diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index a8ced99b..1a6e50be 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -1,4 +1,5 @@ name: CI + on: push: branches: @@ -11,38 +12,43 @@ on: jobs: check: - runs-on: shell + runs-on: ubuntu-latest + + env: + SKIP_ENV_VALIDATION: 1 + ARGON2_MEMORY_SIZE: 1024 + ARGON2_ITERATIONS: 1 + BCRYPT_ROUNDS: 4 + DATABASE_URL: "mysql://ci:dummy@127.0.0.1:3306/ci" + steps: - - name: Typecheck, lint, security audit, and test - run: | - set -e - WORK="$(mktemp -d /var/tmp/epicnext-ci.XXXXXX)" - cleanup() { rm -rf "${WORK}"; } - trap cleanup EXIT + - name: Checkout code + uses: actions/checkout@v4 - echo "--- CI checks (${WORK}) ---" - git clone --depth 50 \ - /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git \ - "${WORK}" - cd "${WORK}" + - name: Setup Node.js + uses: actions/setup-node@v4 + with: + node-version: 22 - REF="${{ gitea.sha }}" - if [ -z "${REF}" ]; then - echo "ERROR: missing gitea.sha" >&2 - exit 1 - fi - git fetch --depth 50 origin "${REF}" - git checkout -f "${REF}" + - name: Setup PNPM + uses: pnpm/action-setup@v4 + with: + version: 10 - export SKIP_ENV_VALIDATION=1 - export ARGON2_MEMORY_SIZE=1024 - export ARGON2_ITERATIONS=1 - export BCRYPT_ROUNDS=4 - export DATABASE_URL="mysql://ci:dummy@127.0.0.1:3306/ci" - pnpm install --frozen-lockfile - pnpm prisma:generate - pnpm audit --audit-level=high || echo "WARNING: pnpm audit found high/critical vulnerabilities" - pnpm biome:lint - pnpm typecheck - pnpm test - echo "--- CI checks passed ---" + - name: Install dependencies + run: pnpm install --frozen-lockfile + + - name: Generate Prisma Client + run: pnpm prisma:generate + + - name: Security Audit + run: pnpm audit --audit-level=high || echo "WARNING: pnpm audit found vulnerabilities" + + - name: Biome Linter + run: pnpm biome:lint + + - name: TypeScript Typecheck + run: pnpm typecheck + + - name: Run Tests + run: pnpm test \ No newline at end of file diff --git a/.gitea/workflows/deploy.yaml b/.gitea/workflows/deploy.yaml index 0aeff37d..c96f0800 100644 --- a/.gitea/workflows/deploy.yaml +++ b/.gitea/workflows/deploy.yaml @@ -33,15 +33,15 @@ jobs: [ -z "$CHANGELOG" ] && CHANGELOG="Initial release" # Pin the other components at their current commits so the release is reproducible. - CAT_REF="$(git ls-remote https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily.git Beta-3 2>/dev/null | awk '{print $1}')" - NITRO_REF="$(git ls-remote https://github.com/duckietm/Nitro-V3.git main 2>/dev/null | awk '{print $1}')" - RENDER_REF="$(git ls-remote https://github.com/duckietm/Nitro_Render_V3.git main 2>/dev/null | awk '{print $1}')" - EMU_REF="$(git ls-remote https://github.com/duckietm/Polaris-Emulator.git main 2>/dev/null | awk '{print $1}')" + CAT_REF="$(git ls-remote https://epicnabbo.nl Beta-3 2>/dev/null | awk '{print $1}')" + NITRO_REF="$(git ls-remote https://github.com main 2>/dev/null | awk '{print $1}')" + RENDER_REF="$(git ls-remote https://github.com main 2>/dev/null | awk '{print $1}')" + EMU_REF="$(git ls-remote https://github.com main 2>/dev/null | awk '{print $1}')" { echo "# EpicNext-CMS ${VERSION}" echo "" - echo "> Modern, high-performance CMS for Habbo hotel emulators — built on Next.js 16, React 19 and Prisma 7. Integrates with Polaris / Arcturus Morningstar databases." + echo "> Modern, high-performance CMS for Habbo hotel emulators — built on Next.js 16, React 19 and Prisma 7. Integrates with Polaris / Arcturus Morningstar databases." echo "" echo "## Menu" echo "- [What is EpicNext-CMS?](#what-is-epicnext-cms)" @@ -54,7 +54,7 @@ jobs: echo '' echo "## What is EpicNext-CMS?" echo "" - echo "EpicNext-CMS is a full public-facing hotel website plus an administrative panel. It features NextAuth authentication (argon2id/bcrypt