Back to Blog DevOps & Scalability

CI/CD Git ke Cloud dengan Docker

Push→Test→Build→Scan→Deploy

CI/CD yang baik mengubah commit menjadi artefak teruji dan release yang dapat dilacak. Docker memastikan lingkungan build konsisten, sedangkan pipeline menjadi bukti otomatis bahwa perubahan layak dipromosikan.

Dockerfile production

Dockerfile
FROM composer:2 AS vendor
WORKDIR /app
COPY composer.json composer.lock ./
RUN composer install --no-dev --prefer-dist --no-interaction --no-scripts
FROM php:8.3-fpm-alpine
WORKDIR /var/www/html
COPY --from=vendor /app/vendor ./vendor
COPY . .
RUN chown -R www-data:www-data storage
USER www-data
CMD ["php-fpm"]

Pipeline GitHub Actions

YAML
name: deploy
on:
  push:
    branches: [main]
jobs:
  test-build-deploy:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      packages: write
    steps:
      - uses: actions/checkout@v4
      - run: docker build --target test -t app:test .
      - run: docker run --rm app:test php vendor/bin/phpunit
      - run: docker build -t ghcr.io/acme/app:${{ github.sha }} .
      - run: echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u ${{ github.actor }} --password-stdin
      - run: docker push ghcr.io/acme/app:${{ github.sha }}
      - run: ./scripts/deploy.sh ${{ github.sha }}

Promotion, bukan rebuild

Image yang lolos test dipromosikan dari staging ke production memakai digest yang sama. Rebuild dapat menghasilkan dependency berbeda dan memutus jejak audit.

Tambahkan gerbang kualitas

Unit & integration test

Mendeteksi regresi fungsi.

Static analysis

Menemukan tipe dan alur berbahaya.

Dependency scan

Mendeteksi CVE library.

Image scan

Memeriksa package OS.

Migration check

Menilai perubahan schema.

Smoke test

Memastikan service hidup setelah deploy.

Pipeline harus cepat memberi umpan balik. Pisahkan test cepat pada pull request dan suite lebih berat sebelum promotion bila diperlukan.

Share this article

Related articles

Copied