HardПрактика2 min

Шаг 23: CI/CD через GitHub Actions

Автоматизация сборки, тестирования и деплоя: GitHub Actions workflow, Publish Profile, secrets, миграции в pipeline и protection rules

CI (Continuous Integration) -- автоматическая сборка и тестирование при каждом коммите. CD (Continuous Deployment) -- автоматический деплой после успешной сборки.

Подготовка

GitHub Secret для Publish Profile

az webapp deployment list-publishing-profiles \
  --name orderapp-dev-unique \
  --resource-group rg-orderapp-dev \
  --xml

Скопируйте XML и сохраните как GitHub Secret AZURE_WEBAPP_PUBLISH_PROFILE в Settings -> Secrets -> Actions.

Connection String Secret

Сохраните connection string как AZURE_SQL_CONNECTION_STRING.

Workflow файл

Создайте .github/workflows/deploy.yml:

name: Build and Deploy to Azure

on:
  push:
    branches: [ main ]
  pull_request:
    branches: [ main ]

env:
  DOTNET_VERSION: '10.0.x'
  AZURE_WEBAPP_NAME: orderapp-dev-unique

jobs:
  build-and-test:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4

      - name: Setup .NET
        uses: actions/setup-dotnet@v4
        with:
          dotnet-version: ${{ env.DOTNET_VERSION }}

      - name: Restore dependencies
        run: dotnet restore

      - name: Build
        run: dotnet build --configuration Release --no-restore

      - name: Run tests
        run: dotnet test --configuration Release --no-build

      - name: Publish
        run: dotnet publish src/OrderManagement.API/OrderManagement.API.csproj
          --configuration Release --output ./publish

      - name: Upload artifact
        uses: actions/upload-artifact@v4
        with:
          name: webapp
          path: ./publish

  deploy:
    needs: build-and-test
    runs-on: ubuntu-latest
    if: github.event_name == 'push' && github.ref == 'refs/heads/main'

    steps:
      - name: Download artifact
        uses: actions/download-artifact@v4
        with:
          name: webapp
          path: ./publish

      - name: Deploy to Azure
        uses: azure/webapps-deploy@v3
        with:
          app-name: ${{ env.AZURE_WEBAPP_NAME }}
          publish-profile: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }}
          package: ./publish

Как это работает

git push -> GitHub Actions:
  1. Checkout code
  2. Setup .NET 10
  3. Restore packages
  4. Build (Release)
  5. Run tests
  6. Publish
  7. Deploy to App Service

Job deploy запускается только при push в main (не при Pull Request). При PR -- только build + tests, что позволяет проверить код до мержа.

Protection Rules

В GitHub Settings -> Branches -> Add rule:

  • Branch: main
  • Require status checks: build-and-test

Теперь нельзя замержить PR, если тесты не прошли.

Проверь себя

Почему deploy запускается только при push в main?

Что такое artifact в GitHub Actions?

Зачем хранить Publish Profile как GitHub Secret?

Что делает Branch Protection Rule с require status checks?