improve error handling and image URL parsing
- Add proper argument escaping for SSH deployment script
This commit is contained in:
2025-11-01 22:16:23 +01:00
parent fa28e3580a
commit 5ec5c41a0a

View File

@@ -830,57 +830,113 @@ jobs:
set -e set -e
DEPLOYMENT_HOST="${{ env.DEPLOYMENT_HOST }}" DEPLOYMENT_HOST="${{ env.DEPLOYMENT_HOST }}"
REGISTRY="${{ env.REGISTRY }}" REGISTRY_HOST="${{ env.REGISTRY }}"
IMAGE_NAME="${{ env.IMAGE_NAME }}" IMAGE_NAME="${{ env.IMAGE_NAME }}"
BUILD_RESULT="${{ needs.build.result }}" BUILD_RESULT="${{ needs.build.result }}"
IMAGE_TAG="${{ needs.build.outputs.image_tag || 'latest' }}" IMAGE_TAG_RAW="${{ needs.build.outputs.image_tag }}"
IMAGE_URL_RAW="${{ needs.build.outputs.image_url }}"
if [ "$BUILD_RESULT" != "success" ]; then DEFAULT_IMAGE="${REGISTRY_HOST}/${IMAGE_NAME}:latest"
IMAGE_TAG="latest" SELECTED_IMAGE=""
if [ "$BUILD_RESULT" = "success" ] && [ -n "$IMAGE_URL_RAW" ] && [ "$IMAGE_URL_RAW" != "null" ]; then
SELECTED_IMAGE="$IMAGE_URL_RAW"
fi fi
if [ -z "$IMAGE_TAG" ] || [ "$IMAGE_TAG" = "null" ]; then if [ -z "$SELECTED_IMAGE" ]; then
IMAGE_TAG="latest" if [ "$BUILD_RESULT" = "success" ] && [ -n "$IMAGE_TAG_RAW" ] && [ "$IMAGE_TAG_RAW" != "null" ]; then
SELECTED_IMAGE="${REGISTRY_HOST}/${IMAGE_NAME}:${IMAGE_TAG_RAW}"
else
SELECTED_IMAGE="$DEFAULT_IMAGE"
fi
fi
if [ -z "$SELECTED_IMAGE" ]; then
SELECTED_IMAGE="$DEFAULT_IMAGE"
fi
SELECTED_TAG="${SELECTED_IMAGE##*:}"
SELECTED_REPO="${SELECTED_IMAGE%:*}"
if [ -z "$SELECTED_REPO" ] || [ "$SELECTED_REPO" = "$SELECTED_IMAGE" ]; then
FALLBACK_IMAGE="$DEFAULT_IMAGE"
else
FALLBACK_IMAGE="${SELECTED_REPO}:latest"
fi fi
FULL_IMAGE="${REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG}"
STACK_PATH="~/deployment/stacks/staging" STACK_PATH="~/deployment/stacks/staging"
echo "🚀 Starting staging deployment..." echo "🚀 Starting staging deployment..."
