2022-01-27 22:28:12 +01:00
|
|
|
---
|
|
|
|
name: Container Registry Purge
|
|
|
|
|
|
|
|
on:
|
2022-02-01 20:41:34 +01:00
|
|
|
schedule:
|
|
|
|
- cron: '0 0 * * SUN'
|
2022-01-27 22:28:12 +01:00
|
|
|
workflow_dispatch:
|
|
|
|
inputs: {}
|
|
|
|
|
|
|
|
jobs:
|
|
|
|
purge:
|
|
|
|
name: Purge old images
|
|
|
|
runs-on: ubuntu-20.04
|
|
|
|
strategy:
|
2022-02-01 20:41:34 +01:00
|
|
|
fail-fast: false
|
2022-01-27 22:28:12 +01:00
|
|
|
matrix:
|
|
|
|
include:
|
|
|
|
- name: bitwardenqa
|
|
|
|
- name: bitwardenprod
|
|
|
|
steps:
|
|
|
|
- name: Login to Azure
|
2022-02-01 20:41:34 +01:00
|
|
|
if: matrix.name == 'bitwardenprod'
|
2022-01-27 22:28:12 +01:00
|
|
|
uses: Azure/login@1f63701bf3e6892515f1b7ce2d2bf1708b46beaf
|
|
|
|
with:
|
|
|
|
creds: ${{ secrets.AZURE_PROD_KV_CREDENTIALS }}
|
|
|
|
|
2022-02-01 20:41:34 +01:00
|
|
|
- name: Login to Azure
|
|
|
|
if: matrix.name == 'bitwardenqa'
|
|
|
|
uses: Azure/login@1f63701bf3e6892515f1b7ce2d2bf1708b46beaf
|
|
|
|
with:
|
|
|
|
creds: ${{ secrets.AZURE_QA_KV_CREDENTIALS }}
|
|
|
|
|
2022-01-27 22:28:12 +01:00
|
|
|
- name: Purge images
|
|
|
|
env:
|
|
|
|
REGISTRY: ${{ matrix.name }}
|
2022-02-01 20:41:34 +01:00
|
|
|
AGO_DUR_VER: "180d"
|
2022-01-27 22:28:12 +01:00
|
|
|
AGO_DUR: "30d"
|
|
|
|
run: |
|
|
|
|
REPO_LIST=$(az acr repository list -n $REGISTRY -o tsv)
|
|
|
|
for REPO in $REPO_LIST
|
|
|
|
do
|
2022-12-21 17:47:23 +01:00
|
|
|
|
|
|
|
PURGE_LATEST=""
|
|
|
|
PURGE_VERSION=""
|
|
|
|
PURGE_ELSE=""
|
|
|
|
|
2022-02-01 20:41:34 +01:00
|
|
|
TAG_LIST=$(az acr repository show-tags -n $REGISTRY --repository $REPO -o tsv)
|
|
|
|
for TAG in $TAG_LIST
|
|
|
|
do
|
2022-03-30 21:08:28 +02:00
|
|
|
if [ $TAG = "latest" ] || [ $TAG = "dev" ]; then
|
2022-12-21 17:47:23 +01:00
|
|
|
PURGE_LATEST+="--filter '$REPO:$TAG' "
|
2022-02-01 20:41:34 +01:00
|
|
|
elif [[ $TAG =~ [0-9]+\.[0-9]+\.[0-9]+ ]]; then
|
2022-12-21 17:47:23 +01:00
|
|
|
PURGE_VERSION+="--filter '$REPO:$TAG' "
|
2022-02-01 20:41:34 +01:00
|
|
|
else
|
2022-12-21 17:47:23 +01:00
|
|
|
PURGE_ELSE+="--filter '$REPO:$TAG' "
|
2022-02-01 20:41:34 +01:00
|
|
|
fi
|
|
|
|
done
|
2022-12-21 17:47:23 +01:00
|
|
|
|
|
|
|
if [ ! -z "$PURGE_LATEST" ]
|
|
|
|
then
|
|
|
|
PURGE_LATEST_CMD="acr purge $PURGE_LATEST --ago $AGO_DUR_VER --untagged --keep 1"
|
|
|
|
az acr run --cmd "$PURGE_LATEST_CMD" --registry $REGISTRY /dev/null &
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [ ! -z "$PURGE_VERSION" ]
|
|
|
|
then
|
|
|
|
PURGE_VERSION_CMD="acr purge $PURGE_VERSION --ago $AGO_DUR_VER --untagged"
|
|
|
|
az acr run --cmd "$PURGE_VERSION_CMD" --registry $REGISTRY /dev/null &
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [ ! -z "$PURGE_ELSE" ]
|
|
|
|
then
|
|
|
|
PURGE_ELSE_CMD="acr purge $PURGE_ELSE --ago $AGO_DUR --untagged"
|
|
|
|
az acr run --cmd "$PURGE_ELSE_CMD" --registry $REGISTRY /dev/null &
|
|
|
|
fi
|
|
|
|
|
|
|
|
wait
|
|
|
|
|
2022-01-27 22:28:12 +01:00
|
|
|
done
|
|
|
|
|
|
|
|
|
|
|
|
check-failures:
|
|
|
|
name: Check for failures
|
|
|
|
if: always()
|
|
|
|
runs-on: ubuntu-20.04
|
|
|
|
needs:
|
|
|
|
- purge
|
|
|
|
steps:
|
|
|
|
- name: Check if any job failed
|
|
|
|
if: |
|
|
|
|
github.ref == 'refs/heads/master'
|
|
|
|
|| github.ref == 'refs/heads/rc'
|
2022-02-09 17:17:17 +01:00
|
|
|
|| github.ref == 'refs/heads/hotfix-rc'
|
2022-01-27 22:28:12 +01:00
|
|
|
env:
|
|
|
|
PURGE_STATUS: ${{ needs.purge.result }}
|
|
|
|
run: |
|
|
|
|
if [ "$PURGE_STATUS" = "failure" ]; then
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
|
|
|
- name: Login to Azure - Prod Subscription
|
|
|
|
uses: Azure/login@1f63701bf3e6892515f1b7ce2d2bf1708b46beaf
|
|
|
|
if: failure()
|
|
|
|
with:
|
|
|
|
creds: ${{ secrets.AZURE_PROD_KV_CREDENTIALS }}
|
|
|
|
|
|
|
|
- name: Retrieve secrets
|
|
|
|
id: retrieve-secrets
|
2022-10-04 20:23:08 +02:00
|
|
|
uses: Azure/get-keyvault-secrets@b5c723b9ac7870c022b8c35befe620b7009b336f
|
2022-01-27 22:28:12 +01:00
|
|
|
if: failure()
|
2022-10-04 20:23:08 +02:00
|
|
|
with:
|
|
|
|
keyvault: "bitwarden-prod-kv"
|
|
|
|
secrets: "devops-alerts-slack-webhook-url"
|
2022-01-27 22:28:12 +01:00
|
|
|
|
|
|
|
- name: Notify Slack on failure
|
2022-03-30 21:08:28 +02:00
|
|
|
uses: act10ns/slack@da3191ebe2e67f49b46880b4633f5591a96d1d33
|
2022-01-27 22:28:12 +01:00
|
|
|
if: failure()
|
|
|
|
env:
|
|
|
|
SLACK_WEBHOOK_URL: ${{ steps.retrieve-secrets.outputs.devops-alerts-slack-webhook-url }}
|
|
|
|
with:
|
|
|
|
status: ${{ job.status }}
|