feat: Add github action ip on security group #7
Workflow file for this run
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: ShowPot-Dev-CD | |
on: | |
push: | |
branches: | |
- feat-cd-dev | |
jobs: | |
build-and-docker-hub-push: | |
runs-on: ubuntu-latest | |
permissions: | |
contents: read | |
steps: | |
- uses: actions/checkout@v4 | |
- name: Set up JDK 17 | |
uses: actions/setup-java@v4 | |
with: | |
java-version: '17' | |
distribution: 'liberica' | |
cache: gradle | |
- name: Setup Gradle | |
uses: gradle/actions/setup-gradle@v3 | |
- name: Copy Secrets | |
env: | |
ACCESS_KEY: ${{ secrets.AWS_ACCESS_KEY }} | |
SECRET_KEY: ${{ secrets.AWS_SECRET_KEY }} | |
run: | |
echo $ACCESS_KEY > ./app/src/main/resources/application-dev.yml | |
echo $SECRET_KEY > ./app/src/main/resources/application-dev.yml | |
- name: Build with Gradle Wrapper | |
run: ./gradlew clean build | |
- name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@v3 | |
- name: Docker Login | |
uses: docker/login-action@v2 | |
with: | |
username: ${{ secrets.DOCKERHUB_USERNAME }} | |
password: ${{ secrets.DOCKERHUB_PASSWORD }} | |
- name: Build Docker Image | |
run: | | |
docker build -t ${{ secrets.DOCKERHUB_USERNAME }}/showpot:dev . | |
docker push ${{ secrets.DOCKERHUB_USERNAME }}/showpot:dev | |
- name: Get Github Actions IP | |
id: ip | |
uses: haythem/[email protected] | |
- name: Configure AWS Credentials | |
uses: aws-actions/configure-aws-credentials@v1 | |
with: | |
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY }} | |
aws-secret-access-key: ${{ secrets.AWS_SECRET_KEY }} | |
aws-region: ap-northeast-2 | |
- name: Add Github Actions IP to Security group | |
run: | | |
aws ec2 authorize-security-group-ingress --group-id ${{ secrets.AWS_DEV_SECURITY_GROUP_ID }} --protocol tcp --port 22 --cidr ${{ steps.ip.outputs.ipv4 }}/32 | |
- name: Deploy to EC2 | |
uses: appleboy/[email protected] | |
with: | |
host: ${{ secrets.EC2_DEV_HOST }} | |
username: ec2-user | |
key: ${{ secrets.EC2_DEV_SSH_PRIVATE_KEY }} | |
script: | | |
docker pull ${{ secrets.DOCKERHUB_USERNAME }}/showpot:dev | |
docker stop showpot-dev | |
docker rm showpot-dev | |
docker run -d -p 8080:8080 --name showpot-dev ${{ secrets.DOCKERHUB_USERNAME }}/showpot:dev | |
- name: Remove Github Actions IP From Security Group | |
run: | | |
aws ec2 revoke-security-group-ingress --group-id ${{ secrets.AWS_DEV_SECURITY_GROUP_ID }} --protocol tcp --port 22 --cidr ${{ steps.ip.outputs.ipv4 }}/32 |