From 3e584aadaf9b10dc6a652c60a99d52c150a20282 Mon Sep 17 00:00:00 2001 From: simoleo89 Date: Thu, 30 Jul 2026 20:58:40 +0200 Subject: [PATCH] ci: unify check and production deploy into one workflow Co-authored-by: Cursor --- .gitea/workflows/ci.yaml | 474 ++++++++++++++++++++++ .gitea/workflows/deploy.yaml | 476 ----------------------- src/lib/ci-workflow-contract.test.ts | 19 +- src/lib/deploy-workflow-contract.test.ts | 16 +- 4 files changed, 502 insertions(+), 483 deletions(-) delete mode 100644 .gitea/workflows/deploy.yaml diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index abddaa60..4faa9aaa 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -3,6 +3,8 @@ on: push: branches: - main + tags: + - "v*" pull_request: branches: - main @@ -10,6 +12,7 @@ on: jobs: check: + if: startsWith(gitea.ref_name, 'v') == false runs-on: shell steps: - name: Typecheck, lint, and test @@ -45,3 +48,474 @@ jobs: pnpm typecheck pnpm test echo "--- CI checks passed ---" + + deploy: + needs: check + if: gitea.event_name == 'push' && gitea.ref_name == 'main' + runs-on: shell + steps: + - name: Deploy + run: | + set -e + + exec 9>/var/tmp/epic_web_control_deploy.lock + flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; } + + echo "--- Deploying ---" + + LIVE="/var/www/atom-nexst" + STAGE="" + CUTOVER_STARTED=0 + + error_handler() { + cd /var/www/atom-nexst 2>/dev/null || cd / || true + echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2 + # Roll back the build artifact if cutover already moved .next into place. + if [ "${CUTOVER_STARTED}" = "1" ] && [ -d "${LIVE}/.next.prev" ]; then + echo "Rolling back .next to previous artifact..." >&2 + rm -rf "${LIVE}/.next" || true + mv "${LIVE}/.next.prev" "${LIVE}/.next" || true + fi + if [ -n "${STAGE}" ] && [ -d "${STAGE}" ]; then + git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true + fi + pm2 restart next --update-env 2>/dev/null || pm2 start pnpm --name "next" -- start 2>/dev/null || true + exit 1 + } + trap 'error_handler $LINENO' ERR + + docker image prune -f + + DEPLOY_USER="$(id -un)" + DEPLOY_GROUP="$(id -gn)" + sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" "${LIVE}" 2>/dev/null || true + git config --global --add safe.directory "${LIVE}" + git -C "${LIVE}" remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/ + + echo "Fetching origin/main..." + git -C "${LIVE}" fetch origin --prune + + echo "Clearing sticky git index bits (if any)..." + STICKY_LIST="$(git -C "${LIVE}" ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' || true)" + if [ -n "${STICKY_LIST}" ]; then + echo "${STICKY_LIST}" | while IFS= read -r f; do + [ -n "$f" ] || continue + git -C "${LIVE}" update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true + done + fi + + export APP_VERSION="$(git -C "${LIVE}" rev-parse --short origin/main)" + export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}" + echo "APP_VERSION=${APP_VERSION}" + + STAGE="/var/tmp/atom-nexst-stage-${APP_VERSION}" + echo "Preparing stage worktree at ${STAGE} (live site stays up)..." + git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true + git -C "${LIVE}" worktree add --detach "${STAGE}" origin/main + + # Production env stays on the live tree; stage only needs a symlink for build/migrate. + ln -sfn "${LIVE}/.env" "${STAGE}/.env" + + if ! grep -qE '^[[:space:]]*REDIS_URL=.+' "${LIVE}/.env" 2>/dev/null; then + echo "WARNING: REDIS_URL is unset in ${LIVE}/.env" >&2 + echo "WARNING: Rate limits, site-settings cache, and JWT invalidation cache will be in-process only." >&2 + fi + + cd "${STAGE}" + rm -f tsconfig.tsbuildinfo .tsbuildinfo + find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true + rm -rf .output dist .next .next/types .next/dev + + # Restore build cache from last deploy so Turbopack can do + # incremental compilation (much faster rebuilds). + if [ -d "${LIVE}/.next/cache" ]; then + mkdir -p .next/cache + cp -r "${LIVE}/.next/cache/." .next/cache/ + fi + + # Stage shares MySQL with the live app + emulator. Keep the stage pool + # tiny so install/test/build cannot exhaust max_connections. + export DATABASE_POOL_SIZE="${DEPLOY_DATABASE_POOL_SIZE:-5}" + echo "STAGE DATABASE_POOL_SIZE=${DATABASE_POOL_SIZE}" + + pnpm install --frozen-lockfile + # prisma generate only needs DATABASE_URL to resolve the schema — no live DB connection. + # Use a placeholder so it doesn't fail if .env isn't loaded yet; db:migrate later + # will use the real DATABASE_URL from the live .env symlink. + export DATABASE_URL="mysql://placeholder:please@localhost/placeholder" + pnpm prisma:generate + unset DATABASE_URL + export BCRYPT_ROUNDS=4 + pnpm typecheck + # Validate production env (AUTH_SECRET, DATABASE_URL, …) during build. + # Do not set SKIP_ENV_VALIDATION here — that flag is for tests/tooling only. + pnpm build + + if [ ! -d "${STAGE}/.next" ]; then + echo "ERROR: stage build produced no .next/" >&2 + exit 1 + fi + + echo "Cutover: stop service (free DB connections), migrate, swap .next..." + CUTOVER_STARTED=1 + pm2 stop next --kill-timeout 10000 || true + # Wait for PM2 to fully exit and MariaDB to reclaim connections. + sleep 10 + + # Migrate only after live is stopped — avoids ER_CON_COUNT_ERROR while + # the old