fix: merge release into deploy workflow for Gitea compatibility
This commit is contained in:
1 parent
02df513b18
commit
0913e9d529
2 files changed
+70
-169
No files matched your search
@@ -1,57 +1,105 @@
|
||||
name: Local Build and Deploy
|
||||
name: Deploy
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
tags:
|
||||
- "v*"
|
||||
jobs:
|
||||
deploy:
|
||||
release:
|
||||
if: startsWith(gitea.ref_name, 'v')
|
||||
runs-on: shell
|
||||
steps:
|
||||
- name: Run Deploy Scripts Locally
|
||||
- name: Create Release
|
||||
env:
|
||||
VERSION: ${{ gitea.ref_name }}
|
||||
GITEA_API: ${{ gitea.api_url }}
|
||||
GITEA_REPO: ${{ gitea.repository }}
|
||||
run: |
|
||||
set -e
|
||||
exec 2>&1
|
||||
BARE="/docker/gitea/gitea/git/repositories/remco/epicnext-cms.git"
|
||||
echo "=== Creating release for ${VERSION} ==="
|
||||
|
||||
PREV_TAG="$(git -C "$BARE" tag --sort=-creatordate | head -2 | tail -1 || echo '')"
|
||||
|
||||
if [ -n "$PREV_TAG" ] && [ "$PREV_TAG" != "$VERSION" ]; then
|
||||
CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate "${PREV_TAG}..${VERSION}")"
|
||||
else
|
||||
CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate "${VERSION}")"
|
||||
fi
|
||||
[ -z "$CHANGELOG" ] && CHANGELOG="Initial release"
|
||||
|
||||
echo "${CHANGELOG}" > /tmp/changelog.txt
|
||||
|
||||
BODY="## EpicNext-CMS ${VERSION}
|
||||
|
||||
### Changes
|
||||
${CHANGELOG}
|
||||
|
||||
---
|
||||
*Automated release from Gitea Actions*
|
||||
"
|
||||
|
||||
PAYLOAD="$(printf '%s' "$BODY" | jq -Rs '{tag_name: $v, name: $v, body: ., draft: false, prerelease: false}' --arg v "${VERSION}")"
|
||||
|
||||
HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \
|
||||
-X POST "${GITEA_API}/repos/${GITEA_REPO}/releases" \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "$PAYLOAD")"
|
||||
|
||||
if [ "${HTTP_CODE}" = "409" ]; then
|
||||
RELEASES="$(curl -sf "${GITEA_API}/repos/${GITEA_REPO}/releases" \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}")"
|
||||
REL_ID="$(echo "$RELEASES" | jq -r ".[] | select(.tag_name==\"${VERSION}\") | .id")"
|
||||
HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \
|
||||
-X PATCH "${GITEA_API}/repos/${GITEA_REPO}/releases/${REL_ID}" \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "$PAYLOAD")"
|
||||
fi
|
||||
|
||||
if [ "${HTTP_CODE:-0}" -ge 200 ] && [ "${HTTP_CODE:-0}" -lt 300 ]; then
|
||||
echo "SUCCESS: Release ${VERSION} created/updated"
|
||||
cat /tmp/release-resp.json | jq -r '.html_url // .id'
|
||||
else
|
||||
echo "FAILED HTTP ${HTTP_CODE}"
|
||||
cat /tmp/release-resp.json
|
||||
exit 1
|
||||
fi
|
||||
deploy:
|
||||
if: startsWith(gitea.ref_name, 'v') == false
|
||||
runs-on: shell
|
||||
steps:
|
||||
- name: Deploy
|
||||
run: |
|
||||
set -e
|
||||
|
||||
# Define a lockfile to prevent double, concurrent deployments
|
||||
exec 9>/var/tmp/epic_web_control_deploy.lock
|
||||
flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; }
|
||||
|
||||
echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---"
|
||||
echo "--- Deploying ---"
|
||||
|
||||
# Fallback routine: If anything crashes during the steps below,
|
||||
# try to keep the current service running so the site doesn't stay down.
|
||||
error_handler() {
|
||||
echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2
|
||||
echo "Attempting to keep the current service running..." >&2
|
||||
sudo systemctl start atom-nexst.service || true
|
||||
exit 1
|
||||
}
|
||||
trap 'error_handler $LINENO' ERR
|
||||
|
||||
# 1. Clean up unused build images safely
|
||||
docker image prune -f
|
||||
|
||||
# 2. Navigate to your website directory
|
||||
cd /var/www/atom-nexst/
|
||||
|
||||
DEPLOY_USER="$(id -un)"
|
||||
DEPLOY_GROUP="$(id -gn)"
|
||||
|
||||
# CRITICAL: last deploy chowns the tree to www-data. Reclaim ownership
|
||||
# BEFORE git reset, otherwise stale sources can survive and break builds.
|
||||
sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/
|
||||
|
||||
# CRITICAL: Prevent Git permission blocks caused by the www-data ownership change
|
||||
git config --global --add safe.directory /var/www/atom-nexst
|
||||
|
||||
# Point Git directly to the local Gitea folder path
|
||||
git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/
|
||||
|
||||
# 3. Fetch and update code
|
||||
echo "Fetching origin/main..."
