Commit Graph
56 Commits
Author SHA1 Message Date
openhands 5b2eb91c5c fix(ops): stop a compose replica from blocking the blue/green release
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m57s
CI / tests-unit (push) Successful in 2m3s
CI / tests-ui (push) Successful in 2m49s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m48s
The deploy failed after the build, the migrations and the browser gate:
"Port 3002 is already in use". The holder was `epicnext-cms`, a compose
replica of release 6bffc537 that the daily scripts/docker-update.sh cron
had recreated at 03:30 with restart=unless-stopped. nginx serves the green
slot on 3003, so that replica was squatting the blue slot the next
candidate needed, and live traffic never noticed.

It got there because the updater's CI-ownership guard only tested
epicnext-cms-app. After a cutover to the green slot that container is
stopped, renamed and deleted, so the guard stopped firing while the host
stayed CI-managed.

- scripts/docker-update.sh: refuse a compose deployment on a CI host by
  checking both slot containers and the nginx upstream, which is the only
  thing that still marks the host as blue/green while a slot is idle.
- scripts/ci-deploy.sh: retire a compose replica of this checkout from
  the candidate port before starting the candidate, so a stray replica
  can never block a release again. Never a slot container, never the port
  nginx serves; anything else still fails loudly in assert_port_free.
- Tests cover both directions: a squatting replica is removed and the
  release lands, a replica on the live port is left alone.
2026-10-05 21:13:49 +02:00
openhands f99980052b perf: optimize cache layer for speed and stability
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 34s
CI / tests-ui (push) Failing after 33m56s
CI / tests-integration (push) Failing after 33m57s
CI / tests-unit (push) Failing after 33m57s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- Remove random TTL jitter to prevent unpredictable cache drops
- Add deterministic LRU eviction with proper entry cleanup
- Improve cache deduplication to prevent duplicate computations
- Skip Redis I/O during tests for faster, more stable execution
- Optimize depth calculation in catalog tree nodes
- Maintain backward compatibility and full test coverage (3331 passed)
2026-10-02 17:16:03 +02:00
openhands e4f83a8036 chore: upgrade to pnpm v12, vitest v5 and resolve deprecated subdependencies
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Failing after 21s
CI / tests-unit (push) Skipped
CI / tests-integration (push) Skipped
CI / tests-ui (push) Skipped
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-27 19:42:34 +02:00
openhands 8486ac4053 feat(security): add darklist.de source and raise the blocklist cap to 1M 2026-09-24 23:22:27 +02:00
openhands 7f6febf906 fix(security): drop URLhaus feed, validate CIDR ranges, pass unknown client IPs
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m46s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m40s
2026-09-24 19:19:22 +02:00
openhands 7392b843ad fix(security): LAPI-only engine boot, import via stdin, correct compose service
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 29s
CI / tests-integration (push) Successful in 1m46s
CI / tests-unit (push) Successful in 1m59s
CI / tests-ui (push) Successful in 2m53s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 1m54s
2026-09-24 18:59:13 +02:00
openhands 9562a75378 feat(security): external IP blocklist sync for the local CrowdSec engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m43s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
2026-09-24 18:39:38 +02:00
openhands 84d53139a9 feat(security): opt-in local CrowdSec LAPI bouncer on the Docker engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m37s
CI / tests-integration (push) Successful in 1m55s
CI / tests-ui (push) Successful in 2m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m38s
2026-09-24 18:08:18 +02:00
openhands 64edb81ab7 docs: add Cloudflare & anti-DDoS setup guide to README