process still holds DATABASE_POOL_SIZE connections. + cd "${STAGE}" + MIGRATE_OK=0 + for i in $(seq 1 10); do + if pnpm db:migrate; then + MIGRATE_OK=1 + break + fi + echo "migrate attempt ${i}/10 failed (likely DB connections), retrying..." + sleep 5 + done + if [ "${MIGRATE_OK}" != "1" ]; then + echo "ERROR: db:migrate failed after retries" >&2 + exit 1 + fi + + cd "${LIVE}" + echo "Hard reset live tree to origin/main (no nuclear src wipe)..." + git reset --hard origin/main + # Keep env, uploads, and deps we are about to replace from stage. + git clean -fd \ + -e .env -e .env.local -e .env.production -e .env*.local \ + -e storage -e public/cache -e node_modules -e .next -e .next.prev + + if ! git diff --exit-code HEAD -- src >/dev/null; then + echo "ERROR: live src/ still differs from HEAD after reset:" >&2 + git diff --stat HEAD -- src >&2 || true + exit 1 + fi + echo "Verified live src/ matches HEAD" + + # Save current .next as backup before swapping (kept until health check passes). + if [ -d .next ]; then + mv .next .next.prev + fi + mv "${STAGE}/.next" .next + + # Use the exact node_modules the stage build resolved against. + rm -rf node_modules + mv "${STAGE}/node_modules" node_modules + + # Prisma client is gitignored — regenerate into live src/generated. + pnpm prisma:generate + + sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" "${LIVE}" 2>/dev/null || true + + # Next.js prefers an already-set process PORT over .env. PM2 may still + # have PORT=3000 from an older start, while .env (and nginx) expect 3002. + # Export PORT before start so the process matches health checks. + DEPLOY_PORT="$(grep -E '^[[:space:]]*PORT=' "${LIVE}/.env" 2>/dev/null | tail -1 | cut -d= -f2- || true)" + DEPLOY_PORT="$(printf '%s' "${DEPLOY_PORT}" | tr -cd '0-9')" + DEPLOY_PORT="${DEPLOY_PORT:-3002}" + export PORT="${DEPLOY_PORT}" + echo "PM2/health PORT=${PORT}" + + free_tcp_port() { + local port="$1" + [ -n "${port}" ] || return 0 + if command -v fuser >/dev/null 2>&1; then + fuser -k "${port}/tcp" 2>/dev/null || true + elif command -v lsof >/dev/null 2>&1; then + # Portable fallback when fuser is unavailable. + lsof -tiTCP:"${port}" -sTCP:LISTEN 2>/dev/null | xargs -r kill -9 2>/dev/null || true + fi + } + + echo "Starting PM2 with a clean PORT=${PORT} listener..." + cd "${LIVE}" + # Cutover already stopped the app, but failed deploys can leave orphans + # on 3002 (or an old PM2 env still bound to 3000). + pm2 stop next --kill-timeout 10000 2>/dev/null || true + free_tcp_port "${PORT}" + free_tcp_port 3000 + sleep 1 + pm2 delete next 2>/dev/null || true + PORT="${PORT}" pm2 start pnpm --name next -- start + pm2 save 2>/dev/null || true + + sleep 3 + if ! pm2 show next 2>/dev/null | grep -q 'online'; then + echo "ERROR: PM2 next failed to start!" >&2 + pm2 logs next --lines 20 --nostream >&2 || true + exit 1 + fi + + echo "Waiting for HTTP health check on port ${PORT}..." + HEALTH_URL="${DEPLOY_HEALTH_URL:-http://127.0.0.1:${PORT}/api/health}" + HEALTH_OK=0 + for i in $(seq 1 20); do + BODY="$(curl -sf --max-time 5 "${HEALTH_URL}" 2>/dev/null || true)" + if echo "${BODY}" | grep -q '"database":true'; then + echo "Health OK (${HEALTH_URL})" + HEALTH_OK=1 + break + fi + echo "Health attempt ${i}/20 failed (body=${BODY:-}), retrying..." + sleep 2 + done + if [ "${HEALTH_OK}" != "1" ]; then + echo "ERROR: Health check failed after deploy (${HEALTH_URL})" >&2 + echo "Last body: ${BODY:-}" >&2 + echo "Listeners on PORT ${PORT}:" >&2 + ss -tlnp 2>/dev/null | grep ":${PORT} " >&2 || netstat -tlnp 2>/dev/null | grep ":${PORT} " >&2 || true + pm2 env 0 2>/dev/null | grep -E '^PORT=' >&2 || true + pm2 logs next --lines 40 --nostream >&2 || true + exit 1 + fi + + echo "Cleaning stage worktree and previous .next backup..." + rm -rf "${LIVE}/.next.prev" + git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true + STAGE="" + + echo "--- Deployed successfully ---" + + release: + if: startsWith(gitea.ref_name, 'v') + runs-on: shell + steps: + - name: Build and deploy + env: + VERSION: ${{ gitea.ref_name }} + run: | + set -e + exec 2>&1 + WORK="$(mktemp -d /var/tmp/epicnext-deploy.XXXXXX)" + cleanup() { rm -rf "${WORK}"; } + trap cleanup EXIT + echo "=== Deploying ${VERSION} ===" + git clone --depth 50 \ + /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git \ + "${WORK}" + cd "${WORK}" + git checkout "${VERSION}" + export NODE_ENV=production + export SKIP_ENV_VALIDATION=1 + pnpm install --frozen-lockfile + export DATABASE_URL="mysql://placeholder:please@localhost/placeholder" + pnpm prisma:generate + pnpm build + pm2 restart next --update-env + pm2 save + echo "=== Deploy complete ===" + - name: Create Release + env: + VERSION: ${{ gitea.ref_name }} + GITEA_API: ${{ gitea.api_url }} + GITEA_REPO: ${{ gitea.repository }} + run: | + set -e + exec 2>&1 + BARE="/docker/gitea/gitea/git/repositories/remco/epicnext-cms.git" + echo "=== Creating release for ${VERSION} ===" + + PREV_TAG="$(git -C "$BARE" tag --sort=-creatordate | head -2 | tail -1 || echo '')" + + if [ -n "$PREV_TAG" ] && [ "$PREV_TAG" != "$VERSION" ]; then + CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate --max-count=50 "${PREV_TAG}..