echo " Image: ${FULL_IMAGE}" echo " Image: ${SELECTED_IMAGE}"
echo " Tag: ${IMAGE_TAG}" echo " Tag: ${SELECTED_TAG}"
echo " Host: ${DEPLOYMENT_HOST}" echo " Host: ${DEPLOYMENT_HOST}"
echo " Stack: ${STACK_PATH}" echo " Stack: ${STACK_PATH}"
FULL_IMAGE_ARG=$(printf '%q' "$SELECTED_IMAGE")
FALLBACK_IMAGE_ARG=$(printf '%q' "$FALLBACK_IMAGE")
IMAGE_NAME_ARG=$(printf '%q' "$IMAGE_NAME")
STACK_PATH_ARG=$(printf '%q' "$STACK_PATH")
REGISTRY_ARG=$(printf '%q' "$REGISTRY_HOST")
ssh -i ~/.ssh/production \ ssh -i ~/.ssh/production \
-o StrictHostKeyChecking=no \ -o StrictHostKeyChecking=no \
-o UserKnownHostsFile=/dev/null \ -o UserKnownHostsFile=/dev/null \
deploy@${DEPLOYMENT_HOST} <<EOF deploy@${DEPLOYMENT_HOST} "bash -s -- $FULL_IMAGE_ARG $FALLBACK_IMAGE_ARG $IMAGE_NAME_ARG $STACK_PATH_ARG $REGISTRY_ARG" <<'EOF'
set -e set -e
FULL_IMAGE="$1"
FALLBACK_IMAGE="$2"
IMAGE_NAME="$3"
STACK_PATH="$4"
REGISTRY="$5"
shift 5
STACK_TARGET="${STACK_PATH:-~/deployment/stacks/staging}"
case "$STACK_TARGET" in
~*) STACK_TARGET="${HOME}${STACK_TARGET#~}" ;;
esac
# Ensure staging stack directory exists # Ensure staging stack directory exists
mkdir -p ${STACK_PATH} mkdir -p "${STACK_TARGET}"
cd ${STACK_PATH} cd "${STACK_TARGET}"
echo "🔐 Logging in to Docker registry..." declare -a REGISTRY_TARGETS=()
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login ${REGISTRY} \ if [ -n "${REGISTRY}" ]; then
REGISTRY_TARGETS+=("${REGISTRY}")
fi
for IMAGE_REF in "${FULL_IMAGE}" "${FALLBACK_IMAGE}"; do
if [ -n "${IMAGE_REF}" ]; then
HOST_PART="${IMAGE_REF%%/*}"
if [ -n "${HOST_PART}" ]; then
if ! printf '%s\n' "${REGISTRY_TARGETS[@]}" | grep -qx "${HOST_PART}"; then
REGISTRY_TARGETS+=("${HOST_PART}")
fi
fi
fi
done
for TARGET in "${REGISTRY_TARGETS[@]}"; do
[ -z "${TARGET}" ] && continue
echo "🔐 Logging in to Docker registry ${TARGET}..."
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login "${TARGET}" \
-u "${{ secrets.REGISTRY_USER }}" \ -u "${{ secrets.REGISTRY_USER }}" \
--password-stdin || echo "⚠️ Registry login failed, continuing..." --password-stdin || echo "⚠️ Registry login failed for ${TARGET}, continuing..."
done
echo "📥 Pulling image ${FULL_IMAGE}..." DEPLOY_IMAGE="$FULL_IMAGE"
if ! docker pull ${FULL_IMAGE}; then echo "📥 Pulling image ${DEPLOY_IMAGE}..."
if [ "${IMAGE_TAG}" != "latest" ]; then if ! docker pull "${DEPLOY_IMAGE}"; then
echo "⚠️ Failed to pull ${FULL_IMAGE}, falling back to :latest" if [ -n "${FALLBACK_IMAGE}" ] && [ "${DEPLOY_IMAGE}" != "${FALLBACK_IMAGE}" ]; then
IMAGE_TAG="latest" echo "⚠️ Failed to pull ${DEPLOY_IMAGE}, attempting fallback ${FALLBACK_IMAGE}"
FULL_IMAGE="${REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG}" if docker pull "${FALLBACK_IMAGE}"; then
if docker pull ${FULL_IMAGE}; then DEPLOY_IMAGE="${FALLBACK_IMAGE}"
echo " Using fallback image ${FULL_IMAGE}" echo " Using fallback image ${DEPLOY_IMAGE}"
else else
echo "❌ Failed to pull fallback image ${FULL_IMAGE}" echo "❌ Failed to pull fallback image ${FALLBACK_IMAGE}"
exit 1 exit 1
fi fi
else else
echo "❌ Failed to pull image ${FULL_IMAGE}" echo "❌ Failed to pull image ${DEPLOY_IMAGE}"
exit 1 exit 1
fi fi
fi fi
@@ -896,7 +952,7 @@ jobs:
# Update docker-compose.yml with new image tag # Update docker-compose.yml with new image tag
echo "📝 Updating docker-compose.yml..." echo "📝 Updating docker-compose.yml..."
sed -i "s|image:.*/${IMAGE_NAME}:.*|image: ${FULL_IMAGE}|g" docker-compose.yml sed -i "s|image:.*/${IMAGE_NAME}:.*|image: ${DEPLOY_IMAGE}|g" docker-compose.yml
echo "✅ Updated docker-compose.yml:" echo "✅ Updated docker-compose.yml:"
grep "image:" docker-compose.yml | head -5 grep "image:" docker-compose.yml | head -5