Feat/add ci cd pipeline (#4)
Johto Infrastructure Pipeline / Run Ansible Lint (push) Successful in 1m45s
Johto Infrastructure Pipeline / Deploy to Production (push) Failing after 1m49s

This PR add the basic CI/CD workflow.

- On push to any branch ansible-lint is ran to verify syntax and formatting
- On push to main, all pushes are required to pass ansible-lint. Project is than ran against all hosts to push changes to production.

---------

Co-authored-by: Jordan Del Pilar <[email protected]>
Reviewed-on: #4
This commit was merged in pull request #4.
This commit is contained in:
2026-06-13 16:43:33 -07:00
co-authored by Jordan Del Pilar
parent 23e3d4af5f
commit cf8f2435f8
+55
View File
@@ -0,0 +1,55 @@
name: Johto Infrastructure Pipeline
on:
push:
branches:
- '**'
jobs:
lint:
name: Run Ansible Lint
runs-on: ubuntu-latest
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Install Ansible and Lint
run: |
sudo apt-get update
sudo apt-get install -y ansible ansible-lint
- name: Inject Vault Password
run: echo "${{ secrets.ANSIBLE_VAULT_PASSWORD }}" > .vault-pass.txt
- name: Lint Playbooks
run: ansible-lint site.yaml
deploy:
name: Deploy to Production
runs-on: ubuntu-latest
needs: lint
if: github.ref == 'refs/heads/main'
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Install Ansible
run: |
sudo apt-get update
sudo apt-get install -y ansible
- name: Inject SSH Key for Ansible
uses: webfactory/[email protected]
with:
ssh-private-key: ${{ secrets.ANSIBLE_SSH_KEY }}
- name: Add Headscale IPs to Known Hosts
run: |
mkdir -p ~/.ssh
ssh-keyscan 100.64.0.1 100.64.0.2 >> ~/.ssh/known_hosts
- name: Inject Vault Password
run: echo "${{ secrets.ANSIBLE_VAULT_PASSWORD }}" > .vault-pass.txt
- name: Run Ansible Playbook
run: ansible-playbook site.yaml