mirror of
https://github.com/ever-co/ever-gauzy.git
synced 2026-10-02 01:54:50 +08:00
* feat(config): add individual Redis connection environment variables - Add REDIS_HOST, REDIS_PORT, REDIS_USER, REDIS_PASSWORD to all env files - Support flexible Redis configuration alongside REDIS_URL - Allow connection via individual parameters or single URL * feat(docker): add Redis env vars to Dockerfiles - Add REDIS_ENABLED, REDIS_HOST, REDIS_PORT, REDIS_USER, REDIS_PASSWORD as build args and env vars - Update API, MCP, and MCP-Auth Dockerfiles - Enable flexible Redis configuration in containerized deployments * feat(k8s): add Redis env vars to Kubernetes manifests - Add REDIS_ENABLED, REDIS_HOST, REDIS_PORT, REDIS_USER, REDIS_PASSWORD to all k8s deployments - Update manifests for prod, stage, and demo environments - Support flexible Redis configuration in Kubernetes (Civo, CW, DO) - Apply to API, MCP, and MCP-Auth deployments * feat(deploy): add Redis env vars to Docker Compose templates - Add REDIS_ENABLED, REDIS_HOST, REDIS_PORT, REDIS_USER, REDIS_PASSWORD to compose templates - Update templates for Cloudflare and Let's Encrypt deployments - Apply to prod, stage, and demo environments - Enable flexible Redis configuration in SSH-based deployments * feat(ci): add Redis env vars to GitHub workflows - Add REDIS_ENABLED, REDIS_HOST, REDIS_PORT, REDIS_USER, REDIS_PASSWORD to deployment workflows - Update workflows for Civo, CW, and DigitalOcean deployments - Apply to API, MCP, and MCP-Auth deployment pipelines - Support flexible Redis configuration in CI/CD * feat(do): add Redis env vars to DigitalOcean App Platform config - Add REDIS_ENABLED, REDIS_HOST, REDIS_PORT, REDIS_USER, REDIS_PASSWORD to app.yaml - Enable flexible Redis configuration for DO App Platform deployments * add redis_tls
57 lines
2.3 KiB
YAML
57 lines
2.3 KiB
YAML
name: Deploy MCP Auth to DigitalOcean Prod
|
|
|
|
on:
|
|
workflow_run:
|
|
workflows: ['Build and Publish Gauzy MCP Auth Image Prod']
|
|
branches: [master]
|
|
types:
|
|
- completed
|
|
|
|
jobs:
|
|
deploy-mcp-auth-prod:
|
|
runs-on: buildjet-4vcpu-ubuntu-2204
|
|
|
|
environment: prod
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Install doctl
|
|
uses: digitalocean/action-doctl@v2
|
|
with:
|
|
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}
|
|
|
|
- name: Log in to DigitalOcean Container Registry with short-lived credentials
|
|
run: doctl registry login --expiry-seconds 600
|
|
|
|
- name: Save DigitalOcean kubeconfig with short-lived credentials
|
|
run: doctl kubernetes cluster kubeconfig save --expiry-seconds 600 k8s-gauzy
|
|
|
|
- name: Generate TLS Secrets for MCP Auth Prod
|
|
run: |
|
|
rm -f ${HOME}/ingress.mcpauth.crt ${HOME}/ingress.mcpauth.key
|
|
echo ${{ secrets.INGRESS_API_CERT }} | base64 --decode > ${HOME}/ingress.mcpauth.crt
|
|
echo ${{ secrets.INGRESS_API_CERT_KEY }} | base64 --decode > ${HOME}/ingress.mcpauth.key
|
|
kubectl create secret tls mcpauth.gauzy.co-tls --save-config --dry-run=client --cert=${HOME}/ingress.mcpauth.crt --key=${HOME}/ingress.mcpauth.key -o yaml | kubectl apply -f -
|
|
|
|
- name: Apply k8s manifests changes in DigitalOcean k8s cluster (if any)
|
|
run: |
|
|
envsubst < $GITHUB_WORKSPACE/.deploy/k8s/k8s-manifest.mcp-auth.prod.yaml | kubectl --context do-sfo2-k8s-gauzy apply -f -
|
|
env:
|
|
MCP_AUTH_PORT: '3003'
|
|
MCP_AUTH_SESSION_SECRET: '${{ secrets.MCP_AUTH_SESSION_SECRET_PROD }}'
|
|
MCP_AUTH_JWT_ISSUER: '${{ secrets.MCP_AUTH_JWT_ISSUER }}'
|
|
MCP_AUTH_JWT_AUDIENCE: '${{ secrets.MCP_AUTH_JWT_AUDIENCE_PROD }}'
|
|
REDIS_ENABLED: '${{ secrets.REDIS_ENABLED }}'
|
|
REDIS_URL: '${{ secrets.REDIS_URL }}'
|
|
REDIS_HOST: '${{ secrets.REDIS_HOST }}'
|
|
REDIS_PASSWORD: '${{ secrets.REDIS_PASSWORD }}'
|
|
REDIS_PORT: '${{ secrets.REDIS_PORT }}'
|
|
REDIS_USER: '${{ secrets.REDIS_USER }}'
|
|
REDIS_TLS: '${{ secrets.REDIS_TLS }}'
|
|
|
|
- name: Restart Pods to pick up :latest tag version
|
|
run: |
|
|
kubectl --context do-sfo2-k8s-gauzy rollout restart deployment/gauzy-mcp-auth-prod
|