Commit Graph
222 Commits
Author SHA1 Message Date
Simo 7c1f109a9d ci: serialize deployments and restore previous release on smoke failure
CI / check (push) Successful in 1m7s
CI / deploy (push) Successful in 1m9s
2026-09-06 11:48:20 +02:00
Simo 2840ef5d9d perf(docker): reuse dependency layers and preserve build caches
CI / check (push) Successful in 1m31s
CI / deploy (push) Successful in 1m42s
CI / e2e (push) Successful in 26s
2026-09-06 11:01:31 +02:00
openhands 226d280c22 ci: prune docker cache after CI runs 2026-09-05 20:13:13 +02:00
Simo 816e3875c2 feat(admin): add production error center and refresh CMS dependencies 2026-09-05 19:53:09 +02:00
openhands 4007b01da9 ci: run e2e smoke against deployed app and ignore playwright artifacts
CI / check (push) Successful in 1m10s
CI / deploy (push) Successful in 1m25s
CI / e2e (push) Successful in 22s
- Add e2e job (needs deploy, main/master only) that installs the
  Playwright browser and smoke-tests the live container on :3002
- Keep deploy-job contract slice from bleeding into the e2e job
- Cover the e2e job in the CI workflow contract test
- Ignore Playwright output dirs (test-results, playwright-report,
  blob-report)
2026-09-04 13:32:51 +02:00
openhands 399c047515 fix: harden admin actions, search, sanitization and repo hygiene
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s
- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
2026-09-04 13:04:08 +02:00
openhands 61769e355b fix(ci): draai DB-migraties in deploy voor het vervangen van de container
CI / check (push) Successful in 1m4s
CI / deploy (push) Successful in 1m29s
Zonder dit loopt nieuwe code tegen een oud schema aan zodra een push
migraties bevat. Idempotent (toegepaste migraties worden overgeslagen),
draait op de host met de productie-.env, vóór de container-replace.
2026-09-04 12:34:49 +02:00
openhands 3fdcf028e8 fix(ci): geef runtime-env door via -e i.p.v. --env-file
CI / check (push) Successful in 1m6s
CI / deploy (push) Successful in 1m22s
docker run --env-file behoudt letterlijke quotes (bewezen test),
waardoor DATABASE_URL ongeldig was en de container crashte. Nu wordt
.env gesourced en elke sleutel met -e doorgegeven: exact dezelfde
waarden als bij de build. Contract-test verbiedt --env-file.
2026-09-04 12:29:06 +02:00
openhands 10da44ee56 fix(ci): bouw met productie-.env, deploy met env+volumes en rollback
CI / check (push) Successful in 1m14s
CI / deploy (push) Failing after 3m10s
- Deploy kopieert de productie-.env van de host in de build-context:
  Next.js bakt NEXT_PUBLIC_* in en valideert DATABASE_URL/HOTEL_NAME
  (SKIP_ENV_VALIDATION is verboden voor productie, zie src/env.ts).
- Dockerfile builder installeert git (next.config.ts deploymentId).
- Deploy-container krijgt --env-file + dezelfde volumes als compose,
  stopt ook de oude compose-container (poort 3002) en rolt terug via
  compose bij een falende health check.
2026-09-04 12:22:02 +02:00
openhands 43ecdaee19 fix(ci): docker build met --network=host tegen hangende registry-stappen
CI / check (push) Successful in 1m4s
CI / deploy (push) Failing after 59s
De host heeft Docker iptables uitgeschakeld, dus build-containers op
bridge hebben geen outbound internet; 'npm install -g pnpm' in de
builder-stage hing daardoor. Met --network=host krijgt de build wel
registry-toegang. Contract-test vergrendelt de flag.
2026-09-04 12:16:26 +02:00
openhands cdb0fef6c9 fix(ci): remove invalid --jobs flag from pnpm install
CI / check (push) Successful in 1m3s
CI / deploy (push) Failing after 2m52s
pnpm 11 has no --jobs option for install; the stray positional '1'
flipped the command into 'add' mode, which then rejected both
--frozen-lockfile and --jobs ('Unknown options', 'pnpm help add').
Reproduced locally, fixed, verified install succeeds. Add contract
regression test.
2026-09-04 12:11:35 +02:00
openhands 4139aa79ff fix(ci): draai alle jobs op self-hosted voor 100% betrouwbaarheid
CI / check (push) Failing after 3m0s
CI / deploy (push) Skipped
Root cause: de job-container (docker mode) heeft GEEN outbound
internet naar GitHub, waardoor actions/checkout@v4 faalde met
'Unable to clone ... i/o timeout'.

Oplossing: zowel check als deploy draaien nu op self-hosted (host)
waar Node 26.8.1 + pnpm 11.25.0 geïnstalleerd zijn en internet
beschikbaar is. Dit is de enige betrouwbare setup in deze omgeving.
Runner is tevens hernoemd naar 'Epic runner'.