${VERSION}")" + [ -z "$CHANGELOG" ] && CHANGELOG="No commit changes since ${PREV_TAG}" + else + TOTAL="$(git -C "$BARE" rev-list --count "${VERSION}" 2>/dev/null || echo '?')" + CHANGELOG="Initial release of EpicNext-CMS (${TOTAL} commits)." + fi + [ -z "$CHANGELOG" ] && CHANGELOG="Initial release" + + # Pin the other components at their current commits so the release is reproducible. + CAT_REF="$(git ls-remote https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily.git Beta-3 2>/dev/null | awk '{print $1}')" + NITRO_REF="$(git ls-remote https://github.com/duckietm/Nitro-V3.git main 2>/dev/null | awk '{print $1}')" + RENDER_REF="$(git ls-remote https://github.com/duckietm/Nitro_Render_V3.git main 2>/dev/null | awk '{print $1}')" + EMU_REF="$(git ls-remote https://github.com/duckietm/Polaris-Emulator.git main 2>/dev/null | awk '{print $1}')" + + { + echo "# EpicNext-CMS ${VERSION}" + echo "" + echo "> Modern, high-performance CMS for Habbo hotel emulators — built on Next.js 16, React 19 and Prisma 7. Integrates with Polaris / Arcturus Morningstar databases." + echo "" + echo "## Menu" + echo "- [What is EpicNext-CMS?](#what-is-epicnext-cms)" + echo "- [System Requirements](#system-requirements)" + echo "- [Installation Wizard](#installation-wizard)" + echo "- [How it is used](#how-it-is-used)" + echo "- [Changes](#changes)" + echo "- [Linked repositories](#linked-repositories)" + echo "" + echo '' + echo "## What is EpicNext-CMS?" + echo "" + echo "EpicNext-CMS is a full public-facing hotel website plus an administrative panel. It features NextAuth authentication (bcrypt with MD5 upgrade), real-time RCON communication with the emulator, Server-Sent Events for live radio, smooth page transitions and extensive extensibility. Full documentation: https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/README.md" + echo "" + echo '' + echo "## System Requirements" + echo "" + echo "What you need to install before running the CMS:" + echo "" + echo "| Component | Version | Notes |" + echo "| --------- | ------- | ----- |" + echo "| Node.js | >= 22 | Required by Next.js 16 |" + echo "| pnpm | >= 10.33.4 | Package manager (npm/yarn not supported) |" + echo "| MySQL / MariaDB | 8.0+ / 10.6+ | Shared with the emulator |" + echo "| Redis | 7.x+ | Optional — caching, rate limiting, SSE |" + echo "| Java | 17+ | Only if building the emulator |" + echo "| Maven | 3.9+ | Only if building the emulator |" + echo "" + echo "The CMS shares its database with the Polaris / Arcturus emulator. It only reads/writes emulator-owned tables and never alters them." + echo "" + echo '' + echo "## Installation Wizard" + echo "" + echo "A complete hotel stack = **EpicNext-CMS** (this repo) + **Polaris Emulator** + **Nitro V3 client** + **Catalogus** data. Follow the steps in order." + echo "" + echo "**Quick links:** [Full setup guide](https://github.com/duckietm/Complete-Retro-on-Ubuntu) · [EpicNext-CMS repo](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms) · [Reference configs in this repo](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup)" + echo "" + echo "### 1. Clone & Install the CMS" + echo '```bash' + echo "git clone https://gitlab.epicnabbo.nl/remco/EpicNext-Cms.git" + echo "cd EpicNext-Cms" + echo "pnpm install" + echo '```' + echo "" + echo "### 2. Database Setup" + echo "" + echo "The CMS shares the emulator database. Import the Polaris/Arcturus database first, then create the CMS schema:" + echo '```sql' + echo "CREATE DATABASE IF NOT EXISTS epicnext_cms CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;" + echo '```' + echo "" + echo "### 3. Configure Environment" + echo '```bash' + echo "cp .env.example .env" + echo '```' + echo "" + echo "Edit .env with at minimum: DATABASE_URL, AUTH_SECRET, HOTEL_NAME and APP_URL. See .env.example for RCON, email, Redis, OAuth and PayPal options." + echo "" + echo "### 4. Generate Prisma Client" + echo '```bash' + echo "pnpm prisma:generate" + echo '```' + echo "" + echo "### 5. Run CMS Migrations" + echo '```bash' + echo "pnpm db:migrate" + echo '```' + echo "" + echo "Creates all CMS-owned tables (website_*, radio_*, acl_*, admin_audit_log). Emulator tables are never touched. Check status with pnpm db:migrate:status." + echo "" + echo "### 6. Polaris Emulator" + echo "" + echo "Clone and build the emulator (requires Java 17+ and Maven 3.9+):" + echo '```bash' + echo "git clone https://github.com/duckietm/Polaris-Emulator.git /var/www/emulator" + echo "cd /var/www/emulator/Emulator" + echo "mvn clean package" + echo '```' + echo "" + echo "Place the built Habbo-*-jar-with-dependencies.jar next to **config.ini** (see [setup/emulator/config.ini](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/config.ini)), then create a systemd unit from [setup/emulator/emulator.service](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/emulator.service) with the [emulator](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/emulator) launcher so it starts on boot. The bundled update-Nitrov3.sh in this repo automates cloning, building and updating the emulator and Nitro — run it any time to pull the latest commits and rebuild:" + echo '```bash' + echo "./update-Nitrov3.sh" + echo '```' + echo "" + echo "### 7. Nitro V3 & Renderer" + echo "" + echo "Clone both Nitro repos and build the client:" + echo '```bash' + echo "git clone https://github.com/duckietm/Nitro_Render_V3.git /var/www/Nitro_Render_V3" + echo "git clone https://github.com/duckietm/Nitro-V3.git /var/www/Nitro-V3" + echo "cd /var/www/Nitro_Render_V3 && yarn install && yarn link" + echo "cd /var/www/Nitro-V3 && yarn install && yarn link \"@nitrots/nitro-renderer\" && yarn build" + echo '```' + echo "" + echo "Copy the reference configs from [setup/nitro/](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/nitro) into /var/www/Nitro-V3/public/configuration, keep them as *.json, and replace **MY_DOMAIN** with your domain, API URL and gamedata paths (see the Full setup guide, NitroV3_And_Emulator.md)." + echo "" + echo "### 8. Catalogus (catalog & gamedata)" + echo "" + echo "Catalogus holds the daily-updated catalog/gamedata. Clone the Beta-3 branch alongside the other components:" + echo '```bash' + echo "git clone -b Beta-3 https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily.git /var/www/catalogus" + echo '```' + echo "" + echo "### 9. Build & Start the CMS" + echo '```bash' + echo "# Development (hot reload)" + echo "pnpm dev" + echo "" + echo "# Production" + echo "pnpm build && pnpm start" + echo '```' + echo "" + echo "Open http://localhost:3000 in your browser." + echo "" + echo "### 10. First Login" + echo "" + echo "1. Register at /register, or log in with an existing emulator account." + echo "2. Grant admin access: UPDATE users SET rank = 7 WHERE username = 'yourname';" + echo "3. Visit /admin and configure your hotel via Admin -> CMS Settings." + echo "" + echo '' + echo "## How it is used" + echo "" + echo "- Public site: browse the hotel, news, radio and the Nitro client at /client." + echo "- Admin panel: /admin for CMS settings, theming (12 presets), users, radio and more." + echo "- Background jobs: run pnpm jobs:worker for daily backups and cleanup." + echo "- Optional: Cloudflare Turnstile / reCAPTCHA, OpenAI moderation and email/PayPal via .env." + echo "" + echo '' + echo "## Changes" + echo '```' + echo "${CHANGELOG}" + echo '```' + echo "" + echo '' + echo "## Linked repositories (exact commits)" + echo "" + echo "The game components below are pinned to the exact commits used by this release and are deployed alongside the CMS:" + echo "" + echo "| Component | Repository | Commit |" + echo "|-----------|------------|--------|" + echo "| Catalogus | https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily | ${CAT_REF:-?} |" + echo "| Nitro-V3 | https://github.com/duckietm/Nitro-V3 | ${NITRO_REF:-?} |" + echo "| Nitro-Render-V3 | https://github.com/duckietm/Nitro_Render_V3 | ${RENDER_REF:-?} |" + echo "| Polaris Emulator | https://github.com/duckietm/Polaris-Emulator | ${EMU_REF:-?} |" + echo "" + echo "**[Nitro-V3](https://github.com/duckietm/Nitro-V3)** · **[Nitro Renderer](https://github.com/duckietm/Nitro_Render_V3)** · **[Polaris Emulator](https://github.com/duckietm/Polaris-Emulator)** · **[Catalogus](https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily)**" + echo "" + echo "---" + echo "*Automated release from Gitea Actions*" + } > /tmp/release-body.md + + PAYLOAD="$(jq -Rs --arg v "${VERSION}" '{tag_name: $v, name: $v, body: ., draft: false, prerelease: false}' < /tmp/release-body.md)" + + TOKEN="${GITEA_TOKEN:-${{ secrets.GITEA_TOKEN }}}" + + HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ + -X POST "${GITEA_API}/repos/${GITEA_REPO}/releases" \ + -H "Authorization: token ${TOKEN}" \ + -H "Content-Type: application/json" \ + -d "$PAYLOAD")" + + if [ "${HTTP_CODE}" = "409" ]; then + RELEASES="$(curl -sf "${GITEA_API}/repos/${GITEA_REPO}/releases" \ + -H "Authorization: token ${TOKEN}")" + REL_ID="$(echo "$RELEASES" | jq -r ".[] | select(.tag_name==\"${VERSION}\") | .id")" + HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ + -X PATCH "${GITEA_API}/repos/${GITEA_REPO}/releases/${REL_ID}" \ + -H "Authorization: token ${TOKEN}" \ + -H "Content-Type: application/json" \ + -d "$PAYLOAD")" + fi + + if [ "${HTTP_CODE:-0}" -ge 200 ] && [ "${HTTP_CODE:-0}" -lt 300 ]; then + echo "SUCCESS: Release ${VERSION} created/updated" + cat /tmp/release-resp.json | jq -r '.html_url // .id' + else + echo "FAILED HTTP ${HTTP_CODE}" + cat /tmp/release-resp.json + exit 1 + fi diff --git a/.gitea/workflows/deploy.yaml b/.gitea/workflows/deploy.yaml deleted file mode 100644 index d46950ae..00000000 --- a/.gitea/workflows/deploy.yaml +++ /dev/null @@ -1,476 +0,0 @@ -name: Deploy -on: - push: - branches: - - main - tags: - - "v*" -jobs: - release: - if: startsWith(gitea.ref_name, 'v') - runs-on: shell - steps: - - name: Build and deploy - env: - VERSION: ${{ gitea.ref_name }} - run: | - set -e - exec 2>&1 - WORK="$(mktemp -d /var/tmp/epicnext-deploy.XXXXXX)" - cleanup() { rm -rf "${WORK}"; } - trap cleanup EXIT - echo "=== Deploying ${VERSION} ===" - git clone --depth 50 \ - /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git \ - "${WORK}" - cd "${WORK}" - git checkout "${VERSION}" - export NODE_ENV=production - export SKIP_ENV_VALIDATION=1 - pnpm install --frozen-lockfile - export DATABASE_URL="mysql://placeholder:please@localhost/placeholder" - pnpm prisma:generate - pnpm build - pm2 restart next --update-env - pm2 save - echo "=== Deploy complete ===" - - name: Create Release - env: - VERSION: ${{ gitea.ref_name }} - GITEA_API: ${{ gitea.api_url }} - GITEA_REPO: ${{ gitea.repository }} - run: | - set -e - exec 2>&1 - BARE="/docker/gitea/gitea/git/repositories/remco/epicnext-cms.git" - echo "=== Creating release for ${VERSION} ===" - - PREV_TAG="$(git -C "$BARE" tag --sort=-creatordate | head -2 | tail -1 || echo '')" - - if [ -n "$PREV_TAG" ] && [ "$PREV_TAG" != "$VERSION" ]; then - CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate --max-count=50 "${PREV_TAG}..