when: - event: push branch: master clone: git: image: woodpeckerci/plugin-git settings: attempts: 5 backoff: 10s steps: - name: install-api-deps image: python:3.13-slim commands: - apt-get update && apt-get install -y --no-install-recommends libglib2.0-0 - python -m venv .venv - .venv/bin/pip install --quiet --upgrade pip - >- .venv/bin/pip install --quiet pytest pytest-asyncio pytest-cov httpx fakeredis aioresponses fastapi uvicorn sqlmodel sqlalchemy alembic pyjwt cryptography celery redis click aiohttp aiohttp-socks pillow numpy pytesseract opentelemetry-api opentelemetry-sdk opentelemetry-exporter-prometheus opentelemetry-instrumentation-fastapi opentelemetry-instrumentation-sqlalchemy python-dotenv webauthn apprise tenacity prometheus-client email-validator opencv-python-headless tqdm pandas cachetools watchdog - name: test-unit image: python:3.13-slim depends_on: - install-api-deps commands: - apt-get update && apt-get install -y --no-install-recommends libglib2.0-0 - .venv/bin/pytest tests/unit/ -v --tb=short - name: test-integration image: python:3.13-slim depends_on: - install-api-deps commands: - apt-get update && apt-get install -y --no-install-recommends libglib2.0-0 - .venv/bin/pytest tests/integration/ tests/regression/ tests/e2e/ tests/test_listing_geojson.py -v --tb=short - name: build-api-image image: plugins/docker environment: DOCKER_BUILDKIT: 1 settings: username: viktorbarzin password: from_secret: dockerhub-token repo: viktorbarzin/realestatecrawler dockerfile: Dockerfile context: . target: production cache_from: - viktorbarzin/realestatecrawler:latest - viktorbarzin/realestatecrawler:builder tags: - "build-${CI_PIPELINE_NUMBER}" - name: publish-api-image image: alpine depends_on: - test-unit - test-integration - build-api-image environment: DOCKERHUB_TOKEN: from_secret: dockerhub-token commands: - apk add --no-cache skopeo - 'skopeo copy --src-creds "viktorbarzin:$DOCKERHUB_TOKEN" --dest-creds "viktorbarzin:$DOCKERHUB_TOKEN" "docker://docker.io/viktorbarzin/realestatecrawler:build-${CI_PIPELINE_NUMBER}" "docker://docker.io/viktorbarzin/realestatecrawler:${CI_PIPELINE_NUMBER}"' - 'skopeo copy --src-creds "viktorbarzin:$DOCKERHUB_TOKEN" --dest-creds "viktorbarzin:$DOCKERHUB_TOKEN" "docker://docker.io/viktorbarzin/realestatecrawler:build-${CI_PIPELINE_NUMBER}" "docker://docker.io/viktorbarzin/realestatecrawler:latest"' - 'skopeo copy --src-creds "viktorbarzin:$DOCKERHUB_TOKEN" --dest-creds "viktorbarzin:$DOCKERHUB_TOKEN" "docker://docker.io/viktorbarzin/realestatecrawler:build-${CI_PIPELINE_NUMBER}" "docker://docker.io/viktorbarzin/realestatecrawler:builder"' - name: update-deployment image: alpine depends_on: - publish-api-image commands: - apk add --no-cache curl jq - | TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token) IMAGE="viktorbarzin/realestatecrawler:${CI_PIPELINE_NUMBER}" RESTART_AT=$(date -u +%Y-%m-%dT%H:%M:%SZ) API="https://kubernetes:6443/apis/apps/v1/namespaces/realestate-crawler/deployments" for DEPLOY in realestate-crawler-api realestate-crawler-celery realestate-crawler-celery-beat; do STATUS=$(curl -sfk "$API/$DEPLOY" \ -H "Authorization: Bearer $TOKEN" \ -H "Accept: application/json") CONTAINER=$(echo "$STATUS" | jq -r '.spec.template.spec.containers[0].name') PAUSED=$(echo "$STATUS" | jq -r '.spec.paused // false') echo "Patching $DEPLOY (container=$CONTAINER, paused=$PAUSED) to image $IMAGE..." curl -sf -X PATCH "$API/$DEPLOY" \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/strategic-merge-patch+json" \ -k -d "{\"spec\":{\"paused\":null,\"template\":{\"metadata\":{\"annotations\":{\"kubectl.kubernetes.io/restartedAt\":\"$RESTART_AT\"}},\"spec\":{\"containers\":[{\"name\":\"$CONTAINER\",\"image\":\"$IMAGE\"}]}}}}" \ | jq '{name: .metadata.name, generation: .metadata.generation, image: .spec.template.spec.containers[0].image, paused: .spec.paused, restartedAt: .spec.template.metadata.annotations["kubectl.kubernetes.io/restartedAt"]}' done - name: verify-deploy image: alpine depends_on: - update-deployment commands: - apk add --no-cache curl jq - | TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token) EXPECTED_IMAGE="viktorbarzin/realestatecrawler:${CI_PIPELINE_NUMBER}" BASE_API="https://kubernetes:6443/api/v1/namespaces/realestate-crawler/pods" DEPLOY_API="https://kubernetes:6443/apis/apps/v1/namespaces/realestate-crawler/deployments" for DEPLOY in realestate-crawler-api realestate-crawler-celery realestate-crawler-celery-beat; do echo "Verifying $DEPLOY..." PODS_API="$BASE_API?labelSelector=app%3D$DEPLOY" RS_API="https://kubernetes:6443/apis/apps/v1/namespaces/realestate-crawler/replicasets?labelSelector=app%3D$DEPLOY" DEPLOY_STATUS=$(curl -sfk "$DEPLOY_API/$DEPLOY" \ -H "Authorization: Bearer $TOKEN" \ -H "Accept: application/json") echo " Deployment spec image: $(echo "$DEPLOY_STATUS" | jq -r '.spec.template.spec.containers[0].image')" echo " Deployment paused: $(echo "$DEPLOY_STATUS" | jq -r '.spec.paused // false')" echo " Deployment status: replicas=$(echo "$DEPLOY_STATUS" | jq -r '.status.replicas // 0') updated=$(echo "$DEPLOY_STATUS" | jq -r '.status.updatedReplicas // 0') ready=$(echo "$DEPLOY_STATUS" | jq -r '.status.readyReplicas // 0') unavailable=$(echo "$DEPLOY_STATUS" | jq -r '.status.unavailableReplicas // 0')" echo " Conditions:" echo "$DEPLOY_STATUS" | jq -r '.status.conditions[]? | " \(.type): \(.status) (\(.reason // "unknown"))"' 2>/dev/null || echo " (none)" echo " ReplicaSets:" curl -sfk "$RS_API" \ -H "Authorization: Bearer $TOKEN" \ -H "Accept: application/json" | \ jq -r '.items[] | " \(.metadata.name) desired=\(.spec.replicas) ready=\(.status.readyReplicas // 0) image=\(.spec.template.spec.containers[0].image)"' 2>/dev/null || echo " (none)" FOUND=0 for i in $(seq 1 60); do RAW=$(curl -sfk "$PODS_API" \ -H "Authorization: Bearer $TOKEN" \ -H "Accept: application/json") if [ "$i" -eq 1 ] || [ "$i" -eq 10 ] || [ "$i" -eq 30 ]; then echo " DEBUG (attempt $i): All pods for $DEPLOY:" echo "$RAW" | jq -r '[.items[] | { name: .metadata.name, image: .spec.containers[0].image, ready: ([.status.containerStatuses[]? | .ready] | first // "unknown"), phase: .status.phase, restarts: ([.status.containerStatuses[]? | .restartCount] | first // 0), reason: ([.status.containerStatuses[]? | .state | to_entries[] | .value.reason // empty] | first // "running") }] | .[] | " \(.name) image=\(.image) ready=\(.ready) phase=\(.phase) restarts=\(.restarts) reason=\(.reason)"' 2>/dev/null || echo " (no pods or parse error)" fi RESULT=$(echo "$RAW" | \ jq --arg img "$EXPECTED_IMAGE" '[.items[] | select( (.status.containerStatuses[]? | .ready == true) and (.spec.containers[]? | .image | endswith($img)) ) | {name: .metadata.name, image: .spec.containers[0].image, started: .status.startTime}]') COUNT=$(echo "$RESULT" | jq 'length' 2>/dev/null || echo 0) echo " Attempt $i/60: $COUNT pod(s) ready with image matching $EXPECTED_IMAGE" if [ "$COUNT" -gt 0 ] 2>/dev/null; then echo "$RESULT" | jq -r '.[] | " \(.name) image=\(.image) started=\(.started)"' echo "$DEPLOY is live!" FOUND=1 break fi sleep 5 done if [ "$FOUND" -ne 1 ]; then echo " FINAL DEBUG: All pods for $DEPLOY:" echo "$RAW" | jq -r '[.items[] | { name: .metadata.name, image: .spec.containers[0].image, ready: ([.status.containerStatuses[]? | .ready] | first // "unknown"), phase: .status.phase, restarts: ([.status.containerStatuses[]? | .restartCount] | first // 0), reason: ([.status.containerStatuses[]? | .state | to_entries[] | .value.reason // empty] | first // "running") }] | .[] | " \(.name) image=\(.image) ready=\(.ready) phase=\(.phase) restarts=\(.restarts) reason=\(.reason)"' 2>/dev/null || echo " (no pods or parse error)" echo "ERROR: No new ready pod for $DEPLOY with image $EXPECTED_IMAGE appeared within 5 minutes" exit 1 fi done