2.9 KiB
2.9 KiB
actions-k8s
Reusable Gitea Actions for Kubernetes deployments via Flux GitOps.
actions/flux-deploy
Composite action that updates a Flux HelmRelease image tag in a GitOps repo to trigger a Kubernetes deployment.
This action clones the GitOps repo, updates the repository and tag fields in the specified release YAML, commits, and pushes. If the release already points to the requested image, the action exits cleanly (idempotent).
Usage
jobs:
deploy:
runs-on: ubuntu-latest
needs: [ci]
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
steps:
- name: Add SSH_KEY
run: |
echo "${{ secrets.SSH_KEY }}" > $HOME/.ssh/id_rsa
chmod 400 $HOME/.ssh/id_rsa
ssh-keyscan -H git.ericxliu.me > $HOME/.ssh/known_hosts
- name: Checkout code
uses: https://gitea.com/actions/checkout@v4
with:
ssh-key: ${{ secrets.SSH_KEY }}
- name: Build and push image
id: image
uses: https://git.ericxliu.me/eric/actions-docker/.gitea/actions/docker-build@main
with:
image-name: ${{ github.event.repository.name }}
push: true
- name: Deploy to K8s via Flux
uses: https://git.ericxliu.me/eric/actions-k8s/.gitea/actions/flux-deploy@main
with:
image-repository: ${{ github.server_url }}/${{ github.repository }}
image-tag: ${{ steps.image.outputs.tag }}
gitops-file: apps/myapp/my-app/release.yaml
deploy-key: ${{ secrets.K8S_FLUX_DEPLOY_KEY }}
Inputs
| Input | Required | Default | Description |
|---|---|---|---|
image-repository |
Yes | — | Full image repository (e.g. git.ericxliu.me/eric/workout) |
image-tag |
Yes | — | Image tag to deploy (e.g. 2026-06-17-abc1234) |
gitops-repo |
No | git@github.com:eric-x-liu/k8s-flux.git |
SSH URL of the GitOps repo |
gitops-file |
Yes | — | Path to release YAML in the GitOps repo |
deploy-key |
Yes | — | SSH private key with push access to the GitOps repo |
git-user-name |
No | gitops-ci |
Git commit author name |
git-user-email |
No | gitops-ci@users.noreply.git.ericxliu.me |
Git commit author email |
commit-message |
No | Update {app} image to {tag} |
Custom commit message ({app} and {tag} are replaced) |
How It Works
- Sets up SSH with the provided deploy key
- Clones the GitOps repo (e.g.
k8s-flux) - Updates
repository:andtag:fields in the specified release YAML via regex - If no changes detected → exits cleanly (idempotent)
- Commits and pushes to trigger Flux reconciliation
Requirements
- The GitOps repo must be accessible via SSH with the provided deploy key
- The release YAML must contain
repository:andtag:fields (standard bjw-sapp-templatechart format) python3must be available on the runner (standard onubuntu-latest)