${VERSION}")" - [ -z "$CHANGELOG" ] && CHANGELOG="No commit changes since ${PREV_TAG}" - else - TOTAL="$(git -C "$BARE" rev-list --count "${VERSION}" 2>/dev/null || echo '?')" - CHANGELOG="Initial release of EpicNext-CMS (${TOTAL} commits)." - fi - [ -z "$CHANGELOG" ] && CHANGELOG="Initial release" - - # Pin the other components at their current commits so the release is reproducible. - CAT_REF="$(git ls-remote https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily.git Beta-3 2>/dev/null | awk '{print $1}')" - NITRO_REF="$(git ls-remote https://github.com/duckietm/Nitro-V3.git main 2>/dev/null | awk '{print $1}')" - RENDER_REF="$(git ls-remote https://github.com/duckietm/Nitro_Render_V3.git main 2>/dev/null | awk '{print $1}')" - EMU_REF="$(git ls-remote https://github.com/duckietm/Polaris-Emulator.git main 2>/dev/null | awk '{print $1}')" - - { - echo "# EpicNext-CMS ${VERSION}" - echo "" - echo "> Modern, high-performance CMS for Habbo hotel emulators — built on Next.js 16, React 19 and Prisma 7. Integrates with Polaris / Arcturus Morningstar databases." - echo "" - echo "## Menu" - echo "- [What is EpicNext-CMS?](#what-is-epicnext-cms)" - echo "- [System Requirements](#system-requirements)" - echo "- [Installation Wizard](#installation-wizard)" - echo "- [How it is used](#how-it-is-used)" - echo "- [Changes](#changes)" - echo "- [Linked repositories](#linked-repositories)" - echo "" - echo '' - echo "## What is EpicNext-CMS?" - echo "" - echo "EpicNext-CMS is a full public-facing hotel website plus an administrative panel. It features NextAuth authentication (bcrypt with MD5 upgrade), real-time RCON communication with the emulator, Server-Sent Events for live radio, smooth page transitions and extensive extensibility. Full documentation: https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/README.md" - echo "" - echo '' - echo "## System Requirements" - echo "" - echo "What you need to install before running the CMS:" - echo "" - echo "| Component | Version | Notes |" - echo "| --------- | ------- | ----- |" - echo "| Node.js | >= 22 | Required by Next.js 16 |" - echo "| pnpm | >= 10.33.4 | Package manager (npm/yarn not supported) |" - echo "| MySQL / MariaDB | 8.0+ / 10.6+ | Shared with the emulator |" - echo "| Redis | 7.x+ | Optional — caching, rate limiting, SSE |" - echo "| Java | 17+ | Only if building the emulator |" - echo "| Maven | 3.9+ | Only if building the emulator |" - echo "" - echo "The CMS shares its database with the Polaris / Arcturus emulator. It only reads/writes emulator-owned tables and never alters them." - echo "" - echo '' - echo "## Installation Wizard" - echo "" - echo "A complete hotel stack = **EpicNext-CMS** (this repo) + **Polaris Emulator** + **Nitro V3 client** + **Catalogus** data. Follow the steps in order." - echo "" - echo "**Quick links:** [Full setup guide](https://github.com/duckietm/Complete-Retro-on-Ubuntu) · [EpicNext-CMS repo](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms) · [Reference configs in this repo](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup)" - echo "" - echo "### 1. Clone & Install the CMS" - echo '```bash' - echo "git clone https://gitlab.epicnabbo.nl/remco/EpicNext-Cms.git" - echo "cd EpicNext-Cms" - echo "pnpm install" - echo '```' - echo "" - echo "### 2. Database Setup" - echo "" - echo "The CMS shares the emulator database. Import the Polaris/Arcturus database first, then create the CMS schema:" - echo '```sql' - echo "CREATE DATABASE IF NOT EXISTS epicnext_cms CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;" - echo '```' - echo "" - echo "### 3. Configure Environment" - echo '```bash' - echo "cp .env.example .env" - echo '```' - echo "" - echo "Edit .env with at minimum: DATABASE_URL, AUTH_SECRET, HOTEL_NAME and APP_URL. See .env.example for RCON, email, Redis, OAuth and PayPal options." - echo "" - echo "### 4. Generate Prisma Client" - echo '```bash' - echo "pnpm prisma:generate" - echo '```' - echo "" - echo "### 5. Run CMS Migrations" - echo '```bash' - echo "pnpm db:migrate" - echo '```' - echo "" - echo "Creates all CMS-owned tables (website_*, radio_*, acl_*, admin_audit_log). Emulator tables are never touched. Check status with pnpm db:migrate:status." - echo "" - echo "### 6. Polaris Emulator" - echo "" - echo "Clone and build the emulator (requires Java 17+ and Maven 3.9+):" - echo '```bash' - echo "git clone https://github.com/duckietm/Polaris-Emulator.git /var/www/emulator" - echo "cd /var/www/emulator/Emulator" - echo "mvn clean package" - echo '```' - echo "" - echo "Place the built Habbo-*-jar-with-dependencies.jar