103 lines
4.0 KiB
YAML
103 lines
4.0 KiB
YAML
name: Local Build and Deploy
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
jobs:
|
|
deploy:
|
|
runs-on: shell
|
|
steps:
|
|
- name: Run Deploy Scripts Locally
|
|
run: |
|
|
set -e
|
|
|
|
# Define a lockfile to prevent double, concurrent deployments
|
|
exec 9>/var/tmp/epic_web_control_deploy.lock
|
|
flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; }
|
|
|
|
echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---"
|
|
|
|
# Fallback routine: If anything crashes during the steps below,
|
|
# try to keep the current service running so the site doesn't stay down.
|
|
error_handler() {
|
|
echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2
|
|
echo "Attempting to keep the current service running..." >&2
|
|
sudo systemctl start atom-nexst.service || true
|
|
exit 1
|
|
}
|
|
trap 'error_handler $LINENO' ERR
|
|
|
|
# 1. Clean up unused build images safely
|
|
docker image prune -f
|
|
|
|
# 2. Navigate to your website directory
|
|
cd /var/www/atom-nexst/
|
|
|
|
# CRITICAL: Prevent Git permission blocks caused by the www-data ownership change
|
|
git config --global --add safe.directory /var/www/atom-nexst
|
|
|
|
# Point Git directly to the local Gitea folder path
|
|
git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/
|
|
|
|
# 3. Fetch and update code
|
|
git fetch origin --prune
|
|
git reset --hard origin/main
|
|
|
|
# Preserve .next/cache so Next.js can reuse its incremental build cache.
|
|
rm -rf .output dist
|
|
|
|
# 4. Configure trusted dependencies globally and install cleanly
|
|
export PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES="@parcel/watcher,@swc/core,sharp"
|
|
pnpm install --frozen-lockfile
|
|
|
|
# 5. [SAFETY] Database Backup with Rotation (Keeps only last 5 backups)
|
|
echo "Creating database backup..."
|
|
BACKUP_DIR="/var/www/atom-nexst/backups"
|
|
mkdir -p "$BACKUP_DIR"
|
|
|
|
TIMESTAMP=$(date +%Y%m%d_%H%M%S)
|
|
BACKUP_FILE="$BACKUP_DIR/db_backup_$TIMESTAMP.sql"
|
|
|
|
# ----------------- DATABASE CONFIGURATION -----------------
|
|
# Read credentials directly from your .env file or environment if available,
|
|
# or customize these variables to match your system.
|
|
DB_USER="root"
|
|
DB_NAME="epicnext"
|
|
# ----------------------------------------------------------
|
|
|
|
# Create a secure, compressed backup using mysqldump
|
|
# Note: If your MySQL requires a password, add '-pYourPassword' (no space after -p)
|
|
# or configure a secure /home/user/.my.cnf file to read credentials automatically.
|
|
mysqldump -u "$DB_USER" "$DB_NAME" > "$BACKUP_FILE"
|
|
|
|
echo "Rotating older backups (keeping only the 5 newest files)..."
|
|
# Lists backup files newest first, skips the first 5, and deletes any remaining older files
|
|
ls -dt "$BACKUP_DIR"/db_backup_*.sql | tail -n +6 | xargs -r rm
|
|
|
|
# Apply versioned CMS migrations and generate the Prisma client safely
|
|
pnpm db:migrate
|
|
pnpm prisma:generate
|
|
|
|
# 6. Next.js Build
|
|
pnpm build
|
|
|
|
# 7. Fix ownership: Build first, THEN set permissions for the web server
|
|
sudo chown -R www-data:www-data /var/www/atom-nexst/
|
|
|
|
# 8. Hard restart of the Systemd service to clear memory cache
|
|
echo "Hard resetting systemd service..."
|
|
sudo systemctl stop atom-nexst.service || true
|
|
|
|
# Kill any lingering next-server processes holding port 3000
|
|
pkill -f 'next-server' || true
|
|
|
|
sudo systemctl start atom-nexst.service
|
|
|
|
# Extra health check: Ensure the service is actually running
|
|
sleep 2
|
|
if ! systemctl is-active --quiet atom-nexst.service; then
|
|
echo "ERROR: atom-nexst.service failed to start!" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "--- Deployment successfully completed ---" |