Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Local Build and Deploy / deploy (push) Successful in 1m42s
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
b9c6001f08
commit
6b884ad25a
12 files changed
+128
-50
No files matched your search
@@ -48,27 +48,36 @@ jobs:
|
||||
# Preserve .next/cache so Next.js can reuse its incremental build cache.
|
||||
rm -rf .output dist
|
||||
|
||||
# 4. Configure trusted dependencies globally and install cleanly
|
||||
export PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES="@parcel/watcher,@swc/core,sharp"
|
||||
# Release tag for Sentry / logs (short git sha)
|
||||
export APP_VERSION="$(git rev-parse --short HEAD)"
|
||||
export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}"
|
||||
echo "APP_VERSION=${APP_VERSION}"
|
||||
|
||||
# 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml
|
||||
# (do not set a PNPM only-built-deps env override here).
|
||||
pnpm install --frozen-lockfile
|
||||
|
||||
# 5. Apply versioned CMS migrations and generate the Prisma client safely
|
||||
pnpm db:migrate
|
||||
pnpm prisma:generate
|
||||
|
||||
# 6. Next.js Build
|
||||
# 6. Pre-deploy quality gates (fail before build if broken)
|
||||
pnpm typecheck
|
||||
pnpm test
|
||||
|
||||
# 7. Next.js Build
|
||||
pnpm build
|
||||
|
||||
# 7. Fix ownership: Build first, THEN set permissions for the web server
|
||||
# 8. Fix ownership: Build first, THEN set permissions for the web server
|
||||
sudo chown -R www-data:www-data /var/www/atom-nexst/
|
||||
|
||||
# 8. Hard restart of the Systemd service to clear memory cache
|
||||
# 9. Hard restart of the Systemd service to clear memory cache
|
||||
echo "Hard resetting systemd service..."
|
||||
sudo systemctl stop atom-nexst.service || true
|
||||
|
||||
# Kill any lingering next-server processes holding port 3000
|
||||
pkill -f 'next-server' || true
|
||||
|
||||
|
||||
sudo systemctl start atom-nexst.service
|
||||
|
||||
# Extra health check: Ensure the service is actually running
|
||||
@@ -78,4 +87,4 @@ jobs:
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "--- Deployment successfully completed ---"
|
||||
echo "--- Deployment successfully completed ---"
|
||||
Reference in new issue
Block a user