Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Local Build and Deploy / deploy (push) Successful in 1m42s

Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-18 19:32:15 +02:00
1 parent b9c6001f08
commit 6b884ad25a
12 files changed
+128 -50

No files matched your search

+16 -7
View File
@@ -48,27 +48,36 @@ jobs:
# Preserve .next/cache so Next.js can reuse its incremental build cache.
rm -rf .output dist
# 4. Configure trusted dependencies globally and install cleanly
export PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES="@parcel/watcher,@swc/core,sharp"
# Release tag for Sentry / logs (short git sha)
export APP_VERSION="$(git rev-parse --short HEAD)"
export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}"
echo "APP_VERSION=${APP_VERSION}"
# 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml
# (do not set a PNPM only-built-deps env override here).
pnpm install --frozen-lockfile
# 5. Apply versioned CMS migrations and generate the Prisma client safely
pnpm db:migrate
pnpm prisma:generate
# 6. Next.js Build
# 6. Pre-deploy quality gates (fail before build if broken)
pnpm typecheck
pnpm test
# 7. Next.js Build
pnpm build
# 7. Fix ownership: Build first, THEN set permissions for the web server
# 8. Fix ownership: Build first, THEN set permissions for the web server
sudo chown -R www-data:www-data /var/www/atom-nexst/
# 8. Hard restart of the Systemd service to clear memory cache
# 9. Hard restart of the Systemd service to clear memory cache
echo "Hard resetting systemd service..."
sudo systemctl stop atom-nexst.service || true
# Kill any lingering next-server processes holding port 3000
pkill -f 'next-server' || true
sudo systemctl start atom-nexst.service
# Extra health check: Ensure the service is actually running
@@ -78,4 +87,4 @@ jobs:
exit 1
fi
echo "--- Deployment successfully completed ---"
echo "--- Deployment successfully completed ---"