Skip to content

Deploy Relayers to Mainnet - v2.6.0 by @mpetrun5 #20

Deploy Relayers to Mainnet - v2.6.0 by @mpetrun5

Deploy Relayers to Mainnet - v2.6.0 by @mpetrun5 #20

# The Licensed Work is (c) 2022 Sygma
# SPDX-License-Identifier: BUSL-1.1
name: Sygma Mainnet
on:
workflow_dispatch:
inputs:
release_tag:
description: 'The Release tag Version'
required: true
type: string
TOKEN:
description: 'Authentication token'
required: true
type: string
run-name: Deploy Relayers to Mainnet - ${{ inputs.release_tag }} by @${{ github.actor }}
env:
ENVIRONMENT: 'MAINNET'
REGISTRY: 'ghcr.io'
jobs:
######################## region 1 ########################
deploy_region_1:
name: deploy
runs-on: ubuntu-latest
environment: mainnet
strategy:
matrix:
relayer_id: [0, 1]
env:
AWS_MAINNET: '${{ secrets.AWS_MAINNET }}'
permissions:
contents: read
id-token: write
steps:
- name: Authentication
id: auth
run: |
if [ "${{ secrets.AUTH_TOKEN }}" != "${{ github.event.inputs.TOKEN }}" ]; then
echo "Authentcation failed. Exiting..."
exit 1
fi
- name: Continue
if: steps.auth.outcome == 'success'
run: |
echo 'Authentication Succeeded!!!'
- name: checkout ecs repo
uses: actions/checkout@v3
with:
repository: sygmaprotocol/devops
token: ${{ secrets.GHCR_TOKEN }}
- name: render jinja2 templates to task definition json files
uses: cuchi/[email protected]
with:
template: 'relayers/ecs/task_definition-${{ env.ENVIRONMENT }}.j2'
output_file: 'relayers/ecs/task_definition-${{ matrix.relayer_id }}_${{ env.ENVIRONMENT }}.json'
data_format: json
variables: |
relayerId=${{ matrix.relayer_id }}
awsAccountId=${{ env.AWS_MAINNET }}
awsRegion=${{ secrets.AWS_REGION_1 }}
imageTag=${{ inputs.release_tag }}
awsEnv=${{ env.ENVIRONMENT }}
awsEfs=${{ secrets.MAINNET_EFS_1 }}
- name: configure aws credentials
uses: aws-actions/configure-aws-credentials@v1
with:
role-to-assume: arn:aws:iam::${{ env.AWS_MAINNET }}:role/github-actions-${{ env.ENVIRONMENT }}-chainbridge
aws-region: ${{ secrets.AWS_REGION_1 }}
role-session-name: GithubActions
- name: deploy task definition
uses: aws-actions/amazon-ecs-deploy-task-definition@v1
with:
task-definition: 'relayers/ecs/task_definition-${{ matrix.relayer_id }}_${{ env.ENVIRONMENT }}.json'
service: 'relayer-${{ matrix.relayer_id }}-service-${{ env.ENVIRONMENT }}'
cluster: 'relayer-${{ env.ENVIRONMENT }}'
wait-for-service-stability: true
- name: slack notify
uses: 8398a7/action-slack@v3
with:
status: ${{ job.status }}
fields: repo,message,commit,author,action,job,eventName,ref,workflow
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} # required
if: always()
######################## region 3 ########################
deploy_region_3:
name: deploy
runs-on: ubuntu-latest
environment: mainnet
strategy:
matrix:
relayer_id: [2]
env:
AWS_MAINNET: '${{ secrets.AWS_MAINNET }}'
permissions:
contents: read
id-token: write
steps:
- name: Authentication
id: auth
run: |
if [ "${{ secrets.AUTH_TOKEN }}" != "${{ github.event.inputs.TOKEN }}" ]; then
echo "Authentcation failed. Exiting..."
exit 1
fi
- name: Continue
if: steps.auth.outcome == 'success'
run: |
echo 'Authentication Succeeded!!!'
- name: checkout ecs repo
uses: actions/checkout@v3
with:
repository: sygmaprotocol/devops
token: ${{ secrets.GHCR_TOKEN }}
- name: render jinja2 templates to task definition json files
uses: cuchi/[email protected]
with:
template: 'relayers/ecs/task_definition-${{ env.ENVIRONMENT }}.j2'
output_file: 'relayers/ecs/task_definition-${{ matrix.relayer_id }}_${{ env.ENVIRONMENT }}.json'
data_format: json
variables: |
relayerId=${{ matrix.relayer_id }}
awsAccountId=${{ env.AWS_MAINNET }}
awsRegion=${{ secrets.AWS_REGION_3 }}
imageTag=${{ inputs.release_tag }}
awsEnv=${{ env.ENVIRONMENT }}
awsEfs=${{ secrets.MAINNET_EFS_3 }}
- name: configure aws credentials
uses: aws-actions/configure-aws-credentials@v1
with:
role-to-assume: arn:aws:iam::${{ env.AWS_MAINNET }}:role/github-actions-${{ env.ENVIRONMENT }}-chainbridge
aws-region: ${{ secrets.AWS_REGION_3 }}
role-session-name: GithubActions
- name: deploy task definition
uses: aws-actions/amazon-ecs-deploy-task-definition@v1
with:
task-definition: 'relayers/ecs/task_definition-${{ matrix.relayer_id }}_${{ env.ENVIRONMENT }}.json'
service: 'relayer-${{ matrix.relayer_id }}-service-${{ env.ENVIRONMENT }}'
cluster: 'relayer-${{ env.ENVIRONMENT }}'
wait-for-service-stability: true
- name: slack notify
uses: 8398a7/action-slack@v3
with:
status: ${{ job.status }}
fields: repo,message,commit,author,action,job,eventName,ref,workflow
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} # required
if: always()