diff --git a/.gitea/workflows/deploy.yaml b/.gitea/workflows/deploy.yaml index 6f25bb11..c8e57138 100644 --- a/.gitea/workflows/deploy.yaml +++ b/.gitea/workflows/deploy.yaml @@ -10,15 +10,14 @@ jobs: - name: Run Deploy Scripts Locally run: | set -e - - # Define a lockfile to prevent double, concurrent deployments + + # 1. Lockfile om dubbele, gelijktijdige deployments te voorkomen exec 9>/var/tmp/epic_web_control_deploy.lock flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; } - + echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---" - - # Fallback routine: If anything crashes during the steps below, - # try to keep the current service running so the site doesn't stay down. + + # Fallback routine bij crashes error_handler() { echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2 echo "Attempting to keep the current service running..." >&2 @@ -26,56 +25,54 @@ jobs: exit 1 } trap 'error_handler $LINENO' ERR - - # 1. Clean up unused build images safely + + # 2. Systeem opruimen docker image prune -f - - # 2. Navigate to your website directory + + # 3. Git updates & Rechten cd /var/www/atom-nexst/ - - # CRITICAL: Prevent Git permission blocks caused by the www-data ownership change git config --global --add safe.directory /var/www/atom-nexst - - # Point Git directly to the local Gitea folder path git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/ - - # 3. Fetch and update code + git fetch origin --prune git reset --hard origin/main - # Drop stray untracked sources left on the host (keep secrets/env). - git clean -fd -e .env -e .env.local -e .env.production -e .env*.local -- src - - # Preserve .next/cache so Next.js can reuse its incremental build cache. - rm -rf .output dist - - # 4. Configure trusted dependencies globally and install cleanly + + # Schoonmaken met behoud van .env en de cruciale Next.js cache map (.next/cache) + # We sluiten expliciet de .next map uit van 'git clean' zodat de build cache overleeft + git clean -fd -e .env -e .env.local -e .env.production -e .env*.local -e .next + + # Verwijder oude builds, maar BEHOUD de cache-map binnen .next + find .next -mindepth 1 -maxdepth 1 ! -name 'cache' -exec rm -rf {} + 2>/dev/null || true + + # 4. Dependencies installeren met de nieuwste PNPM security flags export PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES="@parcel/watcher,@swc/core,sharp" pnpm install --frozen-lockfile - - # 5. Apply versioned CMS migrations and generate the Prisma client safely + + # 5. Database & Prisma pnpm db:migrate pnpm prisma:generate - + # 6. Next.js Build + # NEXT_DISABLE_SOURCEMAPS bespaart enorm veel RAM tijdens de build (fijn voor rustige server-resources) + export NEXT_DISABLE_SOURCEMAPS=1 pnpm build - - # 7. Fix ownership: Build first, THEN set permissions for the web server + + # 7. Rechten corrigeren voor de webserver + # Zorgt dat www-data de nieuwe bestanden kan lezen, maar behoudt schrijfrechten voor de deployer sudo chown -R www-data:www-data /var/www/atom-nexst/ - - # 8. Hard restart of the Systemd service to clear memory cache + sudo chmod -R g+rw /var/www/atom-nexst/ + + # 8. Service herstarten en controleren echo "Hard resetting systemd service..." sudo systemctl stop atom-nexst.service || true - - # Kill any lingering next-server processes holding port 3000 pkill -f 'next-server' || true sudo systemctl start atom-nexst.service - - # Extra health check: Ensure the service is actually running + sleep 2 if ! systemctl is-active --quiet atom-nexst.service; then echo "ERROR: atom-nexst.service failed to start!" >&2 exit 1 fi - + echo "--- Deployment successfully completed ---" \ No newline at end of file