mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
feat(ci): run db migrations from github ci with environment-scoped secrets (#4957)
* feat(ci): run db migrations from github ci with environment-scoped secrets
* fix(ci): pass environment input via env var instead of shell interpolation
* fix(ci): rename migration environments to db-* to avoid collision with Vercel's Production env
* improvement(ci): resolve migration db url from prefixed repo secrets, drop github environments
* fix(ci): dev migrations use db:push only, matching previous behavior
* improvement(ci): reject pooled (pgbouncer) database urls for migrations
* Revert "improvement(ci): reject pooled (pgbouncer) database urls for migrations"
This reverts commit 3b80d8387b.
This commit is contained in:
+25
-10
@@ -46,10 +46,33 @@ jobs:
|
||||
echo "ℹ️ Not a release commit"
|
||||
fi
|
||||
|
||||
# Run database migrations before images are pushed: the ECR push triggers
|
||||
# CodePipeline, so migrating first guarantees the schema is in place before
|
||||
# the new app version deploys (replaces the removed ECS migration sidecar)
|
||||
migrate:
|
||||
name: Migrate DB
|
||||
needs: [test-build]
|
||||
if: >-
|
||||
github.event_name == 'push' &&
|
||||
(github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging')
|
||||
uses: ./.github/workflows/migrations.yml
|
||||
with:
|
||||
environment: ${{ github.ref == 'refs/heads/main' && 'production' || 'staging' }}
|
||||
secrets: inherit
|
||||
|
||||
# Same ordering for dev (schema push before the dev image lands in ECR)
|
||||
migrate-dev:
|
||||
name: Migrate Dev DB
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/dev'
|
||||
uses: ./.github/workflows/migrations.yml
|
||||
with:
|
||||
environment: dev
|
||||
secrets: inherit
|
||||
|
||||
# Dev: build all 3 images for ECR only (no GHCR, no ARM64)
|
||||
build-dev:
|
||||
name: Build Dev ECR
|
||||
needs: [detect-version]
|
||||
needs: [detect-version, migrate-dev]
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/dev'
|
||||
runs-on: blacksmith-8vcpu-ubuntu-2404
|
||||
permissions:
|
||||
@@ -108,7 +131,7 @@ jobs:
|
||||
# Main/staging: build AMD64 images and push to ECR + GHCR
|
||||
build-amd64:
|
||||
name: Build AMD64
|
||||
needs: [test-build, detect-version]
|
||||
needs: [test-build, detect-version, migrate]
|
||||
if: >-
|
||||
github.event_name == 'push' &&
|
||||
(github.ref == 'refs/heads/main' || github.ref == 'refs/heads/staging')
|
||||
@@ -318,14 +341,6 @@ jobs:
|
||||
docker manifest push "${IMAGE_BASE}:${VERSION}"
|
||||
fi
|
||||
|
||||
# Run database migrations for dev
|
||||
migrate-dev:
|
||||
name: Migrate Dev DB
|
||||
needs: [build-dev]
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/dev'
|
||||
uses: ./.github/workflows/migrations.yml
|
||||
secrets: inherit
|
||||
|
||||
# Check if docs changed
|
||||
check-docs-changes:
|
||||
name: Check Docs Changes
|
||||
|
||||
@@ -2,7 +2,21 @@ name: Database Migrations
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
environment:
|
||||
description: Target environment (production, staging, or dev)
|
||||
required: true
|
||||
type: string
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
environment:
|
||||
description: Target environment
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- production
|
||||
- staging
|
||||
- dev
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
@@ -35,15 +49,24 @@ jobs:
|
||||
- name: Install dependencies
|
||||
run: bun install --frozen-lockfile
|
||||
|
||||
# The expression maps the explicit environment input to exactly one repo
|
||||
# secret, so the job never holds another environment's database URL. An
|
||||
# unknown environment resolves to empty and the guard below fails the job.
|
||||
- name: Apply database schema changes
|
||||
working-directory: ./packages/db
|
||||
env:
|
||||
DATABASE_URL: ${{ github.ref == 'refs/heads/main' && secrets.DATABASE_URL || github.ref == 'refs/heads/dev' && secrets.DEV_DATABASE_URL || secrets.STAGING_DATABASE_URL }}
|
||||
DATABASE_URL: ${{ inputs.environment == 'production' && secrets.DATABASE_URL || inputs.environment == 'staging' && secrets.STAGING_DATABASE_URL || inputs.environment == 'dev' && secrets.DEV_DATABASE_URL || '' }}
|
||||
ENVIRONMENT: ${{ inputs.environment }}
|
||||
run: |
|
||||
if [ "${{ github.ref }}" = "refs/heads/dev" ]; then
|
||||
echo "Dev environment detected — pushing schema with drizzle-kit (db:push)"
|
||||
if [ -z "$DATABASE_URL" ]; then
|
||||
echo "ERROR: no database URL secret resolved for environment '${ENVIRONMENT}'" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ "${ENVIRONMENT}" = "dev" ]; then
|
||||
echo "Dev environment — pushing schema directly (db:push)"
|
||||
bun run db:push --force
|
||||
else
|
||||
echo "Applying versioned migrations (db:migrate)"
|
||||
bun run ./scripts/migrate.ts
|
||||
fi
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user