This commit is contained in:
1 parent
bbdc94870a
commit
e7beae1ca0
1 file changed
+18
-21
@@ -11,14 +11,13 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
# Define a lockfile to prevent double, concurrent deployments
|
# 1. Lockfile om dubbele, gelijktijdige deployments te voorkomen
|
||||||
exec 9>/var/tmp/epic_web_control_deploy.lock
|
exec 9>/var/tmp/epic_web_control_deploy.lock
|
||||||
flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; }
|
flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; }
|
||||||
|
|
||||||
echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---"
|
echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---"
|
||||||
|
|
||||||
# Fallback routine: If anything crashes during the steps below,
|
# Fallback routine bij crashes
|
||||||
# try to keep the current service running so the site doesn't stay down.
|
|
||||||
error_handler() {
|
error_handler() {
|
||||||
echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2
|
echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2
|
||||||
echo "Attempting to keep the current service running..." >&2
|
echo "Attempting to keep the current service running..." >&2
|
||||||
@@ -27,51 +26,49 @@ jobs:
|
|||||||
}
|
}
|
||||||
trap 'error_handler $LINENO' ERR
|
trap 'error_handler $LINENO' ERR
|
||||||
|
|
||||||
# 1. Clean up unused build images safely
|
# 2. Systeem opruimen
|
||||||
docker image prune -f
|
docker image prune -f
|
||||||
|
|
||||||
# 2. Navigate to your website directory
|
# 3. Git updates & Rechten
|
||||||
cd /var/www/atom-nexst/
|
cd /var/www/atom-nexst/
|
||||||
|
|
||||||
# CRITICAL: Prevent Git permission blocks caused by the www-data ownership change
|
|
||||||
git config --global --add safe.directory /var/www/atom-nexst
|
git config --global --add safe.directory /var/www/atom-nexst
|
||||||
|
|
||||||
# Point Git directly to the local Gitea folder path
|
|
||||||
git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/
|
git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/
|
||||||
|
|
||||||
# 3. Fetch and update code
|
|
||||||
git fetch origin --prune
|
git fetch origin --prune
|
||||||
git reset --hard origin/main
|
git reset --hard origin/main
|
||||||
# Drop stray untracked sources left on the host (keep secrets/env).
|
|
||||||
git clean -fd -e .env -e .env.local -e .env.production -e .env*.local -- src
|
|
||||||
|
|
||||||
# Preserve .next/cache so Next.js can reuse its incremental build cache.
|
# Schoonmaken met behoud van .env en de cruciale Next.js cache map (.next/cache)
|
||||||
rm -rf .output dist
|
# We sluiten expliciet de .next map uit van 'git clean' zodat de build cache overleeft
|
||||||
|
git clean -fd -e .env -e .env.local -e .env.production -e .env*.local -e .next
|
||||||
|
|
||||||
# 4. Configure trusted dependencies globally and install cleanly
|
# Verwijder oude builds, maar BEHOUD de cache-map binnen .next
|
||||||
|
find .next -mindepth 1 -maxdepth 1 ! -name 'cache' -exec rm -rf {} + 2>/dev/null || true
|
||||||
|
|
||||||
|
# 4. Dependencies installeren met de nieuwste PNPM security flags
|
||||||
export PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES="@parcel/watcher,@swc/core,sharp"
|
export PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES="@parcel/watcher,@swc/core,sharp"
|
||||||
pnpm install --frozen-lockfile
|
pnpm install --frozen-lockfile
|
||||||
|
|
||||||
# 5. Apply versioned CMS migrations and generate the Prisma client safely
|
# 5. Database & Prisma
|
||||||
pnpm db:migrate
|
pnpm db:migrate
|
||||||
pnpm prisma:generate
|
pnpm prisma:generate
|
||||||
|
|
||||||
# 6. Next.js Build
|
# 6. Next.js Build
|
||||||
|
# NEXT_DISABLE_SOURCEMAPS bespaart enorm veel RAM tijdens de build (fijn voor rustige server-resources)
|
||||||
|
export NEXT_DISABLE_SOURCEMAPS=1
|
||||||
pnpm build
|
pnpm build
|
||||||
|
|
||||||
# 7. Fix ownership: Build first, THEN set permissions for the web server
|
# 7. Rechten corrigeren voor de webserver
|
||||||
|
# Zorgt dat www-data de nieuwe bestanden kan lezen, maar behoudt schrijfrechten voor de deployer
|
||||||
sudo chown -R www-data:www-data /var/www/atom-nexst/
|
sudo chown -R www-data:www-data /var/www/atom-nexst/
|
||||||
|
sudo chmod -R g+rw /var/www/atom-nexst/
|
||||||
|
|
||||||
# 8. Hard restart of the Systemd service to clear memory cache
|
# 8. Service herstarten en controleren
|
||||||
echo "Hard resetting systemd service..."
|
echo "Hard resetting systemd service..."
|
||||||
sudo systemctl stop atom-nexst.service || true
|
sudo systemctl stop atom-nexst.service || true
|
||||||
|
|
||||||
# Kill any lingering next-server processes holding port 3000
|
|
||||||
pkill -f 'next-server' || true
|
pkill -f 'next-server' || true
|
||||||
|
|
||||||
sudo systemctl start atom-nexst.service
|
sudo systemctl start atom-nexst.service
|
||||||
|
|
||||||
# Extra health check: Ensure the service is actually running
|
|
||||||
sleep 2
|
sleep 2
|
||||||
if ! systemctl is-active --quiet atom-nexst.service; then
|
if ! systemctl is-active --quiet atom-nexst.service; then
|
||||||
echo "ERROR: atom-nexst.service failed to start!" >&2
|
echo "ERROR: atom-nexst.service failed to start!" >&2
|
||||||
|
|||||||
Reference in new issue
Block a user