Skip to content

Commit a4aa9b5

Browse files
committed
Updated deployments to use secrets directly to avoid odd masking behaviour
1 parent 34ce4f2 commit a4aa9b5

File tree

3 files changed

+15
-23
lines changed

3 files changed

+15
-23
lines changed

.github/workflows/deploy_nccrd.saeon.ac.za.yml

Lines changed: 13 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,6 @@ on:
44
workflow_dispatch:
55

66
env:
7-
SWARM_HOSTNAME: ${{ secrets.SWARM_HOSTNAME }} # Organization secret
8-
SWARM_USERNAME: ${{ secrets.SWARM_USERNAME }} # Organization secret
9-
SWARM_PASSWORD: ${{ secrets.SWARM_PASSWORD }} # Organization secret
10-
SWARM_SSH_PORT: ${{ secrets.SWARM_SSH_PORT }} # Organization secret
11-
MSSQL_PASSWORD: ${{ secrets.MSSQL_PASSWORD_NEXT }} # Repository secret
12-
MSSQL_USERNAME: ${{ secrets.MSSQL_USERNAME_NEXT }} # Repository secret
13-
ODP_AUTH_CLIENT_SECRET: ${{ secrets.ODP_AUTH_CLIENT_SECRET }} # Repository secret
14-
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
157
NCCRD_IMAGE_NAME: ${{ github.repository }}_next_node
168
NGINX_IMAGE_NAME: ${{ github.repository }}_next_nginx
179
REGISTRY: ghcr.io
@@ -33,7 +25,7 @@ jobs:
3325
with:
3426
registry: ${{ env.REGISTRY }}
3527
username: ${{ github.actor }}
36-
password: ${{ env.GITHUB_TOKEN }}
28+
password: ${{ secrets.GITHUB_TOKEN }}
3729

3830
- name: Extract metadata (tags, labels) for Docker
3931
id: meta
@@ -66,7 +58,7 @@ jobs:
6658
with:
6759
registry: ${{ env.REGISTRY }}
6860
username: ${{ github.actor }}
69-
password: ${{ env.GITHUB_TOKEN }}
61+
password: ${{ secrets.GITHUB_TOKEN }}
7062

7163
- name: Extract metadata (tags, labels) for Docker
7264
id: meta
@@ -101,24 +93,24 @@ jobs:
10193
- name: (SCP) Copy Docker files to app server
10294
uses: appleboy/scp-action@master
10395
with:
104-
host: ${{ env.SWARM_HOSTNAME }}
105-
username: ${{ env.SWARM_USERNAME }}
106-
password: ${{ env.SWARM_PASSWORD }}
107-
port: ${{ env.SWARM_SSH_PORT }}
96+
host: ${{ secrets.SWARM_HOSTNAME }}
97+
username: ${{ secrets.SWARM_USERNAME }}
98+
password: ${{ secrets.SWARM_PASSWORD }}
99+
port: ${{ secrets.SWARM_SSH_PORT }}
108100
source: 'deploy/next/stack.yml'
109101
target: 'nccrd-next'
110102

111103
- name: (SSH) Deploy Docker stack
112104
uses: appleboy/ssh-action@master
113105
with:
114-
host: ${{ env.SWARM_HOSTNAME }}
115-
username: ${{ env.SWARM_USERNAME }}
116-
password: ${{ env.SWARM_PASSWORD }}
117-
port: ${{ env.SWARM_SSH_PORT }}
106+
host: ${{ secrets.SWARM_HOSTNAME }}
107+
username: ${{ secrets.SWARM_USERNAME }}
108+
password: ${{ secrets.SWARM_PASSWORD }}
109+
port: ${{ secrets.SWARM_SSH_PORT }}
118110
script: |
119-
echo "MSSQL_PASSWORD=${{ env.MSSQL_PASSWORD }}" > /home/runner/nccrd-next/deploy/next/stack.env
120-
echo "MSSQL_USERNAME=${{ env.MSSQL_USERNAME }}" >> /home/runner/nccrd-next/deploy/next/stack.env
111+
echo "MSSQL_PASSWORD=${{ secrets.MSSQL_PASSWORD_NEXT }}" > /home/runner/nccrd-next/deploy/next/stack.env
112+
echo "MSSQL_USERNAME=${{ secrets.MSSQL_USERNAME_NEXT }}" >> /home/runner/nccrd-next/deploy/next/stack.env
121113
echo "NCCRD_IMAGE=${{ needs.build-nccrd.outputs.image }}" >> /home/runner/nccrd-next/deploy/next/stack.env
122114
echo "NGINX_IMAGE=${{ needs.build-nginx.outputs.image }}" >> /home/runner/nccrd-next/deploy/next/stack.env
123-
echo "ODP_AUTH_CLIENT_SECRET=${{ env.ODP_AUTH_CLIENT_SECRET }}" >> /home/runner/nccrd-next/deploy/next/stack.env
115+
echo "ODP_AUTH_CLIENT_SECRET=${{ secrets.ODP_AUTH_CLIENT_SECRET }}" >> /home/runner/nccrd-next/deploy/next/stack.env
124116
sudo /opt/deploy-docker-stack.sh /home/runner/nccrd-next/deploy/next/stack.yml /home/runner/nccrd-next/deploy/next/stack.env nccrd_next

deploy/next/stack.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
version: '3.8'
1+
version: '3.9'
22

33
volumes:
44
nccrd_next:

deploy/stable/stack.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
version: '3.8'
1+
version: '3.9'
22

33
volumes:
44
nccrd_stable:

0 commit comments

Comments
 (0)