CI / check (push) Successful in 51s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / tests-ui (push) Failing after 32s
CI / tests-unit (push) Successful in 1m37s
CI / tests-integration (push) Successful in 1m41s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-22 23:38:54 +02:00
openhands a039ba13cc chore: align Node toolchain on 26.9.0
CI / check (push) Failing after 1m33s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-19 23:28:09 +02:00
Simo fff284aaa0 ci: remove container publication workflows
CI / check (push) Failing after 1m26s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-14 21:28:21 +02:00
openhands 1df1ffc3e9 Make avatar imager resilient with upstream fallback everywhere
CI / check (push) Failing after 24s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-14 17:35:36 +02:00
openhands 75eada7a59 Replace DragonflyDB with Valkey throughout codebase
CI / check (push) Failing after 18s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
- Update all DragonflyDB references to Valkey in README and docker-compose.yml
- Update install instructions to use Valkey package repository and .deb download
- Update configuration paths from /etc/dragonfly/ to /etc/valkey/
- Update version requirement to Valkey 8.x+ (successor to Redis OSS)
2026-09-10 17:52:47 +02:00
Simo 27447ce029 feat(docker): add guided install and saved one-command updates
CI / check (push) Successful in 53s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Successful in 46s
2026-09-09 20:49:05 +02:00
Simo 8dc187483c fix(ci): verify registry upload against exported OCI config
CI / check (push) Successful in 51s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Successful in 54s
2026-09-09 20:33:14 +02:00
Simo 2af244b634 fix(ci): publish registry blobs in bounded chunks
CI / check (push) Successful in 52s
CI / deploy (push) Successful in 1m6s
CI / publish-container (push) Failing after 1m2s
2026-09-09 20:22:07 +02:00
Simo 867113d5d4 fix(ci): publish container under token account namespace
CI / check (push) Successful in 56s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Failing after 30s
2026-09-09 19:53:16 +02:00
Simo b3a6531d7b Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms 2026-09-09 18:29:06 +02:00
openhands 25f4d74209 feat(ci): switch Cloudflare bypass from FlareSolverr to Byparr
CI / check (push) Successful in 3m59s
CI / deploy (push) Successful in 2m13s
2026-09-08 16:02:12 +02:00
Simo f1571a1a62 ci: publish portable containers after successful main deployment 2026-09-07 23:02:18 +02:00
Simo c4496e710b feat(docker): prepare portable images with runtime hotel configuration
CI / check (push) Successful in 1m6s
CI / deploy (push) Successful in 1m23s
2026-09-07 22:37:53 +02:00
Simo 745d0b7247 feat(docker): restore failed Compose updates and retain recent releases
CI / check (push) Successful in 1m7s
CI / deploy (push) Successful in 1m20s
2026-09-07 22:10:13 +02:00
Simo cbaa115d56 fix(deploy): verify Docker clone updates against the served release
CI / check (push) Successful in 59s
CI / deploy (push) Failing after 1m21s
2026-09-07 21:17:34 +02:00
openhands 52459c0b74 feat(db): add self-tuned mariadb-turbo container and bulk JSON importer
CI / check (push) Failing after 1m15s
CI / deploy (push) Skipped
- docker-compose: opt-in mariadb-turbo service (profile 'db') with inline
  mysqld tuning (max_allowed_packet=512M, innodb_flush_log_at_trx_commit=2,
  2G buffer pool, net_read/write_timeout=600) for >50 MB JSON bulk loads;
  named volume for the datadir + node_modules host-sync guidance
- scripts/bulk-import-json.ts: chunked (2000-row) idempotent importer with
  ON DUPLICATE KEY UPDATE, resumable, habbo furnidata or flat-array input
- src/db/schema-gamedata.ts: promote+index JSON storage schema (furnidata,
  docs, texts) incl. VIRTUAL generated columns for MariaDB
- package.json: add db:bulk, db:up, db:down, db:introspect, db:schema:generate
2026-09-07 16:54:44 +02:00
openhands 9dc9d1fa4b perf: pre-compress gamedata JSON, tune MariaDB, fix avatar imager, docs
