name: CI/CD on: push: branches: - main env: REGISTRY: gitea.gitea.svc.cluster.local:3000 K8S_MANIFESTS_REPO: http://chemavx:${{ secrets.CI_TOKEN }}@gitea.gitea.svc.cluster.local:3000/chemavx/k8s-manifests.git GIT_SSL_NO_VERIFY: "true" TELEGRAM_CHAT_ID: "5138407666" jobs: build-and-push: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v4 with: ssl-verify: false - name: Set image tag id: tag run: echo "TAG=${GITHUB_SHA::8}" >> $GITHUB_OUTPUT - name: Log in to registry run: echo "${{ secrets.CI_TOKEN }}" | docker login gitea.gitea.svc.cluster.local:3000 -u chemavx --password-stdin - name: Create buildx builder run: | cat > /tmp/buildkitd.toml << 'EOF' [registry."registry-cache.registry-cache.svc.cluster.local:5000"] http = true insecure = true [registry."gitea.gitea.svc.cluster.local:3000"] http = true insecure = true [registry."docker.io"] mirrors = ["registry-cache.registry-cache.svc.cluster.local:5000"] EOF docker buildx create \ --name ci-builder \ --driver docker-container \ --driver-opt network=host \ --config /tmp/buildkitd.toml \ --use docker buildx inspect --bootstrap - name: Build and push n8n image run: | TAG=${{ steps.tag.outputs.TAG }} docker buildx build \ --builder ci-builder \ --cache-from type=registry,ref=gitea.gitea.svc.cluster.local:3000/chemavx/n8n:buildcache \ --cache-to type=registry,ref=gitea.gitea.svc.cluster.local:3000/chemavx/n8n:buildcache,mode=max \ -t gitea.gitea.svc.cluster.local:3000/chemavx/n8n:${TAG} \ --push \ -f Dockerfile . - name: Verify image in registry run: | TAG=${{ steps.tag.outputs.TAG }} HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" \ -u "chemavx:${{ secrets.CI_TOKEN }}" \ -H "Accept: application/vnd.docker.distribution.manifest.v2+json" \ "http://gitea.gitea.svc.cluster.local:3000/v2/chemavx/n8n/manifests/${TAG}") if [ "$HTTP_CODE" != "200" ]; then echo "ERROR: chemavx/n8n:${TAG} not found in registry (HTTP $HTTP_CODE)" exit 1 fi echo "OK: chemavx/n8n:${TAG} verified in registry" - name: Update k8s manifests run: | TAG=${{ steps.tag.outputs.TAG }} git config --global user.email "ci@git.chemavx.xyz" git config --global user.name "Gitea CI" git clone ${{ env.K8S_MANIFESTS_REPO }} /tmp/k8s-manifests cd /tmp/k8s-manifests sed -i "s|image: .*n8n.*|image: git.chemavx.xyz/chemavx/n8n:${TAG}|g" \ n8n/deployment-n8n.yaml sed -i "s|imagePullPolicy: Always|imagePullPolicy: IfNotPresent|g" \ n8n/deployment-n8n.yaml python3 -c " import yaml, sys try: yaml.safe_load(open('n8n/deployment-n8n.yaml')) print('OK: n8n/deployment-n8n.yaml') except yaml.YAMLError as e: print('FAIL: n8n/deployment-n8n.yaml: ' + str(e), file=sys.stderr) sys.exit(1) " git add n8n/deployment-n8n.yaml git diff --cached --quiet || git commit -m "ci: update n8n image to ${TAG} [skip ci]" git push - name: Notify Telegram if: always() env: TAG: ${{ steps.tag.outputs.TAG }} JOB_STATUS: ${{ job.status }} TELEGRAM_TOKEN: ${{ secrets.TELEGRAM_BOT_TOKEN }} run: | TAG="${TAG:-${GITHUB_SHA:0:8}}" if [ "$JOB_STATUS" = "success" ]; then MSG="✅ Deploy n8n:${TAG} completado" else MSG="❌ Deploy n8n:${TAG} fallido (status: ${JOB_STATUS})" fi curl -s -X POST "https://api.telegram.org/bot${TELEGRAM_TOKEN}/sendMessage" \ -d "chat_id=${{ env.TELEGRAM_CHAT_ID }}" \ --data-urlencode "text=${MSG}"