Local Build and Deploy / deploy (push) Canceled after 9m26s
Host built a different event-form than HEAD while git looked clean; delete src, restore from git objects, and hash-verify every tracked blob. Co-authored-by: Cursor <[email protected]>
147 lines
5.7 KiB
YAML
147 lines
5.7 KiB
YAML
name: Local Build and Deploy
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
jobs:
|
|
deploy:
|
|
runs-on: shell
|
|
steps:
|
|
- name: Run Deploy Scripts Locally
|
|
run: |
|
|
set -e
|
|
|
|
# Define a lockfile to prevent double, concurrent deployments
|
|
exec 9>/var/tmp/epic_web_control_deploy.lock
|
|
flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; }
|
|
|
|
echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---"
|
|
|
|
# Fallback routine: If anything crashes during the steps below,
|
|
# try to keep the current service running so the site doesn't stay down.
|
|
error_handler() {
|
|
echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2
|
|
echo "Attempting to keep the current service running..." >&2
|
|
sudo systemctl start atom-nexst.service || true
|
|
exit 1
|
|
}
|
|
trap 'error_handler $LINENO' ERR
|
|
|
|
# 1. Clean up unused build images safely
|
|
docker image prune -f
|
|
|
|
# 2. Navigate to your website directory
|
|
cd /var/www/atom-nexst/
|
|
|
|
DEPLOY_USER="$(id -un)"
|
|
DEPLOY_GROUP="$(id -gn)"
|
|
|
|
# CRITICAL: last deploy chowns the tree to www-data. Reclaim ownership
|
|
# BEFORE git reset, otherwise stale sources can survive and break builds.
|
|
sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/
|
|
|
|
# CRITICAL: Prevent Git permission blocks caused by the www-data ownership change
|
|
git config --global --add safe.directory /var/www/atom-nexst
|
|
|
|
# Point Git directly to the local Gitea folder path
|
|
git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/
|
|
|
|
# 3. Fetch and update code
|
|
git fetch origin --prune
|
|
|
|
# Clear EVERY skip-worktree / assume-unchanged bit. Those bits make
|
|
# `git reset --hard` and `git diff` lie: the working tree can keep
|
|
# ancient file contents while git reports a clean checkout.
|
|
STICKY=0
|
|
while IFS= read -r -d '' f; do
|
|
if git ls-files -v -- "$f" | grep -qE '^[a-zS]'; then
|
|
STICKY=$((STICKY + 1))
|
|
fi
|
|
git update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true
|
|
done < <(git ls-files -z)
|
|
echo "Cleared skip-worktree/assume-unchanged bits (saw ${STICKY} sticky before clear)"
|
|
|
|
git reset --hard origin/main
|
|
|
|
# Nuclear: delete src/ on disk, then restore ONLY from git objects.
|
|
# This is the only reliable way to drop host-local ghosts that survive
|
|
# reset/checkout when index flags or permissions pin old bytes.
|
|
rm -rf src
|
|
git checkout -f HEAD -- src
|
|
|
|
# Drop other stray untracked junk under the app root (keep secrets/env).
|
|
git clean -fd -e .env -e .env.local -e .env.production -e .env*.local
|
|
|
|
# Prove EVERY tracked file under src/ matches the HEAD blob (content hash).
|
|
# `git diff` alone is not enough when skip-worktree was previously set.
|
|
MISMATCH=0
|
|
while IFS= read -r -d '' f; do
|
|
case "$f" in
|
|
src/*) ;;
|
|
*) continue ;;
|
|
esac
|
|
expected="$(git rev-parse "HEAD:${f}")"
|
|
actual="$(git hash-object "${f}")"
|
|
if [ "${expected}" != "${actual}" ]; then
|
|
echo "ERROR: content hash mismatch: ${f}" >&2
|
|
echo " expected=${expected}" >&2
|
|
echo " actual=${actual}" >&2
|
|
MISMATCH=1
|
|
fi
|
|
done < <(git ls-files -z)
|
|
if [ "${MISMATCH}" -ne 0 ]; then
|
|
echo "ERROR: src/ working tree does not match HEAD after nuclear checkout" >&2
|
|
exit 1
|
|
fi
|
|
echo "Verified all tracked src/ blobs match HEAD"
|
|
|
|
# Drop incremental TS caches that can hide real type errors.
|
|
rm -f tsconfig.tsbuildinfo .tsbuildinfo
|
|
find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true
|
|
|
|
# Wipe .next entirely — partial cache has disagreed with clean sources.
|
|
rm -rf .output dist .next
|
|
|
|
# Release tag for Sentry / logs (short git sha)
|
|
export APP_VERSION="$(git rev-parse --short HEAD)"
|
|
export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}"
|
|
echo "APP_VERSION=${APP_VERSION}"
|
|
|
|
# 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml
|
|
# (do not set a PNPM only-built-deps env override here).
|
|
pnpm install --frozen-lockfile
|
|
|
|
# 5. Apply versioned CMS migrations and generate the Prisma client safely
|
|
pnpm db:migrate
|
|
pnpm prisma:generate
|
|
|
|
# 6. Pre-deploy quality gates (fail before build if broken)
|
|
pnpm typecheck
|
|
pnpm test
|
|
|
|
# 7. Next.js Build
|
|
# Skip env refine during compile/page-data; runtime still validates via env.ts.
|
|
export SKIP_ENV_VALIDATION=1
|
|
pnpm build
|
|
|
|
# 8. Fix ownership: Build first, THEN set permissions for the web server
|
|
sudo chown -R www-data:www-data /var/www/atom-nexst/
|
|
|
|
# 9. Hard restart of the Systemd service to clear memory cache
|
|
echo "Hard resetting systemd service..."
|
|
sudo systemctl stop atom-nexst.service || true
|
|
|
|
# Kill any lingering next-server processes holding port 3000
|
|
pkill -f 'next-server' || true
|
|
|
|
sudo systemctl start atom-nexst.service
|
|
|
|
# Extra health check: Ensure the service is actually running
|
|
sleep 2
|
|
if ! systemctl is-active --quiet atom-nexst.service; then
|
|
echo "ERROR: atom-nexst.service failed to start!" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "--- Deployment successfully completed ---"
|