192 lines
6.0 KiB
YAML
192 lines
6.0 KiB
YAML
name: Auto-PR Check/Creation and TF/OpenTofu Plan
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
push:
|
|
branches-ignore:
|
|
- "main"
|
|
- "renovate/**"
|
|
paths:
|
|
- "cloudflare/**"
|
|
env:
|
|
OPENTOFU_VERSION: "1.10.6"
|
|
HC_VAULT_VERSION: "1.20.4"
|
|
TEA_VERSION: "0.10.1"
|
|
|
|
jobs:
|
|
check-and-create-pr:
|
|
name: Check and Create PR
|
|
outputs:
|
|
pr_number: ${{ steps.pr-check-create.outputs.pr_number }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout Code
|
|
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
|
|
with:
|
|
fetch-depth: 1
|
|
|
|
- name: Setting Vault Token
|
|
run: |
|
|
echo "VAULT_TOKEN=${{ secrets.VAULT_GITEA_TOKEN }}" >> $GITHUB_ENV
|
|
|
|
- name: Gotify Notification
|
|
uses: eikendev/gotify-action@master
|
|
with:
|
|
gotify_api_base: "${{ secrets.RUNNER_GOTIFY_URL }}"
|
|
gotify_app_token: "${{ secrets.RUNNER_GOTIFY_TOKEN }}"
|
|
notification_title: "GITEA: PR Check @ Rinoa"
|
|
notification_message: "Checking for existing PR... 🔍"
|
|
|
|
- name: PR Check/Creation
|
|
id: pr-check-create
|
|
uses: https://git.trez.wtf/Trez/gitea-auto-pr@main
|
|
with:
|
|
url: ${{ secrets.TREZ_GITEA_URL }}
|
|
token: ${{ secrets.BOT_GITEA_TOKEN }}
|
|
pr-label: docker-compose,manual
|
|
assignee: ${{ github.actor }}
|
|
|
|
- name: Gotify Notification
|
|
uses: eikendev/gotify-action@master
|
|
with:
|
|
gotify_api_base: "${{ secrets.RUNNER_GOTIFY_URL }}"
|
|
gotify_app_token: "${{ secrets.RUNNER_GOTIFY_TOKEN }}"
|
|
notification_title: "GITEA: PR Check @ Rinoa"
|
|
notification_message: "PR Check done 🎟️"
|
|
|
|
plan-approval:
|
|
name: OpenTofu Plan
|
|
needs: check-and-create-pr
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
VAULT_TOKEN: ${{ secrets.VAULT_GITEA_TOKEN }}
|
|
outputs:
|
|
tofu-cloudflare-plan: ${{ steps.tofu_plan.outputs.plan-output }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup OpenTofu
|
|
uses: opentofu/setup-opentofu@v1.0.6
|
|
with:
|
|
version: ${{ env.OPENTOFU_VERSION }}
|
|
tofu_wrapper: true
|
|
|
|
- name: Generate .env from Hashicorp Vault
|
|
uses: https://git.trez.wtf/Trez/hc-vault-env@main
|
|
with:
|
|
HC_VAULT_VERSION: ${{ env.HC_VAULT_VERSION }}
|
|
HC_VAULT_ADDR: ${{ secrets.TREZ_VAULT_ADDR }}
|
|
HC_VAULT_AUTH: token
|
|
HC_VAULT_TOKEN: ${{ env.VAULT_TOKEN }}
|
|
HC_VAULT_SECRETS_PATH: tar-valon-terraform/env
|
|
ENV_FILE_NAME: cloudflare/.env
|
|
|
|
- name: Export env vars from Vault .env
|
|
id: env-vault-vars
|
|
run: |
|
|
echo "🧩 Cleaning and loading cloudflare/.env into GitHub Actions environment..."
