Skip to content

Releases: mtizima/docker-rollout-action

v1.0.0

Choose a tag to compare

@mtizima mtizima released this 25 Sep 06:27
30d1a8e

First release.

  • Zero-downtime rollout of Compose services over SSH with docker-rollout.
  • File upload, registry login with an ephemeral Docker config, image pull.
  • pre-deploy / post-deploy hooks, up-services for services that can't be rolled out.
  • Healthcheck policy (warn / require / ignore), connection draining via pre-stop-hook.
  • Automatic installation of the docker-rollout plugin on the server.
  • End-to-end tests under load: zero failed requests on deploy and on rollback of a broken release.

v1.0.0 - Zero-downtime Docker Compose deploys over SSH

Choose a tag to compare

@mtizima mtizima released this 25 Sep 06:34
30d1a8e

First public release 🚀

Deploy Docker Compose services to your own server with zero downtime, straight from GitHub Actions - no Kubernetes, no Swarm, no agents. Powered by docker-rollout.

- uses: mtizima/docker-rollout-action@v1
  with:
    host: ${{ secrets.SSH_HOST }}
    user: deploy
    ssh-key: ${{ secrets.SSH_KEY }}
    known-hosts: ${{ secrets.SSH_KNOWN_HOSTS }}
    project-dir: /opt/myapp
    pre-deploy: docker compose run --rm web ./manage.py migrate
    services: web

Highlights

  • Zero-downtime rollout: new containers start next to the old ones, and traffic switches only once they are healthy
  • Automatic rollback: an unhealthy release is removed, the old containers keep serving, and the step fails
  • Migrations hook: pre-deploy runs after the pull and before the switch
  • Whole stack in one step: services with container_name / ports are updated with docker compose up -d
  • Connection draining via pre-stop-hook, so in-flight requests aren't dropped
  • Secure by default: pinned host key, no secrets on command lines, registry credentials in a throwaway Docker config removed after the deploy
  • docker-rollout auto-install on the server if missing
  • Plain Bash, a single SSH session, nothing to install on the runner

Tested under load

Every change is deployed in CI under constant traffic through Traefik. The test fails if a single request fails, both on a normal deploy and on the rollback of a broken release.

Requirements

Docker with Compose v2, bash 4.4+ and a reverse proxy (Traefik, nginx-proxy, Caddy…) on the server. Rolled-out services need a healthcheck and must not use container_name or published ports. See the README for the full input reference.