Signed-off-by: Simo <[email protected]>
This commit is contained in:
1 parent
f48532f2d0
commit
71e0457e7e
1 file changed
+103
-42
+103
-42
@@ -11,69 +11,130 @@ concurrency:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
deploy:
|
deploy:
|
||||||
runs-on: shell
|
runs-on: ubuntu-latest
|
||||||
|
timeout-minutes: 30
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Check out pushed commit
|
- name: Check out exact commit
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 1
|
fetch-depth: 1
|
||||||
|
|
||||||
- name: Deploy AtomCMS
|
- name: Create release archive
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
set -Eeuo pipefail
|
set -Eeuo pipefail
|
||||||
|
|
||||||
readonly APP_DIR="/var/www/atom-nexst"
|
git archive \
|
||||||
readonly SOURCE_DIR="${GITHUB_WORKSPACE}"
|
--format=tar.gz \
|
||||||
|
--output=atomcms-release.tar.gz \
|
||||||
|
HEAD
|
||||||
|
|
||||||
echo "--- Starting EPIC WEB CONTROL Deployment ---"
|
test -s atomcms-release.tar.gz
|
||||||
|
sha256sum atomcms-release.tar.gz > atomcms-release.tar.gz.sha256
|
||||||
|
|
||||||
test -n "$SOURCE_DIR"
|
- name: Upload release to VPS
|
||||||
test -d "$SOURCE_DIR/src"
|
uses: appleboy/[email protected]
|
||||||
test -f "$SOURCE_DIR/package.json"
|
with:
|
||||||
test -f "$SOURCE_DIR/pnpm-lock.yaml"
|
host: "172.20.2.1"
|
||||||
|
username: "root"
|
||||||
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||||
|
port: 22
|
||||||
|
source: "atomcms-release.tar.gz,atomcms-release.tar.gz.sha256"
|
||||||
|
target: "/tmp"
|
||||||
|
overwrite: true
|
||||||
|
timeout: 120s
|
||||||
|
command_timeout: 10m
|
||||||
|
|
||||||
test -d "$APP_DIR"
|
- name: Deploy through SSH
|
||||||
test -f "$APP_DIR/.env"
|
uses: appleboy/[email protected]
|
||||||
test "$APP_DIR" = "/var/www/atom-nexst"
|
with:
|
||||||
|
host: "172.20.2.1"
|
||||||
|
username: "root"
|
||||||
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||||
|
port: 22
|
||||||
|
timeout: 120s
|
||||||
|
command_timeout: 25m
|
||||||
|
script: |
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
echo "--- Synchronizing Application Files ---"
|
readonly APP_DIR="/var/www/atom-nexst"
|
||||||
|
readonly RELEASE="/tmp/atomcms-release.tar.gz"
|
||||||
|
readonly CHECKSUM="/tmp/atomcms-release.tar.gz.sha256"
|
||||||
|
readonly BACKUP_DIR="/var/backups/atom-nexst"
|
||||||
|
readonly TIMESTAMP="$(date +%Y%m%d-%H%M%S)"
|
||||||
|
|
||||||
sudo rsync -a --delete \
|
failure() {
|
||||||
--exclude=".git/" \
|
local exit_code=$?
