Merge pull request #33 from Nook-Book/develop #5
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Deploy to Amazon EC2 | |
on: | |
push: | |
branches: | |
- main | |
# νκ²½ λ³μ μ€μ | |
env: | |
AWS_REGION: ap-northeast-2 | |
S3_BUCKET_NAME: nookbook-deploy-bucket | |
CODE_DEPLOY_APPLICATION_NAME: nookbook-codedeploy-app | |
CODE_DEPLOY_DEPLOYMENT_GROUP_NAME: nookbook-deployment-group | |
permissions: | |
contents: read | |
jobs: | |
deploy: | |
name: Deploy | |
runs-on: ubuntu-latest | |
environment: production | |
steps: | |
- name: Checkout | |
uses: actions/checkout@v4 | |
# JDK 17 μΈν | |
- name: Set up JDK 17 | |
uses: actions/setup-java@v4 | |
with: | |
distribution: 'temurin' | |
java-version: '17' | |
# gradle μΊμ± | |
- name: Gradle Caching | |
uses: actions/cache@v4 | |
with: | |
path: | | |
~/.gradle/caches | |
~/.gradle/wrapper | |
key: ${{ runner.os }}-gradle-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }} | |
restore-keys: | | |
${{ runner.os }}-gradle- | |
# νμΌ μμ± | |
- name: create files | |
run: | | |
cd ./src/main/resources | |
# nook-book-service.json μμ± | |
touch ./nook-book-service.json | |
echo "${{ secrets.NOOK_BOOK_SERVICE_JSON }}" | base64 --decode > ./nook-book-service.json | |
echo "GOOGLE_APPLICATION_CREDENTIALS=./nook-book-service.json" >> $GITHUB_ENV | |
# database λλ ν 리 λ° νμΌ μμ± | |
mkdir -p ./database | |
touch ./database/application-database.yml | |
echo "${{ secrets.APPLICATION_DATABASE_YML }}" | base64 --decode > ./database/application-database.yml | |
# book λλ ν 리 λ° νμΌ μμ± | |
mkdir -p ./book | |
touch ./book/application-book.yml | |
echo "${{ secrets.APPLICATION_BOOK_YML }}" | base64 --decode > ./book/application-book.yml | |
# s3 λλ ν 리 λ° νμΌ μμ± | |
mkdir -p ./s3 | |
touch ./s3/application-s3.yml | |
echo "${{ secrets.APPLICATION_S3_YML }}" | base64 --decode > ./s3/application-s3.yml | |
# oauth2 λλ ν 리 λ° νμΌ μμ± | |
mkdir -p ./oauth2 | |
touch ./oauth2/application-oauth2.yml | |
echo "${{ secrets.APPLICATION_OAUTH2_YML }}" | base64 --decode > ./oauth2/application-oauth2.yml | |
# vision λλ ν 리 λ° νμΌ μμ± | |
mkdir -p ./vision | |
touch ./vision/application-vision.yml | |
echo "${{ secrets.APPLICATION_VISION_YML }}" | base64 --decode > ./vision/application-vision.yml | |
# webclient λλ ν 리 λ° νμΌ μμ± | |
mkdir -p ./webclient | |
touch ./webclient/application-webclient.yml | |
echo "${{ secrets.APPLICATION_WEBCLIENT_YML }}" | base64 --decode > ./webclient/application-webclient.yml | |
# κΆν λΆμ¬ | |
- name: Grant execute permission for gradlew | |
run: chmod +x ./gradlew | |
# Gradle build (Test μ μΈ) | |
- name: Build with Gradle | |
run: ./gradlew clean build -x test | |
# AWS μΈμ¦ (IAM μ¬μ©μ Access Key, Secret Key νμ©) | |
- name: Configure AWS credentials | |
uses: aws-actions/configure-aws-credentials@v1 | |
with: | |
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY }} | |
aws-secret-access-key: ${{ secrets.AWS_SECRET_KEY }} | |
aws-region: ${{ env.AWS_REGION }} | |
# λΉλ κ²°κ³Όλ¬Όμ S3 λ²ν·μ μ λ‘λ | |
- name: Upload to AWS S3 | |
run: | | |
aws deploy push \ | |
--application-name ${{ env.CODE_DEPLOY_APPLICATION_NAME }} \ | |
--ignore-hidden-files \ | |
--s3-location s3://$S3_BUCKET_NAME/$GITHUB_SHA.zip \ | |
--source . | |
# S3 λ²ν·μ μλ νμΌμ λμμΌλ‘ CodeDeploy μ€ν | |
- name: Deploy to AWS EC2 from S3 | |
run: | | |
aws deploy create-deployment \ | |
--application-name ${{ env.CODE_DEPLOY_APPLICATION_NAME }} \ | |
--deployment-config-name CodeDeployDefault.AllAtOnce \ | |
--deployment-group-name ${{ env.CODE_DEPLOY_DEPLOYMENT_GROUP_NAME }} \ | |
--s3-location bucket=$S3_BUCKET_NAME,key=$GITHUB_SHA.zip,bundleType=zip |