next to **config.ini** (see [setup/emulator/config.ini](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/config.ini)), then create a systemd unit from [setup/emulator/emulator.service](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/emulator.service) with the [emulator](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/emulator) launcher so it starts on boot. The bundled update-Nitrov3.sh in this repo automates cloning, building and updating the emulator and Nitro — run it any time to pull the latest commits and rebuild:" - echo '```bash' - echo "./update-Nitrov3.sh" - echo '```' - echo "" - echo "### 7. Nitro V3 & Renderer" - echo "" - echo "Clone both Nitro repos and build the client:" - echo '```bash' - echo "git clone https://github.com/duckietm/Nitro_Render_V3.git /var/www/Nitro_Render_V3" - echo "git clone https://github.com/duckietm/Nitro-V3.git /var/www/Nitro-V3" - echo "cd /var/www/Nitro_Render_V3 && yarn install && yarn link" - echo "cd /var/www/Nitro-V3 && yarn install && yarn link \"@nitrots/nitro-renderer\" && yarn build" - echo '```' - echo "" - echo "Copy the reference configs from [setup/nitro/](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/nitro) into /var/www/Nitro-V3/public/configuration, keep them as *.json, and replace **MY_DOMAIN** with your domain, API URL and gamedata paths (see the Full setup guide, NitroV3_And_Emulator.md)." - echo "" - echo "### 8. Catalogus (catalog & gamedata)" - echo "" - echo "Catalogus holds the daily-updated catalog/gamedata. Clone the Beta-3 branch alongside the other components:" - echo '```bash' - echo "git clone -b Beta-3 https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily.git /var/www/catalogus" - echo '```' - echo "" - echo "### 9. Build & Start the CMS" - echo '```bash' - echo "# Development (hot reload)" - echo "pnpm dev" - echo "" - echo "# Production" - echo "pnpm build && pnpm start" - echo '```' - echo "" - echo "Open http://localhost:3000 in your browser." - echo "" - echo "### 10. First Login" - echo "" - echo "1. Register at /register, or log in with an existing emulator account." - echo "2. Grant admin access: UPDATE users SET rank = 7 WHERE username = 'yourname';" - echo "3. Visit /admin and configure your hotel via Admin -> CMS Settings." - echo "" - echo '' - echo "## How it is used" - echo "" - echo "- Public site: browse the hotel, news, radio and the Nitro client at /client." - echo "- Admin panel: /admin for CMS settings, theming (12 presets), users, radio and more." - echo "- Background jobs: run pnpm jobs:worker for daily backups and cleanup." - echo "- Optional: Cloudflare Turnstile / reCAPTCHA, OpenAI moderation and email/PayPal via .env." - echo "" - echo '' - echo "## Changes" - echo '```' - echo "${CHANGELOG}" - echo '```' - echo "" - echo '' - echo "## Linked repositories (exact commits)" - echo "" - echo "The game components below are pinned to the exact commits used by this release and are deployed alongside the CMS:" - echo "" - echo "| Component | Repository | Commit |" - echo "|-----------|------------|--------|" - echo "| Catalogus | https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily | ${CAT_REF:-?} |" - echo "| Nitro-V3 | https://github.com/duckietm/Nitro-V3 | ${NITRO_REF:-?} |" - echo "| Nitro-Render-V3 | https://github.com/duckietm/Nitro_Render_V3 | ${RENDER_REF:-?} |" - echo "| Polaris Emulator | https://github.com/duckietm/Polaris-Emulator | ${EMU_REF:-?} |" - echo "" - echo "**[Nitro-V3](https://github.com/duckietm/Nitro-V3)** · **[Nitro Renderer](https://github.com/duckietm/Nitro_Render_V3)** · **[Polaris Emulator](https://github.com/duckietm/Polaris-Emulator)** · **[Catalogus](https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily)**" - echo "" - echo "---" - echo "*Automated release from Gitea Actions*" - } > /tmp/release-body.md - - PAYLOAD="$(jq -Rs --arg v "${VERSION}" '{tag_name: $v, name: $v, body: ., draft: false, prerelease: false}' < /tmp/release-body.md)" - - TOKEN="${GITEA_TOKEN:-${{ secrets.GITEA_TOKEN }}}" - - HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ - -X POST "${GITEA_API}/repos/${GITEA_REPO}/releases" \ - -H "Authorization: token ${TOKEN}" \ - -H "Content-Type: application/json" \ - -d "$PAYLOAD")" - - if [ "${HTTP_CODE}" = "409" ]; then - RELEASES="$(curl -sf "${GITEA_API}/repos/${GITEA_REPO}/releases" \ - -H "Authorization: token ${TOKEN}")" - REL_ID="$(echo "$RELEASES" | jq -r ".[] | select(.tag_name==\"${VERSION}\") | .id")" - HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ - -X PATCH "${GITEA_API}/repos/${GITEA_REPO}/releases/${REL_ID}" \ - -H "Authorization: token ${TOKEN}" \ - -H "Content-Type: application/json" \ - -d "$PAYLOAD")" - fi - - if [ "${HTTP_CODE:-0}" -ge 200 ] && [ "${HTTP_CODE:-0}" -lt 300 ]; then - echo "SUCCESS: Release ${VERSION} created/updated" - cat /tmp/release-resp.json | jq -r '.html_url // .id' - else - echo "FAILED HTTP ${HTTP_CODE}" - cat /tmp/release-resp.json - exit 1 - fi - deploy: - if: startsWith(gitea.ref_name, 'v') == false - runs-on: shell - steps: - - name: Deploy - run: | - set -e - - exec 9>/var/tmp/epic_web_control_deploy.lock - flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; } - - echo "--- Deploying ---" - - LIVE="/var/www/atom-nexst" - STAGE="" - CUTOVER_STARTED=0 - - error_handler() { - cd /var/www/atom-nexst 2>/dev/null || cd / || true - echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2 - # Roll back the build artifact if cutover already moved .next into place. - if [ "${CUTOVER_STARTED}" = "1" ] && [ -d "${LIVE}/.next.prev" ]; then - echo "Rolling back .next to previous artifact..." >&2 - rm -rf "${LIVE}/.next" || true - mv "${LIVE}/.next.prev" "${LIVE}/.next" || true - fi - if [ -n "${STAGE}" ] && [ -d "${STAGE}" ]; then - git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true - fi - pm2 restart next --update-env 2>/dev/null || pm2 start pnpm --name "next" -- start 2>/dev/null || true - exit 1 - } - trap 'error_handler $LINENO' ERR - - docker image prune -f - - DEPLOY_USER="$(id -un)" - DEPLOY_GROUP="$(id -gn)" - sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" "${LIVE}" 2>/dev/null || true - git config --global --add safe.directory "${LIVE}" - git -C "${LIVE}" remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/ - - echo "Fetching origin/main..." - git -C "${LIVE}" fetch origin --prune - - echo "Clearing sticky git index bits (if any)..." - STICKY_LIST="$(git -C "${LIVE}" ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' || true)" - if [ -n "${STICKY_LIST}" ]; then - echo "${STICKY_LIST}" | while IFS= read -r f; do - [ -n "$f" ] || continue - git -C "${LIVE}" update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true - done - fi - - export APP_VERSION="$(git -C "${LIVE}" rev-parse --short origin/main)" - export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}" - echo "APP_VERSION=${APP_VERSION}" - - STAGE="/var/tmp/atom-nexst-stage-${APP_VERSION}" - echo "Preparing stage worktree at ${STAGE} (live site stays up)..." - git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true - git -C "${LIVE}" worktree add --detach "${STAGE}" origin/main - - # Production env stays on the live tree; stage only needs a symlink for build/migrate. - ln -sfn "${LIVE}/.env" "${STAGE}/.env" - - if ! grep -qE '^[[:space:]]*REDIS_URL=.+' "${LIVE}/.env" 2>/dev/null; then - echo "WARNING: REDIS_URL is unset in ${LIVE}/.env" >&2 - echo "WARNING: Rate limits, site-settings cache, and JWT invalidation cache will be in-process only." >&2 - fi - - cd "${STAGE}" - rm -f tsconfig.tsbuildinfo .tsbuildinfo - find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true - rm -rf .output dist .next .next/types .next/dev - - # Restore build cache from last deploy so Turbopack can do - # incremental compilation (much faster rebuilds). - if [ -d "${LIVE}/.next/cache" ]; then - mkdir -p .next/cache - cp -r "${LIVE}/.next/cache/." .next/cache/ - fi - - # Stage shares MySQL with the live app + emulator. Keep the stage pool - # tiny so install/test/build cannot exhaust max_connections. - export DATABASE_POOL_SIZE="${DEPLOY_DATABASE_POOL_SIZE:-5}" - echo "STAGE DATABASE_POOL_SIZE=${DATABASE_POOL_SIZE}" - - pnpm install --frozen-lockfile - # prisma generate only needs DATABASE_URL to resolve the schema — no live DB connection. - # Use a placeholder so it doesn't fail if .env isn't loaded yet; db:migrate later - # will use the real DATABASE_URL from the live .env symlink. - export DATABASE_URL="mysql://placeholder:please@localhost/placeholder" - pnpm prisma:generate - unset DATABASE_URL - export BCRYPT_ROUNDS=4 - pnpm typecheck - # Validate production env (AUTH_SECRET, DATABASE_URL, …) during build. - # Do not set SKIP_ENV_VALIDATION here — that flag is for tests/tooling only. - pnpm build - - if [ ! -d "${STAGE}/.next" ]; then - echo "ERROR: stage build produced no .next/" >&2 - exit 1 - fi - - echo "Cutover: stop service (free DB connections), migrate, swap .next..." - CUTOVER_STARTED=1 - pm2 stop next --kill-timeout 10000 || true - # Wait for PM2 to fully exit and MariaDB to reclaim connections. - sleep 10 - - # Migrate only after live is stopped — avoids ER_CON_COUNT_ERROR while - # the old process still holds DATABASE_POOL_SIZE connections. - cd "${STAGE}" - MIGRATE_OK=0 - for i in $(seq 1 10); do - if pnpm db:migrate; then - MIGRATE_OK=1 - break - fi - echo "migrate attempt ${i}/10 failed (likely DB connections), retrying..." - sleep 5 - done - if [ "${MIGRATE_OK}" != "1" ]; then - echo "ERROR: db:migrate failed after retries" >&2 - exit 1 - fi - - cd "${LIVE}" - echo "Hard reset live tree to origin/main (no nuclear src wipe)..." - git reset --hard origin/main - # Keep env, uploads, and deps we are about to replace from stage. - git clean -fd \ - -e .env -e .env.local -e .env.production -e .env*.local \ - -e storage -e public/cache -e node_modules -e .next -e .next.prev - - if ! git diff --exit-code HEAD -- src >/dev/null; then - echo "ERROR: live src/ still differs from HEAD after reset:" >&2 - git diff --stat HEAD -- src >&2 || true - exit 1 - fi - echo "Verified live src/ matches HEAD" - - # Save current .next as backup before swapping (kept until health check passes). - if [ -d .next ]; then - mv .next .next.prev - fi - mv "${STAGE}/.next" .next - - # Use the exact node_modules the stage build resolved against. - rm -rf node_modules - mv "${STAGE}/node_modules" node_modules - - # Prisma client is gitignored — regenerate