|
||||
git fetch origin --prune
|
||||
|
||||
# Only touch files that actually have sticky bits (fast). Clearing
|
||||
# every tracked path one-by-one can hang the runner for minutes.
|
||||
echo "Clearing sticky git index bits (if any)..."
|
||||
STICKY_LIST="$(git ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' || true)"
|
||||
if [ -n "${STICKY_LIST}" ]; then
|
||||
@@ -59,24 +107,16 @@ jobs:
|
||||
[ -n "$f" ] || continue
|
||||
git update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true
|
||||
done
|
||||
echo "Cleared sticky bits on $(echo "${STICKY_LIST}" | grep -c . || true) path(s)"
|
||||
else
|
||||
echo "No sticky bits found"
|
||||
fi
|
||||
|
||||
echo "Hard reset to origin/main..."
|
||||
git reset --hard origin/main
|
||||
|
||||
# Nuclear: delete src/ on disk, then restore ONLY from git objects.
|
||||
# Defeats host-local ghosts that survive reset when index flags pin old bytes.
|
||||
echo "Nuclear-replacing src/ from HEAD..."
|
||||
rm -rf src
|
||||
git checkout -f HEAD -- src
|
||||
|
||||
# Drop other stray untracked junk under the app root (keep secrets/env).
|
||||
git clean -fd -e .env -e .env.local -e .env.production -e .env*.local
|
||||
|
||||
# After sticky clear + nuclear replace, content diff is trustworthy again.
|
||||
if ! git diff --exit-code HEAD -- src >/dev/null; then
|
||||
echo "ERROR: src/ still differs from HEAD after nuclear checkout:" >&2
|
||||
git diff --stat HEAD -- src >&2 || true
|
||||
@@ -84,53 +124,33 @@ jobs:
|
||||
fi
|
||||
echo "Verified src/ matches HEAD"
|
||||
|
||||
# Drop incremental TS caches that can hide real type errors.
|
||||
rm -f tsconfig.tsbuildinfo .tsbuildinfo
|
||||
find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true
|
||||
|
||||
# Clear generated Next types/dev dirs, but keep .next/cache for faster rebuilds.
|
||||
# Full src/ nuclear replace above already guarantees sources match HEAD.
|
||||
rm -rf .output dist .next/types .next/dev
|
||||
|
||||
# Release tag for Sentry / logs (short git sha)
|
||||
export APP_VERSION="$(git rev-parse --short HEAD)"
|
||||
export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}"
|
||||
echo "APP_VERSION=${APP_VERSION}"
|
||||
|
||||
# 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml
|
||||
# (do not set a PNPM only-built-deps env override here).
|
||||
pnpm install --frozen-lockfile
|
||||
|
||||
# 5. Apply versioned CMS migrations and generate the Prisma client safely
|
||||
pnpm db:migrate
|
||||
pnpm prisma:generate
|
||||
|
||||
# 6. Pre-deploy quality gates (fail before build if broken)
|
||||
pnpm typecheck
|
||||
pnpm test
|
||||
|
||||
# 7. Next.js Build
|
||||
# Skip env refine during compile/page-data; runtime still validates via env.ts.
|
||||
export SKIP_ENV_VALIDATION=1
|
||||
pnpm build
|
||||
|
||||
# 8. Fix ownership: Build first, THEN set permissions for the web server
|
||||
sudo chown -R www-data:www-data /var/www/atom-nexst/
|
||||
|
||||
# 9. Hard restart of the Systemd service to clear memory cache
|
||||
echo "Hard resetting systemd service..."
