-
Notifications
You must be signed in to change notification settings - Fork 3.5k
139 lines (128 loc) · 5.92 KB
/
Copy pathcd-mcp-image.yml
File metadata and controls
139 lines (128 loc) · 5.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
#
# Build and push MCP server container image.
#
# This is the MCP server that runs on k8s (EU + US clusters)
# using Redis for session state instead of Cloudflare Durable Objects.
#
name: MCP Container Image CD
on:
push:
branches:
- master
paths:
- 'services/mcp/**'
- '.github/workflows/cd-mcp-image.yml'
# Bundled into the MCP image at build time (copy-instructions.ts `shared/` copy +
# shared parser sources) — without these paths an edit there never rebuilds the
# image and the bundle goes stale.
- 'products/ai_observability/backend/prompts/parser_recipe_examples.yaml'
- 'packages/llm-normalizer/**'
# paths mirror the push trigger; the build-mcp-image label only forces a
# build on PRs touching these paths, use workflow_dispatch otherwise.
pull_request:
types: [opened, synchronize, reopened, labeled]
paths:
- 'services/mcp/**'
- '.github/workflows/cd-mcp-image.yml'
- 'products/ai_observability/backend/prompts/parser_recipe_examples.yaml'
- 'packages/llm-normalizer/**'
workflow_dispatch:
jobs:
build:
name: Build and push container image
if: |
github.repository_owner == 'PostHog' && (
github.event_name == 'push' ||
github.event_name == 'workflow_dispatch' ||
contains(github.event.pull_request.labels.*.name, 'build-mcp-image')
)
runs-on: depot-ubuntu-24.04
timeout-minutes: 30
permissions:
contents: read
packages: write
id-token: write
outputs:
sha: ${{ steps.push.outputs.digest }}
steps:
- name: Check out
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 2
- name: Docker meta and registry login
id: docker-meta
uses: ./.github/actions/docker-meta
with:
image-name: posthog-mcp
# Publishes only from the default branch — assume the role and touch ECR only there;
# labeled PRs still build (push=false) without assuming it.
aws-role-to-assume: ${{ vars.AWS_ECR_POSTHOG_MASTER_PUBLISH_IAM_ROLE }}
push-to-ecr: ${{ github.ref == 'refs/heads/master' }}
github-token: ${{ secrets.GITHUB_TOKEN }}
dockerhub-username: ${{ secrets.DOCKERHUB_USER }}
dockerhub-password: ${{ secrets.DOCKERHUB_TOKEN }}
push-to-dockerhub: 'false'
# Prod deploys from private ECR; pause the public ghcr push during an embargo.
push-to-ghcr: ${{ vars.PUBLIC_IMAGE_PUSH_PAUSED != 'true' }}
- name: Set up Depot CLI
uses: depot/setup-action@15c09a5f77a0840ad4bce955686522a257853461 # v1.7.1
- name: Build and push container image
id: push
uses: depot/build-push-action@5f3b3c2e5a00f0093de47f657aeaefcedff27d18 # v1.17.0
with:
project: c1f2m5s6zd
file: ./services/mcp/Dockerfile
buildx-fallback: false
push: ${{ github.ref == 'refs/heads/master' && vars.CD_DEPLOY_ENABLED == 'true' }}
tags: ${{ steps.docker-meta.outputs.tags }}
labels: ${{ steps.docker-meta.outputs.labels }}
annotations: ${{ steps.docker-meta.outputs.annotations }}
platforms: linux/arm64,linux/amd64
build-args: COMMIT_HASH=${{ github.sha }}
deploy:
name: Trigger MCP deployment
runs-on: ubuntu-24.04
timeout-minutes: 5
needs: build
if: github.repository_owner == 'PostHog' && vars.CD_DEPLOY_ENABLED == 'true' && github.ref == 'refs/heads/master'
permissions: {}
steps:
- name: Get deployer token
id: deployer
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
with:
client-id: ${{ secrets.GH_APP_CHARTS_DEPLOYER_APP_ID }}
private-key: ${{ secrets.GH_APP_CHARTS_DEPLOYER_PRIVATE_KEY }}
owner: PostHog
repositories: charts
- name: Get PR labels
id: labels
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
with:
script: |
const { data: pulls } = await github.rest.repos.listPullRequestsAssociatedWithCommit({
owner: context.repo.owner,
repo: context.repo.repo,
commit_sha: context.sha,
});
const labels = pulls.flatMap(pr => pr.labels.map(l => l.name));
return JSON.stringify([...new Set(labels)]);
- name: Trigger MCP deployment
uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4.0.1
with:
token: ${{ steps.deployer.outputs.token }}
repository: PostHog/charts
event-type: commit_state_update
client-payload: |
{
"values": {
"image": {
"sha": "${{ needs.build.outputs.sha }}"
}
},
"release": "mcp",
"commit": ${{ toJson(github.event.head_commit) }},
"repository": ${{ toJson(github.repository) }},
"labels": ${{ steps.labels.outputs.result }},
"timestamp": "${{ github.event.head_commit.timestamp }}"
}