into live src/generated. - pnpm prisma:generate - - sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" "${LIVE}" 2>/dev/null || true - - # Next.js prefers an already-set process PORT over .env. PM2 may still - # have PORT=3000 from an older start, while .env (and nginx) expect 3002. - # Export PORT before start so the process matches health checks. - DEPLOY_PORT="$(grep -E '^[[:space:]]*PORT=' "${LIVE}/.env" 2>/dev/null | tail -1 | cut -d= -f2- || true)" - DEPLOY_PORT="$(printf '%s' "${DEPLOY_PORT}" | tr -cd '0-9')" - DEPLOY_PORT="${DEPLOY_PORT:-3002}" - export PORT="${DEPLOY_PORT}" - echo "PM2/health PORT=${PORT}" - - free_tcp_port() { - local port="$1" - [ -n "${port}" ] || return 0 - if command -v fuser >/dev/null 2>&1; then - fuser -k "${port}/tcp" 2>/dev/null || true - elif command -v lsof >/dev/null 2>&1; then - # Portable fallback when fuser is unavailable. - lsof -tiTCP:"${port}" -sTCP:LISTEN 2>/dev/null | xargs -r kill -9 2>/dev/null || true - fi - } - - echo "Starting PM2 with a clean PORT=${PORT} listener..." - cd "${LIVE}" - # Cutover already stopped the app, but failed deploys can leave orphans - # on 3002 (or an old PM2 env still bound to 3000). - pm2 stop next --kill-timeout 10000 2>/dev/null || true - free_tcp_port "${PORT}" - free_tcp_port 3000 - sleep 1 - pm2 delete next 2>/dev/null || true - PORT="${PORT}" pm2 start pnpm --name next -- start - pm2 save 2>/dev/null || true - - sleep 3 - if ! pm2 show next 2>/dev/null | grep -q 'online'; then - echo "ERROR: PM2 next failed to start!" >&2 - pm2 logs next --lines 20 --nostream >&2 || true - exit 1 - fi - - echo "Waiting for HTTP health check on port ${PORT}..." - HEALTH_URL="${DEPLOY_HEALTH_URL:-http://127.0.0.1:${PORT}/api/health}" - HEALTH_OK=0 - for i in $(seq 1 20); do - BODY="$(curl -sf --max-time 5 "${HEALTH_URL}" 2>/dev/null || true)" - if echo "${BODY}" | grep -q '"database":true'; then - echo "Health OK (${HEALTH_URL})" - HEALTH_OK=1 - break - fi - echo "Health attempt ${i}/20 failed (body=${BODY:-}), retrying..." - sleep 2 - done - if [ "${HEALTH_OK}" != "1" ]; then - echo "ERROR: Health check failed after deploy (${HEALTH_URL})" >&2 - echo "Last body: ${BODY:-}" >&2 - echo "Listeners on PORT ${PORT}:" >&2 - ss -tlnp 2>/dev/null | grep ":${PORT} " >&2 || netstat -tlnp 2>/dev/null | grep ":${PORT} " >&2 || true - pm2 env 0 2>/dev/null | grep -E '^PORT=' >&2 || true - pm2 logs next --lines 40 --nostream >&2 || true - exit 1 - fi - - echo "Cleaning stage worktree and previous .next backup..." - rm -rf "${LIVE}/.next.prev" - git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true - STAGE="" - - echo "--- Deployed successfully ---" diff --git a/src/lib/ci-workflow-contract.test.ts b/src/lib/ci-workflow-contract.test.ts index 49e0841b..2e951208 100644 --- a/src/lib/ci-workflow-contract.test.ts +++ b/src/lib/ci-workflow-contract.test.ts @@ -8,18 +8,27 @@ describe("CI workflow", () => { "utf8", ); - it("only runs check (lint/typecheck/test), not production deploy", () => { + it("runs check then production deploy on push to main", () => { expect(workflow).toContain("pnpm biome:lint"); expect(workflow).toContain("pnpm typecheck"); expect(workflow).toContain("pnpm test"); - expect(workflow).not.toMatch(/\n\s*deploy:\s*\n/); - expect(workflow).not.toContain("pm2 restart"); - expect(workflow).not.toContain("pm2 start"); + expect(workflow).toContain("needs: check"); + expect(workflow).toContain( + "gitea.event_name == 'push' && gitea.ref_name == 'main'", + ); + expect(workflow).toContain("worktree add --detach"); + expect(workflow).toContain("/api/health"); expect(workflow).not.toContain("github.ref"); }); - it("uses Gitea SHA for checkout", () => { + it("uses Gitea SHA for check checkout", () => { expect(workflow).toContain("gitea.sha"); expect(workflow).toContain("SKIP_ENV_VALIDATION=1"); }); + + it("keeps tag release in the same workflow", () => { + expect(workflow).toContain('tags:\n - "v*"'); + expect(workflow).toContain("Creating release for"); + expect(workflow).toContain("startsWith(gitea.ref_name, 'v')"); + }); }); diff --git a/src/lib/deploy-workflow-contract.test.ts b/src/lib/deploy-workflow-contract.test.ts index 0f7a97c2..8eb78609 100644 --- a/src/lib/deploy-workflow-contract.test.ts +++ b/src/lib/deploy-workflow-contract.test.ts @@ -14,10 +14,22 @@ function toContainLiteral(workflow: string, literal: string) { describe("production deploy workflow", () => { const workflow = readFileSync( - resolve(process.cwd(), ".gitea/workflows/deploy.yaml"), + resolve(process.cwd(), ".gitea/workflows/ci.yaml"), "utf8", ); - const deployJob = workflow.slice(workflow.indexOf("\n deploy:")); + const deployStart = workflow.indexOf("\n deploy:"); + const afterDeploy = workflow.indexOf("\n release:", deployStart + 1); + const deployJob = + afterDeploy > deployStart + ? workflow.slice(deployStart, afterDeploy) + : workflow.slice(deployStart); + + it("is gated behind the check job", () => { + expect(deployJob).toContain("needs: check"); + expect(deployJob).toContain( + "gitea.event_name == 'push' && gitea.ref_name == 'main'", + ); + }); it("builds in a stage worktree while preserving live .env and storage", () => { expect(deployJob).toContain("worktree add --detach");