with MD5 upgrade), real-time RCON communication with the emulator, Server-Sent Events for live radio, smooth page transitions and extensive extensibility. Full documentation: https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/README.md" + echo "EpicNext-CMS is a full public-facing hotel website plus an administrative panel. It features NextAuth authentication (argon2id/bcrypt with MD5 upgrade), real-time RCON communication with the emulator, Server-Sent Events for live radio, smooth page transitions and extensive extensibility. Full documentation: https://epicnabbo.nl" echo "" echo '' echo "## System Requirements" @@ -66,7 +66,7 @@ jobs: echo "| Node.js | >= 22 | Required by Next.js 16 |" echo "| pnpm | >= 10.33.4 | Package manager (npm/yarn not supported) |" echo "| MySQL / MariaDB | 8.0+ / 10.6+ | Shared with the emulator |" - echo "| Redis | 7.x+ | Optional — caching, rate limiting, SSE |" + echo "| Redis | 7.x+ | Optional — caching, rate limiting, SSE |" echo "| Java | 17+ | Only if building the emulator |" echo "| Maven | 3.9+ | Only if building the emulator |" echo "" @@ -77,11 +77,11 @@ jobs: echo "" echo "A complete hotel stack = **EpicNext-CMS** (this repo) + **Polaris Emulator** + **Nitro V3 client** + **Catalogus** data. Follow the steps in order." echo "" - echo "**Quick links:** [Full setup guide](https://github.com/duckietm/Complete-Retro-on-Ubuntu) · [EpicNext-CMS repo](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms) · [Reference configs in this repo](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup)" + echo "**Quick links:** [Full setup guide](https://github.com) · [EpicNext-CMS repo](https://epicnabbo.nl) · [Reference configs in this repo](https://epicnabbo.nl/src/branch/main/setup)" echo "" echo "### 1. Clone & Install the CMS" echo '```bash' - echo "git clone https://gitlab.epicnabbo.nl/remco/EpicNext-Cms.git" + echo "git clone https://epicnabbo.nl.git" echo "cd EpicNext-Cms" echo "pnpm install" echo '```' @@ -116,12 +116,12 @@ jobs: echo "" echo "Clone and build the emulator (requires Java 17+ and Maven 3.9+):" echo '```bash' - echo "git clone https://github.com/duckietm/Polaris-Emulator.git /var/www/emulator" + echo "git clone https://github.com /var/www/emulator" echo "cd /var/www/emulator/Emulator" echo "mvn clean package" echo '```' echo "" - echo "Place the built Habbo-*-jar-with-dependencies.jar next to **config.ini** (see [setup/emulator/config.ini](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/config.ini)), then create a systemd unit from [setup/emulator/emulator.service](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/emulator.service) with the [emulator](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/emulator/emulator) launcher so it starts on boot. The bundled update-Nitrov3.sh in this repo automates cloning, building and updating the emulator and Nitro — run it any time to pull the latest commits and rebuild:" + echo "Place the built Habbo-*-jar-with-dependencies.jar next to **config.ini** (see [setup/emulator/config.ini](https://epicnabbo.nl/src/branch/main/setup/emulator/config.ini)), then create a systemd unit from [setup/emulator/emulator.service](https://epicnabbo.nl/src/branch/main/setup/emulator/emulator.service) with the [emulator](https://epicnabbo.nl/src/branch/main/setup/emulator/emulator) launcher so it starts on boot. The bundled update-Nitrov3.sh in this repo automates cloning, building and updating the emulator and Nitro — run it any time to pull the latest commits and rebuild:" echo '```bash' echo "./update-Nitrov3.sh" echo '```' @@ -130,19 +130,19 @@ jobs: echo "" echo "Clone both Nitro repos and build the client:" echo '```bash' - echo "git clone https://github.com/duckietm/Nitro_Render_V3.git /var/www/Nitro_Render_V3" - echo "git clone https://github.com/duckietm/Nitro-V3.git /var/www/Nitro-V3" + echo "git clone https://github.com /var/www/Nitro_Render_V3" + echo "git clone https://github.com /var/www/Nitro-V3" echo "cd /var/www/Nitro_Render_V3 && yarn install && yarn link" echo "cd /var/www/Nitro-V3 && yarn install && yarn link \"@nitrots/nitro-renderer\" && yarn build" echo '```' echo "" - echo "Copy the reference configs from [setup/nitro/](https://gitlab.epicnabbo.nl/remco/EpicNext-Cms/src/branch/main/setup/nitro) into /var/www/Nitro-V3/public/configuration, keep them as *.json, and replace **MY_DOMAIN** with your domain, API URL and gamedata paths (see the Full setup guide, NitroV3_And_Emulator.md)." + echo "Copy the reference configs from [setup/nitro/](https://epicnabbo.nl/src/branch/main/setup/nitro) into /var/www/Nitro-V3/public/configuration, keep them as *.json, and replace **MY_DOMAIN** with your domain, API URL and gamedata paths (see the Full setup guide, NitroV3_And_Emulator.md)." echo "" echo "### 8. Catalogus (catalog & gamedata)" echo "" echo "Catalogus holds the daily-updated catalog/gamedata. Clone the Beta-3 branch alongside the other components:" echo '```bash' - echo "git clone -b Beta-3 https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily.git /var/www/catalogus" + echo "git clone -b Beta-3 https://epicnabbo.nl /var/www/catalogus" echo '```' echo "" echo "### 9. Build & Start the CMS" @@ -176,242 +176,4 @@ jobs: echo "${CHANGELOG}" echo '```' echo "" - echo '' - echo "## Linked repositories (exact commits)" - echo "" - echo "The game components below are pinned to the exact commits used by this release and are deployed alongside the CMS:" - echo "" - echo "| Component | Repository | Commit |" - echo "|-----------|------------|--------|" - echo "| Catalogus | https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily | ${CAT_REF:-?} |" - echo "| Nitro-V3 | https://github.com/duckietm/Nitro-V3 | ${NITRO_REF:-?} |" - echo "| Nitro-Render-V3 | https://github.com/duckietm/Nitro_Render_V3 | ${RENDER_REF:-?} |" - echo "| Polaris Emulator | https://github.com/duckietm/Polaris-Emulator | ${EMU_REF:-?} |" - echo "" - echo "**[Nitro-V3](https://github.com/duckietm/Nitro-V3)** · **[Nitro Renderer](https://github.com/duckietm/Nitro_Render_V3)** · **[Polaris Emulator](https://github.com/duckietm/Polaris-Emulator)** · **[Catalogus](https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily)**" - echo "" - echo "---" - echo "*Automated release from Gitea Actions*" - } > /tmp/release-body.md - - PAYLOAD="$(jq -Rs --arg v "${VERSION}" '{tag_name: $v, name: $v, body: ., draft: false, prerelease: false}' < /tmp/release-body.md)" - - TOKEN="${GITEA_TOKEN:-${{ secrets.GITEA_TOKEN }}}" - - HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ - -X POST "${GITEA_API}/repos/${GITEA_REPO}/releases" \ - -H "Authorization: token ${TOKEN}" \ - -H "Content-Type: application/json" \ - -d "$PAYLOAD")" - - if [ "${HTTP_CODE}" = "409" ]; then - RELEASES="$(curl -sf "${GITEA_API}/repos/${GITEA_REPO}/releases" \ - -H "Authorization: token ${TOKEN}")" - REL_ID="$(echo "$RELEASES" | jq -r ".[] | select(.tag_name==\"${VERSION}\") | .id")" - HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ - -X PATCH "${GITEA_API}/repos/${GITEA_REPO}/releases/${REL_ID}" \ - -H "Authorization: token ${TOKEN}" \ - -H "Content-Type: application/json" \ - -d "$PAYLOAD")" - fi - - if [ "${HTTP_CODE:-0}" -ge 200 ] && [ "${HTTP_CODE:-0}" -lt 300 ]; then - echo "SUCCESS: Release ${VERSION} created/updated" - cat /tmp/release-resp.json | jq -r '.html_url // .id' - else - echo "FAILED HTTP ${HTTP_CODE}" - cat /tmp/release-resp.json - exit 1 - fi - deploy: - if: startsWith(gitea.ref_name, 'v') == false - runs-on: shell - steps: - - name: Deploy - run: | - set -e - - exec 9>/var/tmp/epic_web_control_deploy.lock - flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; } - - echo "--- Deploying ---" - - LIVE="/var/www/atom-nexst" - STAGE="" - CUTOVER_STARTED=0 - - error_handler() { - cd /var/www/atom-nexst 2>/dev/null || cd / || true - echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2 - # Roll back the build artifact if cutover already moved .next into place. - if [ "${CUTOVER_STARTED}" = "1" ] && [ -d "${LIVE}/.next.prev" ]; then - echo "Rolling back .next to previous artifact..." >&2 - rm -rf "${LIVE}/.next" || true - mv "${LIVE}/.next.prev" "${LIVE}/.next" || true - fi - if [ -n "${STAGE}" ] && [ -d "${STAGE}" ]; then - git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true - fi - pm2 restart next --update-env 2>/dev/null || pm2 start pnpm --name "next" -- start 2>/dev/null || true - exit 1 - } - trap 'error_handler $LINENO' ERR - - docker image prune -f - - DEPLOY_USER="$(id -un)" - DEPLOY_GROUP="$(id -gn)" - sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" "${LIVE}" 2>/dev/null || true - git config --global --add safe.directory "${LIVE}" - git -C "${LIVE}" remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/ - - echo "Fetching origin/main..." - git -C "${LIVE}" fetch origin --prune - - echo "Clearing sticky git index bits (if any)..." - STICKY_LIST="$(git -C "${LIVE}" ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' || true)" - if [ -n "${STICKY_LIST}" ]; then - echo "${STICKY_LIST}" | while IFS= read -r f; do - [ -n "$f" ] || continue - git -C "${LIVE}" update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true - done - fi - - export APP_VERSION="$(git -C "${LIVE}" rev-parse --short origin/main)" - export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}" - echo "APP_VERSION=${APP_VERSION}" - - STAGE="/var/tmp/atom-nexst-stage-${APP_VERSION}" - echo "Preparing stage worktree at ${STAGE} (live site stays up)..." - git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true - git -C "${LIVE}" worktree add --detach "${STAGE}" origin/main - - # Production env stays on the live tree; stage only needs a symlink for build/migrate. - ln -sfn "${LIVE}/.env" "${STAGE}/.env" - - if ! grep -qE '^[[:space:]]*REDIS_URL=.+' "${LIVE}/.env" 2>/dev/null; then - echo "WARNING: REDIS_URL is unset in ${LIVE}/.env" >&2 - echo "WARNING: Rate limits, site-settings cache, and JWT invalidation cache will be in-process only." >&2 - fi - - cd "${STAGE}" - rm -f tsconfig.tsbuildinfo .tsbuildinfo - find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true - rm -rf .output dist .next .next/types .next/dev - - # Restore build cache from last deploy so Turbopack can do - # incremental compilation (much faster rebuilds). - if [ -d "${LIVE}/.next/cache" ]; then - mkdir -p .next/cache - cp -r "${LIVE}/.next/cache/." .next/cache/ - fi - - # Stage shares MySQL with the live app + emulator. Keep the stage pool - # tiny so install/test/build cannot exhaust max_connections. - export DATABASE_POOL_SIZE="${DEPLOY_DATABASE_POOL_SIZE:-5}" - echo "STAGE DATABASE_POOL_SIZE=${DATABASE_POOL_SIZE}" - - pnpm install --frozen-lockfile - # prisma generate does not need a live DB connection. - pnpm prisma:generate - export ARGON2_MEMORY_SIZE=1024 ARGON2_ITERATIONS=1 BCRYPT_ROUNDS=4 - pnpm typecheck - pnpm test - # Validate production env (AUTH_SECRET, DATABASE_URL, …) during build. - # Do not set SKIP_ENV_VALIDATION here — that flag is for tests/tooling only. - pnpm build - - if [ ! -d "${STAGE}/.next" ]; then - echo "ERROR: stage build produced no .next/" >&2 - exit 1 - fi - - echo "Cutover: stop service (free DB connections), migrate, swap .next..." - CUTOVER_STARTED=1 - pm2 stop next --kill-timeout 10000 || true - # Wait for PM2 to fully exit and MariaDB