Files
cloud-host/scripts/gitops-deploy.sh
T
keyhan 7e66d1edf3
Build and Deploy Platform / build-and-deploy (push) Failing after 20m1s
ci: split GitOps state into cloud-host-gitops repo, add Sealed Secrets, fix pipeline auth
- Workflow now pushes image tags to the separate cloud-host-gitops repo
  (no more CI loop risk) and authenticates via CI_TOKEN secret
- Fix undefined ${REGISTRY} in Kaniko jobs, add concurrency group,
  targeted tag update, and mounted kaniko-harbor-auth docker config
- Argo CD Application is now multi-source (chart from cloud-host,
  values from cloud-host-gitops)
- Remove plaintext runner token and proxy credentials from manifests;
  secrets are now SealedSecrets in the gitops repo

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 14:10:46 +03:30

45 lines
1.6 KiB
Bash
Executable File

#!/usr/bin/env bash
# Deploy platform via Helm only — images must already be in Harbor (built by Gitea Actions / Kaniko).
set -euo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
NAMESPACE="${NAMESPACE:-cloudhost}"
RELEASE="${RELEASE:-cloudhost}"
# Production values now live in the cloud-host-gitops repo (platform/values-abrban.yaml).
VALUES="${VALUES:-${ROOT}/../cloud-host-gitops/platform/values-abrban.yaml}"
TAG="${TAG:-}"
if [[ ! -f "${VALUES}" ]]; then
echo "ERROR: values file not found: ${VALUES}" >&2
echo "Clone the GitOps repo next to this one, or pass VALUES=/path/to/values-abrban.yaml:" >&2
echo " git clone https://git.abrban.com/abrban/cloud-host-gitops.git" >&2
exit 1
fi
if [[ -z "${TAG}" ]]; then
TAG="$(grep -E '^\s+tag:' "${VALUES}" | head -1 | sed 's/.*tag: *"\?\([^"]*\)"\?.*/\1/')"
fi
if [[ -z "${TAG}" || "${TAG}" == "1.0.0" ]]; then
echo "ERROR: No image tag set. Build in-cluster first:" >&2
echo " ./scripts/trigger-platform-build.sh" >&2
echo "Or set TAG=... after CI has pushed images." >&2
exit 1
fi
echo "==> Helm upgrade ${RELEASE} (tag=${TAG})"
helm upgrade --install "${RELEASE}" "${ROOT}/backend/helm/cloudhost-platform" \
-n "${NAMESPACE}" \
-f "${VALUES}" \
--set createNamespace=false \
--set global.storageClass=local-path \
--set images.backend.tag="${TAG}" \
--set images.frontend.tag="${TAG}" \
--timeout 15m \
--wait
kubectl -n "${NAMESPACE}" rollout status deploy/cloudhost-backend --timeout=300s
kubectl -n "${NAMESPACE}" rollout status deploy/cloudhost-frontend --timeout=300s
echo "==> Done (tag=${TAG})"