CI / check (push) Successful in 1m3s
CI / deploy (push) Successful in 1m12s
- scripts/compress-gamedata.mjs: pre-compress large gamedata JSON to .gz
  (gzip level 9, idempotent mtime check) served via nginx gzip_static
  (48 MB FurnitureData.json -> ~2.4 MB, ~0.3s -> ~0.005s per request)
- package.json: add gamedata:compress script
- fix(imaging): accept real Habbo figure strings in avatar route
  (allow optional second number per part, e.g. hd-180-1.ch-210-66)
- README: document avatar imager container (avatar-imaging-pixinode,
  port 8082, /docker/Polaris-imager), nginx /imaging proxying, MariaDB
  tuning, gamedata pre-compression cron and caching layers
2026-09-06 12:06:38 +02:00
openhands c4a3bec367 chore: test pipeline trigger
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 19s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-09-03 16:58:50 +02:00
openhands e1ecb190bc docs(docker): clarify how to update (nightly cron + manual run) in README
CI / check (push) Successful in 34s
CI / runtime-diagnostics (push) Skipped
CI / deploy (push) Successful in 1m5s
CI / release (push) Skipped
2026-09-02 12:58:39 +02:00
openhands fb978612d7 docs(docker): also relax permissions on write volumes for imported asset dirs
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s
2026-09-02 12:53:10 +02:00
openhands 037b295b93 feat(ci): automated docker update script + nightly cron
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m3s
- scripts/docker-update.sh: git pull --ff-only, host db:migrate, docker compose
  build + up -d, health-check wait, keeps host-side PM2 'next' stopped.
  Fails safe on dirty working tree (exit 1) and on health failure (exit 3).
- cron entry: daily 03:30 -> logs/docker-update.cron.log
- README: Automatic Updates section + docker commands row
2026-09-02 12:25:42 +02:00
openhands cb927db78d Docker: full Dockerized deployment (volumes, host networking, multi-package-manager build)
- docker-compose.yml: network_mode host so 127.0.0.1 refs (.env) keep working;
  mounts /var/www/Gamedata + write volumes; /api/health healthcheck; mem_limit
- Dockerfile: package-manager detection (pnpm/yarn/npm) + PACKAGE_MANAGER arg;
  runs as www-data (UID/GID 33) so gamedata is writable; .env loaded only for
  the build (no secrets baked in); build runs on the host network
- .dockerignore: .env stays in the build context (needed for NEXT_PUBLIC_*)
- README: Docker deployment section (paths, volumes, chown, migrations on host)
2026-09-02 12:25:42 +02:00
Simo 6ed1b03e24 chore: align Node 26.7.0 toolchain
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
2026-08-24 19:12:11 +02:00
openhands b5c8a29956 docs: add furniture import auto-translation guide
CI / check (push) Successful in 37s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m8s
2026-08-21 20:25:52 +02:00
openhands 65e3915a5f feat: replace Redis with DragonflyDB
CI / check (push) Successful in 31s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s
- Replace Redis server with DragonflyDB v1.40.1 (Redis protocol compatible)
- Stop redis-server service, enable dragonfly service on 127.0.0.1:6379
- Configure dragonfly in /etc/dragonfly/dragonfly.conf (bind 127.0.0.1, maxmemory 2gb)
- Update .env: remove REDIS_URL reference

Improve database reliability:
- Fix catalog-tree.ts: remove CAST(page_id AS CHAR) to enable index usage (122 rows vs 78k full scan)
- Fix catalog-repair.ts: replace sql.raw() string interpolation with parameterized sql queries using quoteIdentifier()
- Improve redis retry resilience: change retryStrategy to not give up after 3 attempts, enabling automatic reconnect after server restart

Update documentation:
- Update README: replace Redis references with DragonflyDB, add DragonflyDB setup section, update performance features list, update architecture diagram
- biome and typecheck pass clean
2026-08-12 14:34:29 +02:00
openhands 3edc987281 feat: integrate FlareSolverr for Cloudflare bypass on clone sources
