Add centralized immutable QuickStack deployment workflow

This commit is contained in:
2026-08-18 14:58:18 +02:00
commit 1febd203d4
5 changed files with 540 additions and 0 deletions
+44
View File
@@ -0,0 +1,44 @@
# Platform CI
This repository is the central, public source for Nuvisphere's Gitea scoped
workflows. Workflow code contains no credentials. Each consuming owner or
organization supplies its own `REGISTRY_USERNAME`, `REGISTRY_TOKEN` and
`QUICKSTACK_API_TOKEN` Actions secrets.
Repositories opt into deployment by committing `.quickstack/deploy.json`.
The central workflow builds every declared target once, publishes an immutable
`sha-<commit>` OCI tag to the Gitea Container Registry and changes QuickStack
to the exact `@sha256:` digest. A failed rollout or postflight automatically
restores the previous QuickStack configuration.
Example:
```json
{
"version": 1,
"registry": "gitea.nuvisphere.de",
"deployments": [
{
"name": "production",
"branch": "main",
"targets": [
{
"name": "website",
"image": "vadimenovikau/example",
"dockerfile": "Dockerfile",
"context": ".",
"appId": "app-example-12345678",
"healthCheckTcpPort": 3000,
"postflight": {
"url": "https://example.com"
}
}
]
}
]
}
```
Pull requests build all matching targets without logging in, publishing or
deploying. Pushes and manual runs publish and deploy. The commit marker
`[skip quickstack-deploy]` skips a push deliberately.