|
|
|
|
# 1️⃣ Strip any single or double quotes from the file to avoid invalid URIs or extra quoting
|
|
sed -i 's/[\"'\'']//g' cloudflare/.env
|
|
|
|
# 2️⃣ Load all vars into current shell
|
|
set -a
|
|
source cloudflare/.env
|
|
set +a
|
|
|
|
# 3️⃣ Export to GitHub Actions environment
|
|
while IFS='=' read -r key value; do
|
|
if [[ -n "$key" ]]; then
|
|
echo "$key=$value" >> $GITHUB_ENV
|
|
fi
|
|
done < cloudflare/.env
|
|
|
|
repo_name=$(echo "${{ github.repository }}" | awk -F"/" '{print $2}')
|
|
|
|
echo "repo_name=$repo_name" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Run tofu init
|
|
uses: dnogu/tofu-init@v1
|
|
with:
|
|
working-directory: .
|
|
chdir: cloudflare
|
|
|
|
- name: Tofu Plan
|
|
id: tofu_plan
|
|
continue-on-error: true
|
|
uses: dnogu/tofu-plan@v1
|
|
with:
|
|
working-directory: .
|
|
chdir: cloudflare
|
|
out: cloudflare.tfplan
|
|
|
|
- name: PR Comment
|
|
uses: alexnorell/tofu-pr-commenter@v2.0.0
|
|
with:
|
|
commenter_type: plan
|
|
commenter_input: ${{ steps.tofu_plan.outputs.stdout }}
|
|
commenter_exitcode: ${{ steps.step_id.outputs.exitcode }}
|
|
|
|
- name: Wait for manual approval
|
|
uses: trstringer/manual-approval@v1
|
|
with:
|
|
secret: ${{ secrets.BOT_GITEA_TOKEN }}
|
|
approvers: WTF
|
|
minimum-approvals: 1
|
|
issue-title: "Tofu Plan for ${{ env.PR_NUMBER }}"
|
|
issue-body: "Please approve or deny the deployment of the below Tofu plan"
|
|
issue-body-file-path: cloudflare.tfplan
|
|
exclude-workflow-initiator-as-approver: false
|
|
fail-on-denial: true
|
|
additional-approved-words: ''
|
|
additional-denied-words: ''
|
|
|
|
# - name: PR Comment
|
|
# uses: https://git.trez.wtf/Trez.One/git-auto-comment@main
|
|
# env:
|
|
# DEBUG: true
|
|
# with:
|
|
# debug: true
|
|
# platform: gitea
|
|
# api_url: https://git.trez.wtf/api/v1
|
|
# token: ${{ secrets.BOT_GITEA_TOKEN }}
|
|
# pr_index: ${{ needs.check-and-create-pr.outputs.pr_number }}
|
|
# repo_owner: ${{ github.repository_owner }}
|
|
# repo_name: ${{ steps.env-vault-vars.outputs.repo_name }}
|
|
# plan_file: cloudflare/cloudflare.tfplan
|
|
# comment_template: |
|
|
# 🚀 **Tofu Plan Output**
|
|
# ---
|
|
# ${{ steps.tofu_plan.outputs.plan-output }}
|
|
# Exit Code: ${{ steps.tofu_plan.outputs.exitcode }}
|
|
|
|
# apply:
|
|
# name: Apply Tofu Plan
|
|
# needs: approval
|
|
# runs-on: ubuntu-latest
|
|
# if: ${{ needs.approval.result == 'success' }}
|
|
# env:
|
|
# VAULT_TOKEN: ${{ secrets.VAULT_GITEA_TOKEN }}
|
|
# steps:
|
|
# - name: Checkout
|
|
# uses: actions/checkout@v4
|
|
|
|
# - name: Setup OpenTofu
|
|
# uses: opentofu/setup-opentofu@v1.0.6
|
|
# with:
|
|
# version: ${{ env.OPENTOFU_VERSION }}
|
|
# tofu_wrapper: true
|
|
|
|
# - name: Export env from Vault
|
|
# run: |
|
|
# set -a
|
|
# source cloudflare/.env
|
|
# set +a
|
|
|
|
# - name: Run Tofu Apply
|
|
# uses: dnogu/tofu-apply@v1
|
|
# with:
|
|
# working-directory: .
|
|
# chdir: cloudflare
|
|
# plan: cloudflare.tfplan |