From 0913e9d529ced1d1f4223343d3141cbb760b914a Mon Sep 17 00:00:00 2001 From: openhands Date: Mon, 20 Jul 2026 15:50:03 +0200 Subject: [PATCH] fix: merge release into deploy workflow for Gitea compatibility --- .gitea/workflows/deploy.yaml | 120 ++++++++++++++++++++-------------- .gitea/workflows/release.yaml | 119 --------------------------------- 2 files changed, 70 insertions(+), 169 deletions(-) delete mode 100644 .gitea/workflows/release.yaml diff --git a/.gitea/workflows/deploy.yaml b/.gitea/workflows/deploy.yaml index 4ed40cb6..6c7fa140 100644 --- a/.gitea/workflows/deploy.yaml +++ b/.gitea/workflows/deploy.yaml @@ -1,57 +1,105 @@ -name: Local Build and Deploy +name: Deploy on: push: branches: - main + tags: + - "v*" jobs: - deploy: + release: + if: startsWith(gitea.ref_name, 'v') runs-on: shell steps: - - name: Run Deploy Scripts Locally + - name: Create Release + env: + VERSION: ${{ gitea.ref_name }} + GITEA_API: ${{ gitea.api_url }} + GITEA_REPO: ${{ gitea.repository }} + run: | + set -e + exec 2>&1 + BARE="/docker/gitea/gitea/git/repositories/remco/epicnext-cms.git" + echo "=== Creating release for ${VERSION} ===" + + PREV_TAG="$(git -C "$BARE" tag --sort=-creatordate | head -2 | tail -1 || echo '')" + + if [ -n "$PREV_TAG" ] && [ "$PREV_TAG" != "$VERSION" ]; then + CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate "${PREV_TAG}..${VERSION}")" + else + CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate "${VERSION}")" + fi + [ -z "$CHANGELOG" ] && CHANGELOG="Initial release" + + echo "${CHANGELOG}" > /tmp/changelog.txt + + BODY="## EpicNext-CMS ${VERSION} + +### Changes +${CHANGELOG} + +--- +*Automated release from Gitea Actions* +" + + PAYLOAD="$(printf '%s' "$BODY" | jq -Rs '{tag_name: $v, name: $v, body: ., draft: false, prerelease: false}' --arg v "${VERSION}")" + + HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ + -X POST "${GITEA_API}/repos/${GITEA_REPO}/releases" \ + -H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \ + -H "Content-Type: application/json" \ + -d "$PAYLOAD")" + + if [ "${HTTP_CODE}" = "409" ]; then + RELEASES="$(curl -sf "${GITEA_API}/repos/${GITEA_REPO}/releases" \ + -H "Authorization: token ${{ secrets.GITEA_TOKEN }}")" + REL_ID="$(echo "$RELEASES" | jq -r ".[] | select(.tag_name==\"${VERSION}\") | .id")" + HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ + -X PATCH "${GITEA_API}/repos/${GITEA_REPO}/releases/${REL_ID}" \ + -H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \ + -H "Content-Type: application/json" \ + -d "$PAYLOAD")" + fi + + if [ "${HTTP_CODE:-0}" -ge 200 ] && [ "${HTTP_CODE:-0}" -lt 300 ]; then + echo "SUCCESS: Release ${VERSION} created/updated" + cat /tmp/release-resp.json | jq -r '.html_url // .id' + else + echo "FAILED HTTP ${HTTP_CODE}" + cat /tmp/release-resp.json + exit 1 + fi + deploy: + if: startsWith(gitea.ref_name, 'v') == false + runs-on: shell + steps: + - name: Deploy run: | set -e - # Define a lockfile to prevent double, concurrent deployments exec 9>/var/tmp/epic_web_control_deploy.lock flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; } - echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---" + echo "--- Deploying ---" - # Fallback routine: If anything crashes during the steps below, - # try to keep the current service running so the site doesn't stay down. error_handler() { echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2 - echo "Attempting to keep the current service running..." >&2 sudo systemctl start atom-nexst.service || true exit 1 } trap 'error_handler $LINENO' ERR - # 1. Clean up unused build images safely docker image prune -f - - # 2. Navigate to your website directory cd /var/www/atom-nexst/ DEPLOY_USER="$(id -un)" DEPLOY_GROUP="$(id -gn)" - - # CRITICAL: