Skip to content

Merge pull request #37 from center-for-threat-informed-defense/TIE-78… #54

Merge pull request #37 from center-for-threat-informed-defense/TIE-78…

Merge pull request #37 from center-for-threat-informed-defense/TIE-78… #54

Workflow file for this run

name: Build Website
on:
push:
branches: [main]
paths:
- 'src/**'
- 'data/**/*.json'
pull_request:
paths:
- 'src/**'
- 'data/**/*.json'
workflow_dispatch:
# If another web build starts for the same branch, cancel the previous build. This
# protects us from two builds trying to upload at the same time and clobbering each
# other.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
id-token: write
pages: write
pull-requests: write
jobs:
tie_website_build:
runs-on: ubuntu-latest
env:
BRANCH_NAME: ${{ github.head_ref || github.ref_name }}
steps:
# Configure Environment
- uses: actions/checkout@v3
# Configure Node
- uses: actions/setup-node@v3
id: "setup-node"
with:
node-version: '19'
cache: 'npm'
cache-dependency-path: 'src/tie-web-interface/package-lock.json'
- name: Install dependencies
working-directory: src/tie-web-interface/
run: npm ci
# Lint
- name: Lint
working-directory: src/tie-web-interface/
run: npm run lint
# Run Type Checks
- name: Type Check
working-directory: src/tie-web-interface/
run: npm run type-check
# Configure Python
- uses: actions/setup-python@v4
with:
python-version: '3.11.8'
- name: Install Poetry
run: curl -sSL https://install.python-poetry.org/ | python -
- name: Add Poetry to PATH
run: echo "$HOME/.poetry/bin" >> $GITHUB_PATH
- name: Install dependencies
run: poetry install
# Train Model
- name: Retrain Technique Inference Engine Model
working-directory: src/tie-web-interface/
run: npm run build-model
# Build Website
- name: Compile Website
working-directory: src/tie-web-interface/
run: npm run build-only -- --base /$BRANCH_NAME/
- name: Upload artifact
uses: actions/upload-artifact@v3
with:
name: tie_website
path: src/tie-web-interface/dist/
# Publish to Azure blob only on PRs, not main.
azure_blob:
needs: tie_website_build
runs-on: ubuntu-latest
env:
AZURE_STORAGE_ACCOUNT: techniqueinferenceengine
AZURE_STORAGE_SAS_TOKEN: ${{ secrets.AZURE_SAS_TOKEN }}
BRANCH_NAME: ${{ github.head_ref || github.ref_name }}
STATICRYPT_PASS: ${{ secrets.STATICRYPT_PASS }}
steps:
- uses: actions/setup-node@v3
with:
node-version: "19"
- run: npm install -g staticrypt
- name: Download Web Site
uses: actions/download-artifact@v3
with:
name: tie_website
path: tie_website
- env:
STATICRYPT_PASS: ${{ secrets.STATICRYPT_PASS }}
run: >
staticrypt --remember 3 --salt b1c18fbb5081eca3e2db08a413b01774 \
--password $STATICRYPT_PASS --short \
--template-title "Technique Inference Engine (branch: $BRANCH_NAME)" \
--template-instructions "The contents of this site are marked TLP:AMBER:CTID-R&D:22-80. Do not share with unauthorized individuals." \
--template-color-primary "#6241c5" \
--template-color-secondary "#b2b2b2" \
--template-button "Log In" \
-r tie_website/
- name: Ensure StatiCrypt ran # StatiCrypt will fail without warning; verify it created a directory
run: test -d encrypted
- name: Copy encrypted HTML files
run: rsync -Ir -v --include='*.html' --exclude='*.*' encrypted/tie_website .
- name: Set the branch name
run: mv tie_website "$BRANCH_NAME"
- name: Install Azure CLI
run: curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
- name: Delete old blobs
run: az storage blob delete-batch -s '$web' --pattern "$BRANCH_NAME/*"
- name: Upload to blob storage
run: az storage blob upload-batch -s . --pattern "$BRANCH_NAME/*" -d '$web'
- uses: actions/github-script@v6
if: github.event_name == 'pull_request'
with:
script: |
github.rest.issues.createComment({
issue_number: context.issue.number,
owner: context.repo.owner,
repo: context.repo.repo,
body: `This PR has been published to https://techniqueinferenceengine.z13.web.core.windows.net/${process.env['BRANCH_NAME']}/`,
})
# github_pages:
# # This job only runs when committing or merging to main branch.
# if: github.ref_name == 'main'
# needs: tie_website_build
# runs-on: ubuntu-latest
# environment:
# name: github-pages
# url: $\{\{ steps.deployment.outputs.page_url \}\}
# steps:
# - name: Setup Pages
# uses: actions/configure-pages@v2
# - name: Download Web Site
# uses: actions/download-artifact@v3
# with:
# name: tie_website
# path: tie_website
# - name: Upload artifact
# uses: actions/upload-pages-artifact@v1
# with:
# path: ./tie_website
# - name: Deploy to GitHub Pages
# id: deployment
# uses: actions/deploy-pages@v1