diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index e1ed3524..dae5a74f 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -70,7 +70,7 @@ jobs: # overslaan is verboden voor productie). .env staat niet in git, # dus kopieer de productie-.env van de host in de build-context. # Hij belandt alleen in de wegwerp-builder-stage, niet in de - # runtime-image (die krijgt env via --env-file bij docker run). + # runtime-image (die krijgt env via -e flags bij docker run). cp /var/www/atom-nexst/.env .env - name: Build image @@ -85,6 +85,7 @@ jobs: -t epicnext-cms:latest . - name: Deploy container + shell: bash run: | # Maak poort 3002 vrij: stop zowel de vorige CI-container als de # compose-container (beide draaien op het host-netwerk). @@ -93,13 +94,30 @@ jobs: docker stop epicnext-cms 2>/dev/null || true docker rm epicnext-cms 2>/dev/null || true + # Geef de productie-env 1-op-1 door. GEEN env-file-flag: `docker run` + # behoudt letterlijke quotes uit het bestand (DATABASE_URL="..." → + # ongeldige URL en crash), terwijl de shell ze correct stript. + # Sourcen + elke sleutel met -e doorgeven geeft de container exact + # dezelfde waarden als waarmee de image gebouwd is. + set -a + # shellcheck disable=SC1091 + . /var/www/atom-nexst/.env + set +a + ENV_ARGS=() + while IFS='=' read -r key _; do + case "$key" in + ''|'#'*|*[!A-Za-z0-9_]* ) continue ;; + esac + ENV_ARGS+=(-e "$key") + done < /var/www/atom-nexst/.env + # Zelfde env + volumes als docker-compose.yml, zodat de CI-container # functioneel gelijk is aan de compose-container die hij vervangt. docker run -d \ --name epicnext-cms-app \ --restart always \ --net=host \ - --env-file /var/www/atom-nexst/.env \ + "${ENV_ARGS[@]}" \ -v /var/www/atom-nexst/public/nitro-assets:/app/public/nitro-assets \ -v /var/www/atom-nexst/public/swf:/app/public/swf \ -v /var/www/atom-nexst/storage:/app/storage \ diff --git a/src/lib/deploy-workflow-contract.test.ts b/src/lib/deploy-workflow-contract.test.ts index 6e22a70c..73cce9b9 100644 --- a/src/lib/deploy-workflow-contract.test.ts +++ b/src/lib/deploy-workflow-contract.test.ts @@ -44,11 +44,16 @@ describe("deploy job", () => { }); it("runs container with production env and volumes", () => { - expect(deployJob).toContain("--env-file /var/www/atom-nexst/.env"); + expect(deployJob).toContain(". /var/www/atom-nexst/.env"); + expect(deployJob).toContain('"${ENV_ARGS[@]}"'); expect(deployJob).toContain("/var/www/Gamedata:/var/www/Gamedata"); expect(deployJob).toContain("/app/storage"); }); + it("does not use --env-file (it keeps literal quotes)", () => { + expect(deployJob).not.toContain("--env-file"); + }); + it("frees port 3002 by stopping the compose container", () => { expect(deployJob).toContain("docker stop epicnext-cms 2>/dev/null || true"); });