Files
cloud-host/scripts/trigger-platform-build.sh
T
keyhan 7e66d1edf3
Build and Deploy Platform / build-and-deploy (push) Failing after 20m1s
ci: split GitOps state into cloud-host-gitops repo, add Sealed Secrets, fix pipeline auth
- Workflow now pushes image tags to the separate cloud-host-gitops repo
  (no more CI loop risk) and authenticates via CI_TOKEN secret
- Fix undefined ${REGISTRY} in Kaniko jobs, add concurrency group,
  targeted tag update, and mounted kaniko-harbor-auth docker config
- Argo CD Application is now multi-source (chart from cloud-host,
  values from cloud-host-gitops)
- Remove plaintext runner token and proxy credentials from manifests;
  secrets are now SealedSecrets in the gitops repo

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 14:10:46 +03:30

78 lines
2.7 KiB
Bash
Executable File

#!/usr/bin/env bash
# Trigger in-cluster Kaniko build → Harbor. No local docker build/push.
set -euo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
NAMESPACE="${BUILD_NAMESPACE:-cloudhost-builds}"
JOB_NAME="${JOB_NAME:-build-platform-images}"
GIT_REPO="${GIT_REPO:-http://gitea-http.gitea.svc.cluster.local:3000/abrban/cloud-host.git}"
GIT_REF="${GIT_REF:-main}"
IMAGE_TAG="${IMAGE_TAG:-$(date +%Y%m%d-%H%M)}"
echo "==> Applying Kaniko build job (tag=${IMAGE_TAG}, ref=${GIT_REF})"
kubectl -n "${NAMESPACE}" delete job "${JOB_NAME}" --ignore-not-found
kubectl apply -f - <<EOF
apiVersion: batch/v1
kind: Job
metadata:
name: ${JOB_NAME}
namespace: ${NAMESPACE}
spec:
ttlSecondsAfterFinished: 3600
backoffLimit: 1
template:
spec:
restartPolicy: Never
imagePullSecrets:
- name: registry-pull-secret
initContainers:
- name: git-clone
image: registry.abrban.com/proxy-dockerhub/alpine/git:2.43.0
command:
- sh
- -ec
- |
git clone --depth=1 --branch "${GIT_REF}" "${GIT_REPO}" /workspace
ls -la /workspace
volumeMounts:
- name: workspace
mountPath: /workspace
containers:
- name: kaniko
image: registry.abrban.com/proxy-gcr/kaniko-project/executor:v1.23.2
command:
- sh
- -ec
- |
set -eux
REG="harbor-registry.cloudhost.svc.cluster.local:5000/abrban"
/kaniko/executor \
--dockerfile=/workspace/backend/Dockerfile \
--context=dir:///workspace/backend \
--destination="${REG}/cloudhost-backend:${IMAGE_TAG}" \
--insecure --skip-tls-verify
/kaniko/executor \
--dockerfile=/workspace/frontend/Dockerfile \
--context=dir:///workspace/frontend \
--build-arg=NEXT_PUBLIC_API_URL=https://api.abrban.com \
--destination="${REG}/cloudhost-frontend:${IMAGE_TAG}" \
--insecure --skip-tls-verify
echo "BUILT_TAG=${IMAGE_TAG}"
volumeMounts:
- name: workspace
mountPath: /workspace
volumes:
- name: workspace
emptyDir: {}
EOF
echo "==> Waiting for build job..."
kubectl -n "${NAMESPACE}" wait --for=condition=complete "job/${JOB_NAME}" --timeout=45m
echo "==> Build complete (tag=${IMAGE_TAG})."
echo "To deploy via GitOps, commit the tag in the cloud-host-gitops repo:"
echo " platform/values-abrban.yaml → images.backend.tag / images.frontend.tag = \"${IMAGE_TAG}\""
echo "Or for a direct Helm deploy (bootstrap only):"
echo " TAG=${IMAGE_TAG} ./scripts/gitops-deploy.sh"