Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
83 changes: 83 additions & 0 deletions .github/workflows/pesacheck-meedan-bridge-cd.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
# yamllint disable rule:line-length
name: PesaCheck Meedan Bridge | Continuous Deployment
"on":
push:
branches:
- main
paths:
- "pesacheck_meedan_bridge/py/VERSION"
# The job only checks out the repo; the deploy uses DockerHub/SSH secrets.
permissions:
contents: read
env:
DOKKU_REMOTE_URL: "ssh://dokku@dokku-1.dev.codeforafrica.org/pesacheck-meedan-bridge"
IMAGE_NAME: "codeforafrica/pesacheck_meedan_bridge"

# This allows a subsequently queued workflow run to interrupt previous runs
concurrency:
group: "${{ github.workflow }} @ ${{ github.event.pull_request.head.label || github.head_ref || github.ref }}"
cancel-in-progress: true

jobs:
build:
name: Build and Deploy
runs-on: ubuntu-latest
strategy:
matrix:
python-version: ["3.11"]
steps:
- name: Checkout
uses: actions/checkout@v6
with:
fetch-depth: 0

- name: Set env
run: echo "VERSION=$(cat pesacheck_meedan_bridge/py/VERSION)" >> $GITHUB_ENV

- name: Setup Python ${{ matrix.python-version }}
uses: actions/setup-python@v6
with:
python-version: ${{ matrix.python-version }}

- name: Initialize Pants
uses: pantsbuild/actions/init-pants@main
with:
# cache0 makes it easy to bust the cache if needed
gha-cache-key: cache0-py${{ matrix.python_version }}
named-caches-hash: ${{ hashFiles('lockfiles/*.json', '**/something-else.lock') }}

- name: Bootstrap Pants
run: |
pants --version

- name: Check BUILD files
run: pants tailor --check update-build-files --check

- name: Lint
run: |
pants lint --lint-skip-formatters pesacheck_meedan_bridge/::

- name: Build Docker image
run: |
VERSION=${{ env.VERSION }} pants package pesacheck_meedan_bridge/docker/::

- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKER_HUB_USERNAME }}
password: ${{ secrets.DOCKER_HUB_ACCESS_TOKEN }}

- name: Push to DockerHub
run: |
docker push ${{ env.IMAGE_NAME }}:${{ env.VERSION }}

- name: Deploy to Dokku
uses: dokku/github-action@v1.9.0
with:
# With deploy_docker_image the action runs `dokku git:from-image` and
# never pushes a branch, so `branch`/`git_push_flags` don't apply.
deploy_docker_image: ${{ env.IMAGE_NAME }}:${{ env.VERSION }}
deploy_user_name: "CodeForAfrica Bot"
deploy_user_email: "support@codeforafrica.org"
git_remote_url: ${{ env.DOKKU_REMOTE_URL }}
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
2 changes: 1 addition & 1 deletion pesacheck_meedan_bridge/py/VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
0.1.18
0.1.21
7 changes: 6 additions & 1 deletion pesacheck_meedan_bridge/py/main.py
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,11 @@ def extract_summary(feed):
return summary_text.strip() if summary_text else None


# Identify the bridge instead of defaulting to "python-requests/x.y.z", which
# Cloudflare challenges in front of pesacheck.org. Kept separate from
# py/VERSION, which isn't packaged into the pex.
USER_AGENT = "PesaCheckMeedanBridge/1.0 (+https://pesacheck.org)"

language_codes = {
"english": "en",
"french": "fr",
Expand Down Expand Up @@ -91,7 +96,7 @@ def fetch_from_pesacheck(since=None):
if since:
since_utc = since.astimezone(UTC).strftime("%Y-%m-%d %H:%M:%S")
params["filter"] = f"published_at:>='{since_utc}'"
headers = {"Accept-Version": "v5.0"}
headers = {"Accept-Version": "v5.0", "User-Agent": USER_AGENT}
posts = []
page = 1
while page:
Expand Down
Loading