blob: 0f3f1ed219851b07e9982ed4e055c0600af79963 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
|
name: Deploy infrastructure
on:
check_suite:
types: [completed]
workflow_dispatch:
jobs:
nixos:
name: Deploy NixOS systems
runs-on: ubuntu-latest
concurrency:
group: deploy
cancel-in-progress: true
# https://github.com/sellout/bash-strict-mode/commit/9bf1d65c2f786a9887facfcb81e06d8b8b5f4667
if: github.event.check_suite.app.name == 'Garnix CI'
&& github.event.check_suite.conclusion == 'success'
&& github.event.check_suite.latest_check_runs_count >= 12
&& github.event.check_suite.head_branch == 'main'
steps:
- uses: actions/checkout@v4
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v9
- name: Setup local Nix cache
uses: DeterminateSystems/magic-nix-cache-action@v2
- name: Connect to Tailscale
uses: tailscale/github-action@v2
with:
oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }}
oauth-secret: ${{ secrets.TS_OAUTH_SECRET }}
tags: tag:gha
- name: Copy known_hosts
run: |
set -eux
[ ! -d ~/.ssh ] && mkdir -p ~/.ssh
cp .known_hosts ~/.ssh/known_hosts
- name: Run deploy
run: |
nix develop --accept-flake-config \
--command just deploy-all
opentofu:
name: Apply OpenTofu plan
needs: nixos
runs-on: ubuntu-latest
concurrency:
group: tofu
cancel-in-progress: true
steps:
- uses: actions/checkout@v4
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v9
- name: Setup local Nix cache
uses: DeterminateSystems/magic-nix-cache-action@v2
- name: Setup OpenTofu
uses: opentofu/setup-opentofu@v1
with:
cli_config_credentials_token: ${{ secrets.TF_API_TOKEN }}
- name: Setup OpenTofu cache
uses: terraform-cache/terraform-cache@v1
- name: Run plan
run: nix run .#plan
- name: Apply
run: tofu apply
|