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
- Add FLARESOLVERR_URL env var to .env.example
- Update fetchSourceFurnidata to fall back to FlareSolverr on CF challenges (403/HTML)
- Add docker-compose.yml with FlareSolverr service
- Add scripts/health-check.sh for FlareSolverr readiness check
- Add health:check script to package.json
- Document FlareSolverr setup in README
2026-08-04 19:00:30 +02:00
openhands ff1fa319a5 docs: add nginx configuration guide with proxy caching
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m17s
2026-08-01 19:05:24 +02:00
openhands c601ffbb76 feat(auth): switch password hashing to argon2id with legacy auto-upgrade
CI / check (push) Failing after 10s
CI / release (push) Skipped
CI / deploy (push) Skipped
- hashPassword now emits argon2id (same params as the legacy AtomCMS
  Laravel setup: memory 64MB, iterations 4, parallelism 1)
- legacy md5 and bcrypt hashes are verified and auto-upgraded to
  argon2id on successful login (CONVERT_PASSWORDS=true)
- replace BCRYPT_ROUNDS env with ARGON2_MEMORY_KB / ARGON2_ITERATIONS /
  ARGON2_PARALLELISM
- update README and add tests for argon2id and bcrypt upgrade paths
2026-08-01 17:09:29 +02:00
SimoandCursor ba82789166 chore(db): finish Prisma cutover to Drizzle Kit tooling
CI / check (push) Failing after 9s
CI / release (push) Skipped
CI / deploy (push) Skipped
Move CMS SQL to drizzle/migrations, drop prisma packages/schema, wire drizzle-kit scripts, and regenerate schema names from src/db/schema.ts.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:02:21 +02:00
SimoandCursor 24d0b735c1 chore(db): remove Prisma facade and drop prisma:generate from CI (2)
CI / check (push) Successful in 22s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:39:20 +02:00
SimoandCursor 67656a9aad fix(ci): migrate on tag release and wire drizzle schema generate
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m1s
Co-authored-by: Cursor <[email protected]>
2026-07-31 21:03:54 +02:00
openhands 9a8905c726 docs: update README for Drizzle ORM migration
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m35s
- Document Drizzle ORM as primary data layer with CLI usage examples
- Add Prisma compatibility facade section (backwards compatibility)
- Document legacy Prisma CLI removal (migrate dev, studio, db push no longer used)
- Update architecture tree with src/db/ and scripts/ directories
- Update migration count (19 SQL files)
- Add contributing guidelines for Drizzle-based code
2026-07-31 14:26:09 +02:00
openhands 56061e41d4 refactor: replace Prisma ORM runtime with Drizzle ORM facade
CI / check (push) Failing after 12s
CI / deploy (push) Skipped
CI / release (push) Skipped
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing

The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
2026-07-31 14:11:03 +02:00
openhands 7cdb785218 Remove argon2id, use bcrypt-only password hashing 2026-07-29 22:50:17 +02:00
openhands fc42a1c138 docs: update README for v1.0.1 — PM2 deploy, premium features, production-ready
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m50s
2026-07-24 14:37:18 +02:00
openhands 7e0519a04c Revert "test: trigger deploy webhook"
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m18s
This reverts commit 6525512a93.
2026-07-20 17:50:10 +02:00
openhands 6525512a93 test: trigger deploy webhook
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m24s
2026-07-20 17:48:29 +02:00
openhands ccd4994028 feat: enable React Compiler, add Redis caching for API routes, update README with requirements and install guide
Local Build and Deploy / deploy (push) Failing after 57s
2026-07-20 14:14:49 +02:00
Simo 65e942b268 Update README.md
Local Build and Deploy / deploy (push) Successful in 1m16s
2026-07-12 20:54:51 +02:00
remco 3c1784fc0f Update README.md
Remote Build and Deploy / deploy (push) Successful in 3s
2026-07-11 21:43:44 +02:00
remco 09654fd5a8 Update README.md
Remote Build and Deploy / deploy (push) Failing after 0s
2026-07-11 21:38:04 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00