to reclaim connections. - sleep 10 - - # Migrate only after live is stopped — avoids ER_CON_COUNT_ERROR while - # the old process still holds DATABASE_POOL_SIZE connections. - cd "${STAGE}" - MIGRATE_OK=0 - for i in $(seq 1 10); do - if pnpm db:migrate; then - MIGRATE_OK=1 - break - fi - echo "migrate attempt ${i}/10 failed (likely DB connections), retrying..." - sleep 5 - done - if [ "${MIGRATE_OK}" != "1" ]; then - echo "ERROR: db:migrate failed after retries" >&2 - exit 1 - fi - - cd "${LIVE}" - echo "Hard reset live tree to origin/main (no nuclear src wipe)..." - git reset --hard origin/main - # Keep env, uploads, and deps we are about to replace from stage. - git clean -fd \ - -e .env -e .env.local -e .env.production -e .env*.local \ - -e storage -e public/cache -e node_modules -e .next -e .next.prev - - if ! git diff --exit-code HEAD -- src >/dev/null; then - echo "ERROR: live src/ still differs from HEAD after reset:" >&2 - git diff --stat HEAD -- src >&2 || true - exit 1 - fi - echo "Verified live src/ matches HEAD" - - # Save current .next as backup before swapping (kept until health check passes). - if [ -d .next ]; then - mv .next .next.prev - fi - mv "${STAGE}/.next" .next - - # Use the exact node_modules the stage build resolved against. - rm -rf node_modules - mv "${STAGE}/node_modules" node_modules - - # Prisma client is gitignored — regenerate into live src/generated. - pnpm prisma:generate - - sudo chown -R www-data:www-data "${LIVE}" 2>/dev/null || true - - echo "Starting PM2 (zero-downtime reload)..." - pm2 reload next --update-env || pm2 start next --update-env - - sleep 3 - if ! pm2 show next 2>/dev/null | grep -q 'online'; then - echo "ERROR: PM2 next failed to start!" >&2 - pm2 logs next --lines 20 --nostream >&2 || true - exit 1 - fi - - echo "Waiting for HTTP health check..." - HEALTH_URL="${DEPLOY_HEALTH_URL:-http://127.0.0.1:3000/api/health}" - HEALTH_OK=0 - for i in $(seq 1 15); do - BODY="$(curl -sf --max-time 5 "${HEALTH_URL}" 2>/dev/null || true)" - if echo "${BODY}" | grep -q '"database":true'; then - echo "Health OK (${HEALTH_URL})" - HEALTH_OK=1 - break - fi - echo "Health attempt ${i}/15 failed, retrying..." - sleep 2 - done - if [ "${HEALTH_OK}" != "1" ]; then - echo "ERROR: Health check failed after deploy (${HEALTH_URL})" >&2 - echo "Last body: ${BODY:-}" >&2 - pm2 logs next --lines 40 --nostream >&2 || true - exit 1 - fi - - echo "Cleaning stage worktree and previous .next backup..." - rm -rf "${LIVE}/.next.prev" - git -C "${LIVE}" worktree remove --force "${STAGE}" 2>/dev/null || rm -rf "${STAGE}" || true - STAGE="" - - echo "--- Deployed successfully ---" + echo '' \ No newline at end of file diff --git a/.gitea/workflows/renovate.yaml b/.gitea/workflows/renovate.yaml index 2f37a6b6..3e013d02 100644 --- a/.gitea/workflows/renovate.yaml +++ b/.gitea/workflows/renovate.yaml @@ -1,8 +1,8 @@ name: Renovate on: schedule: - - cron: "0 5 * * *" # every day at 05:00 - workflow_dispatch: # manual trigger + - cron: "0 5 * * *" # Every day at 05:00 UTC + workflow_dispatch: # Manual trigger jobs: renovate: @@ -11,7 +11,13 @@ jobs: - name: Self-hosted Renovate run: | set -e + + # Zorg ervoor dat de cache-map lokaal bestaat vóór Docker start + # Dit voorkomt dat Docker de map automatisch als 'root' aanmaakt + mkdir -p /var/tmp/renovate-cache + docker run --rm \ + --user "$(id -u):$(id -g)" \ -e RENOVATE_TOKEN="${{ secrets.RENOVATE_TOKEN }}" \ -e RENOVATE_AUTODISCOVER=false \ -e RENOVATE_REPOSITORIES="${{ gitea.repository }}" \ @@ -19,4 +25,4 @@ jobs: -e RENOVATE_CONFIG_FILE='{"extends":["config:recommended"]}' \ -e LOG_LEVEL=info \ -v /var/tmp/renovate-cache:/tmp/renovate-cache \ - ghcr.io/renovatebot/renovate:latest + ghcr.io/renovatebot/renovate:latest \ No newline at end of file