last deploy chowns the tree to www-data. Reclaim ownership - # BEFORE git reset, otherwise stale sources can survive and break builds. sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/ - - # CRITICAL: Prevent Git permission blocks caused by the www-data ownership change git config --global --add safe.directory /var/www/atom-nexst - - # Point Git directly to the local Gitea folder path git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/ - # 3. Fetch and update code echo "Fetching origin/main..." git fetch origin --prune - # Only touch files that actually have sticky bits (fast). Clearing - # every tracked path one-by-one can hang the runner for minutes. echo "Clearing sticky git index bits (if any)..." STICKY_LIST="$(git ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' || true)" if [ -n "${STICKY_LIST}" ]; then @@ -59,24 +107,16 @@ jobs: [ -n "$f" ] || continue git update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true done - echo "Cleared sticky bits on $(echo "${STICKY_LIST}" | grep -c . || true) path(s)" - else - echo "No sticky bits found" fi echo "Hard reset to origin/main..." git reset --hard origin/main - # Nuclear: delete src/ on disk, then restore ONLY from git objects. - # Defeats host-local ghosts that survive reset when index flags pin old bytes. echo "Nuclear-replacing src/ from HEAD..." rm -rf src git checkout -f HEAD -- src - - # Drop other stray untracked junk under the app root (keep secrets/env). git clean -fd -e .env -e .env.local -e .env.production -e .env*.local - # After sticky clear + nuclear replace, content diff is trustworthy again. if ! git diff --exit-code HEAD -- src >/dev/null; then echo "ERROR: src/ still differs from HEAD after nuclear checkout:" >&2 git diff --stat HEAD -- src >&2 || true @@ -84,53 +124,33 @@ jobs: fi echo "Verified src/ matches HEAD" - # Drop incremental TS caches that can hide real type errors. rm -f tsconfig.tsbuildinfo .tsbuildinfo find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true - - # Clear generated Next types/dev dirs, but keep .next/cache for faster rebuilds. - # Full src/ nuclear replace above already guarantees sources match HEAD. rm -rf .output dist .next/types .next/dev - # Release tag for Sentry / logs (short git sha) export APP_VERSION="$(git rev-parse --short HEAD)" export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}" echo "APP_VERSION=${APP_VERSION}" - # 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml - # (do not set a PNPM only-built-deps env override here). pnpm install --frozen-lockfile - - # 5. Apply versioned CMS migrations and generate the Prisma client safely pnpm db:migrate pnpm prisma:generate - - # 6. Pre-deploy quality gates (fail before build if broken) pnpm typecheck pnpm test - - # 7. Next.js Build - # Skip env refine during compile/page-data; runtime still validates via env.ts. export SKIP_ENV_VALIDATION=1 pnpm build - # 8. Fix ownership: Build first, THEN set permissions for the web server sudo chown -R www-data:www-data /var/www/atom-nexst/ - # 9. Hard restart of the Systemd service to clear memory cache echo "Hard resetting systemd service..." sudo systemctl stop atom-nexst.service || true - - # Kill any lingering next-server processes holding port 3000 pkill -f 'next-server' || true - sudo systemctl start atom-nexst.service - # Extra health check: Ensure the service is actually running sleep 2 if ! systemctl is-active --quiet atom-nexst.service; then echo "ERROR: atom-nexst.service failed to start!" >&2 exit 1 fi - echo "--- Deployment successfully completed ---" + echo "--- Deployed successfully ---" diff --git a/.gitea/workflows/release.yaml b/.gitea/workflows/release.yaml deleted file mode 100644 index f273aec5..00000000 --- a/.gitea/workflows/release.yaml +++ /dev/null @@ -1,119 +0,0 @@ -name: Create Release -on: - push: - tags: - - "v*" -jobs: - release: - runs-on: shell - steps: - - name: Debug - check bare repo - run: | - echo "=== DEBUG ===" - echo "PWD: $(pwd)" - echo "BARE exists: $(test -d /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git && echo YES || echo NO)" - echo "Tags: $(git -C /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git tag -l 2>&1)" - echo "Log: $(git -C /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git log --oneline v1.0 2>&1 | head -3)" - echo "=== END ===" - - name: Create release - env: - VERSION: ${{ gitea.ref_name }} - GITEA_API: ${{ gitea.api_url }} - GITEA_REPO: ${{ gitea.repository }} - run: | - set -e - exec 2>&1 - - BARE="/docker/gitea/gitea/git/repositories/remco/epicnext-cms.git" - echo "=== START ${VERSION} ===" - - echo "=== Tags in bare repo ===" - git -C "$BARE" tag -l - echo "=== Done ===" - - echo "=== Log for ${VERSION} ===" - git -C "$BARE" log --oneline --no-decorate "${VERSION}" 2>&1 || echo "LOG FAILED" - echo "=== Done ===" - - PREV_TAG="$(git -C "$BARE" tag --sort=-creatordate | head -2 | tail -1 || echo '')" - echo "Previous tag: '${PREV_TAG}'" - - if [ -n "$PREV_TAG" ] && [ "$PREV_TAG" != "$VERSION" ]; then - CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate "${PREV_TAG}..${VERSION}" 2>&1)" - else - CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate "${VERSION}" 2>&1)" - fi - - [ -z "$CHANGELOG" ] && CHANGELOG="Initial release" - - echo "=== Changelog (${#CHANGELOG} chars) ===" - echo "${CHANGELOG}" - echo "=== End ===" - - echo "$CHANGELOG" > /tmp/changelog.txt - - # Build - SRC="/tmp/epicnext-release" - rm -rf "$SRC" - git clone --branch "${VERSION}" --depth 1 "$BARE" "$SRC" - cd "$SRC" - - if [ -f /var/www/atom-nexst/.env ]; then - cp /var/www/atom-nexst/.env "$SRC/.env" - fi - pnpm install --frozen-lockfile - pnpm prisma:generate - export SKIP_ENV_VALIDATION=1 - pnpm build - - # Create release - echo "=== Creating release ===" - NOTES="$(cat /tmp/changelog.txt)" - echo "NOTES length: ${#NOTES}" - BODY="## EpicNext-CMS ${VERSION} - -### Changes -${NOTES} - ---- -*Automated release from Gitea Actions* -" - echo "BODY length: ${#BODY}" - - PAYLOAD="$(echo "$BODY" | jq -Rs '{tag_name: $v, name: $v, body: ., draft: false, prerelease: false}' --arg v "${VERSION}" 2>&1)" - echo "Payload: ${#PAYLOAD} bytes" - echo "PAYLOAD: ${PAYLOAD:0:200}..." - - HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ - -X POST "${GITEA_API}/repos/${GITEA_REPO}/releases" \ - -H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \ - -H "Content-Type: application/json" \ - -d "$PAYLOAD" 2>&1)" - echo "POST response: ${HTTP_CODE}" - echo "Response: $(cat /tmp/release-resp.json | head -5)" - - if [ "${HTTP_CODE}" = "409" ]; then - echo "Release exists, updating..." - RELEASES="$(curl -sf "${GITEA_API}/repos/${GITEA_REPO}/releases" \ - -H "Authorization: token ${{ secrets.GITEA_TOKEN }}")" - REL_ID="$(echo "$RELEASES" | jq -r ".[] | select(.tag_name==\"${VERSION}\") | .id")" - echo "Release ID: ${REL_ID}" - HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ - -X PATCH "${GITEA_API}/repos/${GITEA_REPO}/releases/${REL_ID}" \ - -H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \ - -H "Content-Type: application/json" \ - -d "$PAYLOAD" 2>&1)" - echo "PATCH response: ${HTTP_CODE}" - fi - - if [ "${HTTP_CODE:-0}" -ge 200 ] && [ "${HTTP_CODE:-0}" -lt 300 ]; then - echo "SUCCESS" - cat /tmp/release-resp.json | jq -r '.html_url // .id' 2>/dev/null || true - echo "BODY: $(cat /tmp/release-resp.json | jq -r '.body // "none"' | head -5)" - else - echo "FAILED with HTTP ${HTTP_CODE}" - cat /tmp/release-resp.json 2>/dev/null || true - exit 1 - fi - - echo "=== DONE ==="