|
||||||
--exclude=".env" \
|
echo "--- DEPLOYMENT FAILED with code ${exit_code} ---"
|
||||||
--exclude=".next/" \
|
systemctl status atom-nexst.service --no-pager || true
|
||||||
--exclude="node_modules/" \
|
exit "$exit_code"
|
||||||
--exclude="storage/" \
|
}
|
||||||
--exclude="docs/" \
|
|
||||||
"$SOURCE_DIR/" "$APP_DIR/"
|
|
||||||
|
|
||||||
cd "$APP_DIR"
|
trap failure ERR
|
||||||
test "$PWD" = "$APP_DIR"
|
|
||||||
|
|
||||||
echo "--- Preparing pnpm ---"
|
echo "--- Starting EPIC WEB CONTROL Deployment ---"
|
||||||
sudo corepack enable
|
|
||||||
sudo corepack prepare [email protected] --activate
|
|
||||||
|
|
||||||
echo "--- Installing Locked Dependencies ---"
|
test "$APP_DIR" = "/var/www/atom-nexst"
|
||||||
sudo pnpm install --frozen-lockfile --prod=false
|
test -d "$APP_DIR"
|
||||||
|
test -f "$APP_DIR/.env"
|
||||||
|
test -s "$RELEASE"
|
||||||
|
test -s "$CHECKSUM"
|
||||||
|
|
||||||
echo "--- Generating Prisma Client ---"
|
cd /tmp
|
||||||
sudo pnpm prisma:generate
|
sha256sum --check "$CHECKSUM"
|
||||||
|
|
||||||
echo "--- Running Database Migrations ---"
|
mkdir -p "$BACKUP_DIR"
|
||||||
sudo pnpm db:migrate
|
|
||||||
|
|
||||||
echo "--- Building Application ---"
|
echo "--- Creating rollback backup ---"
|
||||||
sudo rm -rf -- "$APP_DIR/.next"
|
tar \
|
||||||
sudo pnpm build
|
--exclude=".next" \
|
||||||
|
--exclude="node_modules" \
|
||||||
|
--exclude="storage" \
|
||||||
|
--exclude=".env" \
|
||||||
|
-czf "$BACKUP_DIR/release-$TIMESTAMP.tar.gz" \
|
||||||
|
-C "$APP_DIR" .
|
||||||
|
|
||||||
echo "--- Restarting Atom Nexst Service ---"
|
cd "$APP_DIR"
|
||||||
sudo systemctl restart atom-nexst.service
|
test "$PWD" = "$APP_DIR"
|
||||||
sudo systemctl is-active --quiet atom-nexst.service
|
|
||||||
|
|
||||||
echo "--- Verifying Deployed Revision ---"
|
echo "--- Replacing tracked application files ---"
|
||||||
echo "DEPLOYED_COMMIT=${GITHUB_SHA}"
|
|
||||||
|
|
||||||
echo "--- Deployment Completed Successfully ---"
|
# These directories come entirely from Git.
|
||||||
|
# Persistent .env, storage and node_modules remain untouched.
|
||||||
|
rm -rf -- src public prisma scripts .gitea
|
||||||
|
|
||||||
|
tar -xzf "$RELEASE" -C "$APP_DIR"
|
||||||
|
|
||||||
|
rm -f -- "$RELEASE" "$CHECKSUM"
|
||||||
|
|
||||||
|
echo "--- Preparing pnpm ---"
|
||||||
|
corepack enable
|
||||||
|
corepack prepare [email protected] --activate
|
||||||
|
|
||||||
|
echo "--- Installing locked dependencies ---"
|
||||||
|
pnpm install --frozen-lockfile --prod=false
|
||||||
|
|
||||||
|
echo "--- Generating Prisma client ---"
|
||||||
|
pnpm prisma:generate
|
||||||
|
|
||||||
|
echo "--- Running database migrations ---"
|
||||||
|
pnpm db:migrate
|
||||||
|
|
||||||
|
echo "--- Building application ---"
|
||||||
|
rm -rf -- "$APP_DIR/.next"
|
||||||
|
pnpm build
|
||||||
|
|
||||||
|
echo "--- Restarting service ---"
|
||||||
|
systemctl restart atom-nexst.service
|
||||||
|
systemctl is-active --quiet atom-nexst.service
|
||||||
|
|
||||||
|
echo "--- Cleaning old backups ---"
|
||||||
|
find "$BACKUP_DIR" \
|
||||||
|
-maxdepth 1 \
|
||||||
|
-type f \
|
||||||
|
-name "release-*.tar.gz" \
|
||||||
|
-mtime +7 \
|
||||||
|
-delete
|
||||||
|
|
||||||
|
echo "--- Deployment Completed Successfully ---"
|
||||||
Reference in new issue
Block a user