|
||||
sudo systemctl stop atom-nexst.service || true
|
||||
|
||||
# Kill any lingering next-server processes holding port 3000
|
||||
pkill -f 'next-server' || true
|
||||
|
||||
sudo systemctl start atom-nexst.service
|
||||
|
||||
# Extra health check: Ensure the service is actually running
|
||||
sleep 2
|
||||
if ! systemctl is-active --quiet atom-nexst.service; then
|
||||
echo "ERROR: atom-nexst.service failed to start!" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "--- Deployment successfully completed ---"
|
||||
echo "--- Deployed successfully ---"
|
||||
@@ -1,119 +0,0 @@
|
||||
name: Create Release
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- "v*"
|
||||
jobs:
|
||||
release:
|
||||
runs-on: shell
|
||||
steps:
|
||||
- name: Debug - check bare repo
|
||||
run: |
|
||||
echo "=== DEBUG ==="
|
||||
echo "PWD: $(pwd)"
|
||||
echo "BARE exists: $(test -d /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git && echo YES || echo NO)"
|
||||
echo "Tags: $(git -C /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git tag -l 2>&1)"
|
||||
echo "Log: $(git -C /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git log --oneline v1.0 2>&1 | head -3)"
|
||||
echo "=== END ==="
|
||||
- name: Create release
|
||||
env:
|
||||
VERSION: ${{ gitea.ref_name }}
|
||||
GITEA_API: ${{ gitea.api_url }}
|
||||
GITEA_REPO: ${{ gitea.repository }}
|
||||
run: |
|
||||
set -e
|
||||
exec 2>&1
|
||||
|
||||
BARE="/docker/gitea/gitea/git/repositories/remco/epicnext-cms.git"
|
||||
echo "=== START ${VERSION} ==="
|
||||
|
||||
echo "=== Tags in bare repo ==="
|
||||
git -C "$BARE" tag -l
|
||||
echo "=== Done ==="
|
||||
|
||||
echo "=== Log for ${VERSION} ==="
|
||||
git -C "$BARE" log --oneline --no-decorate "${VERSION}" 2>&1 || echo "LOG FAILED"
|
||||
echo "=== Done ==="
|
||||
|
||||
PREV_TAG="$(git -C "$BARE" tag --sort=-creatordate | head -2 | tail -1 || echo '')"
|
||||
echo "Previous tag: '${PREV_TAG}'"
|
||||
|
||||
if [ -n "$PREV_TAG" ] && [ "$PREV_TAG" != "$VERSION" ]; then
|
||||
CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate "${PREV_TAG}..${VERSION}" 2>&1)"
|
||||
else
|
||||
CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate "${VERSION}" 2>&1)"
|
||||
fi
|
||||
|
||||
[ -z "$CHANGELOG" ] && CHANGELOG="Initial release"
|
||||
|
||||
echo "=== Changelog (${#CHANGELOG} chars) ==="
|
||||
echo "${CHANGELOG}"
|
||||
echo "=== End ==="
|
||||
|
||||
echo "$CHANGELOG" > /tmp/changelog.txt
|
||||
|
||||
# Build
|
||||
SRC="/tmp/epicnext-release"
|
||||
rm -rf "$SRC"
|
||||
git clone --branch "${VERSION}" --depth 1 "$BARE" "$SRC"
|
||||
cd "$SRC"
|
||||
|
||||
if [ -f /var/www/atom-nexst/.env ]; then
|
||||
cp /var/www/atom-nexst/.env "$SRC/.env"
|
||||
fi
|
||||
pnpm install --frozen-lockfile
|
||||
pnpm prisma:generate
|
||||
export SKIP_ENV_VALIDATION=1
|
||||
pnpm build
|
||||
|
||||
# Create release
|
||||
echo "=== Creating release ==="
|
||||
NOTES="$(cat /tmp/changelog.txt)"
|
||||
echo "NOTES length: ${#NOTES}"
|
||||
BODY="## EpicNext-CMS ${VERSION}
|
||||
|
||||
### Changes
|
||||
${NOTES}
|
||||
|
||||
---
|
||||
*Automated release from Gitea Actions*
|
||||
"
|
||||
echo "BODY length: ${#BODY}"
|
||||
|
||||
PAYLOAD="$(echo "$BODY" | jq -Rs '{tag_name: $v, name: $v, body: ., draft: false, prerelease: false}' --arg v "${VERSION}" 2>&1)"
|
||||
echo "Payload: ${#PAYLOAD} bytes"
|
||||
echo "PAYLOAD: ${PAYLOAD:0:200}..."
|
||||
|
||||
HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \
|
||||
-X POST "${GITEA_API}/repos/${GITEA_REPO}/releases" \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "$PAYLOAD" 2>&1)"
|
||||
echo "POST response: ${HTTP_CODE}"
|
||||
echo "Response: $(cat /tmp/release-resp.json | head -5)"
|
||||
|
||||
if [ "${HTTP_CODE}" = "409" ]; then
|
||||
echo "Release exists, updating..."
|
||||
RELEASES="$(curl -sf "${GITEA_API}/repos/${GITEA_REPO}/releases" \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}")"
|
||||
REL_ID="$(echo "$RELEASES" | jq -r ".[] | select(.tag_name==\"${VERSION}\") | .id")"
|
||||
echo "Release ID: ${REL_ID}"
|
||||
HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \
|
||||
-X PATCH "${GITEA_API}/repos/${GITEA_REPO}/releases/${REL_ID}" \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "$PAYLOAD" 2>&1)"
|
||||
echo "PATCH response: ${HTTP_CODE}"
|
||||
fi
|
||||
|
||||
if [ "${HTTP_CODE:-0}" -ge 200 ] && [ "${HTTP_CODE:-0}" -lt 300 ]; then
|
||||
echo "SUCCESS"
|
||||
cat /tmp/release-resp.json | jq -r '.html_url // .id' 2>/dev/null || true
|
||||
echo "BODY: $(cat /tmp/release-resp.json | jq -r '.body // "none"' | head -5)"
|
||||
else
|
||||
echo "FAILED with HTTP ${HTTP_CODE}"
|
||||
cat /tmp/release-resp.json 2>/dev/null || true
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "=== DONE ==="
|
||||
Reference in new issue
Block a user