name: Docker Compose Deploy on: push: branches: - main # Manual re-run, for redeploying after a rollback or re-creating the # workspace .env that the cleanup step below now removes. workflow_dispatch: permissions: contents: read jobs: build_and_deploy: runs-on: [self-hosted, linux] # SEC-01: this gates nothing until required reviewers are configured on the # "production" environment itself. See the pull request description. environment: production steps: - name: Checkout code uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: clean: true fetch-depth: 1 - name: Create environment file working-directory: ${{ github.workspace }} env: DOT_ENV: ${{ secrets.DOT_ENV }} run: | if [ -z "$DOT_ENV" ]; then echo "DOT_ENV secret is missing or empty." exit 1 fi umask 077 printf '%s\n' "$DOT_ENV" > .env - name: Build and deploy working-directory: ${{ github.workspace }} run: | sudo docker compose up -d --build --force-recreate echo "Deployment complete." - name: Remove environment file if: always() working-directory: ${{ github.workspace }} run: rm -f .env - name: Clean up old Docker images run: sudo docker image prune -f