2026-09-04 11:35:22 +02:00
openhands 3c0acc3fcf refactor(ci): volledig opnieuw geschreven CI workflow
CI / check (push) Canceled after 1m56s
CI / deploy (push) Skipped
- Check job: lint, typecheck, test in node:26 container
- Deploy job: Docker build + deploy + health check op host
- Corepack pnpm installatie
- BuildKit caching
- Contract tests herschreven (18 tests)
2026-09-04 11:26:25 +02:00
openhands a52cbead8a perf(ci): snellere workflow + Epic runner naam
CI / check (push) Failing after 3m1s
CI / deploy (push) Skipped
- Runner hernoemd naar 'Epic runner'
- Env variabelen als global env (niet per step)
- fetch-depth: 1 voor snellere checkout
- Knip verwijderd (traag, niet kritiek)
- Docker BuildKit caching
- Health check opgeschoond
2026-09-04 11:22:28 +02:00
openhands e97a9f3119 fix(ci): update runner labels en workflow voor self-hosted Docker setup
- Check job: node:26-bookworm-slim image + corepack pnpm
- Deploy job: self-hosted host mode voor Docker CLI toegang
- Health check na deploy (30 pogingen)
- Runner labels bijgewerkt in docker-compose
2026-09-04 11:12:49 +02:00
openhands f0efb6b169 Fix: CI bestand hernoemd naar .yaml voor contract tests 2026-09-03 17:26:21 +02:00
openhands c992bed970 Fix: dubbele CI bestanden opgeruimd en contract test gefixt 2026-09-03 17:25:40 +02:00
openhands c1b0c40725 perf: voeg CPU en RAM limieten toe tegen server lag
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 1s
CI / deploy (push) Skipped
CI / release (push) Skipped
CI / check (push) Canceled after 0s
CI / deploy (push) Canceled after 0s
2026-09-03 17:10:08 +02:00
openhands 15a0007fa7 fix: switch naar host executor
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 0s
CI / release (push) Skipped
CI / deploy (push) Skipped
CI / check (push) Failing after 1s
CI / deploy (push) Skipped
2026-09-03 17:09:02 +02:00
openhands 4ce5f8ae56 fix: wijzig test databases naar host gateway
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 1s
CI / deploy (push) Skipped
CI / release (push) Skipped
CI / check (push) Failing after 1s
CI / deploy (push) Skipped
2026-09-03 17:07:16 +02:00
openhands 4852847e0f fix: forceer HTTPS checkout actie
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 1s
CI / release (push) Skipped
CI / deploy (push) Skipped
CI / check (push) Failing after 7s
CI / deploy (push) Skipped
2026-09-03 17:05:08 +02:00
openhands 3bf9765917 fix: gebruik officiële checkout actie ipv lokaal pad
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 1s
CI / release (push) Skipped
CI / deploy (push) Skipped
CI / check (push) Failing after 1s
CI / deploy (push) Skipped
2026-09-03 17:04:28 +02:00
openhands fcf3d62197 fix: corrigeer git remote paden voor docker runner
CI / runtime-diagnostics (push) Skipped
CI / release (push) Skipped
CI / check (push) Failing after 1s
CI / deploy (push) Skipped
2026-09-03 16:41:37 +02:00
openhands 7f1482cd1e fix: forceer bash installatie in alpine runner container
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 2s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-09-03 16:39:02 +02:00
openhands 2a7702cade fix: verander Gitea runner van shell naar ubuntu-latest
CI / runtime-diagnostics (push) Skipped
CI / release (push) Skipped
CI / check (push) Failing after 1s
CI / deploy (push) Skipped
2026-09-03 16:13:49 +02:00
Simo e3a4726648 ci: register permission diagnostics command
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 44s
2026-08-31 21:15:14 +02:00
Simo 75b85dcdd9 ci: probe permission page database reads
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 27s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-31 21:13:03 +02:00
Simo a11575bae3 ci: add manual runtime diagnostics
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 42s
2026-08-31 21:09:06 +02:00
Simo 6ed1b03e24 chore: align Node 26.7.0 toolchain
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
2026-08-24 19:12:11 +02:00
openhands 29958d0f8c fix(ci): drop invalid RENOVATE_CONFIG_FILE inline JSON
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 56s
RENOVATE_CONFIG_FILE must point to a config file on disk; the inline
JSON string made Renovate abort with 'Custom config file ... must exist'.
The repo-root renovate.json (which already extends config:recommended)
is picked up automatically, so the env var is not needed.
2026-08-20 11:51:16 +02:00
openhands 703c29bc83 revert: keep devDependencies on live tree, drop --prod prune
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m5s
2026-08-09 12:51:54 +02:00
openhands de28f26e0e ci: prune devDependencies from live tree after deploy build
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m40s
2026-08-09 12:41:48 +02:00
openhands ebd2ff131c inport fix
CI / check (push) Failing after 13s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-08 21:39:52 +02:00
openhands 510d070dc5 chore: add jobs:worker script and knip dead-code check to CI
Add 'knip' and 'jobs:worker' scripts to package.json. Wire knip into CI check job after tests. Remove redundant jobs-worker entry from knip.json (auto-detected).
2026-08-07 18:54:51 +02:00
Simo 0c8e62357f fix: preserve runtime furni assets during deploy
CI / check (push) Successful in 46s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m33s
2026-08-02 17:32:32 +02:00
Simo bfc951cfd9 fix: minimize deploy cutover downtime
CI / check (push) Successful in 22s
CI / release (push) Skipped
CI / deploy (push) Successful in 40s
2026-08-02 11:25:03 +02:00
Simo 828fda63e7 fix: keep app online during deploy preparation
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 44s
2026-08-02 11:19:53 +02:00
Simo 1f4aadb3d7 chore: remove Sentry integration
CI / check (push) Successful in 21s
CI / release (push) Skipped
CI / deploy (push) Successful in 53s
2026-08-01 22:12:31 +02:00
SimoandCursor ba82789166 chore(db): finish Prisma cutover to Drizzle Kit tooling
CI / check (push) Failing after 9s
CI / release (push) Skipped
CI / deploy (push) Skipped
Move CMS SQL to drizzle/migrations, drop prisma packages/schema, wire drizzle-kit scripts, and regenerate schema names from src/db/schema.ts.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:02:21 +02:00
SimoandCursor 422567272c chore(db): remove Prisma facade and drop prisma:generate from CI
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:38:42 +02:00
SimoandCursor 67656a9aad fix(ci): migrate on tag release and wire drizzle schema generate
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m1s
Co-authored-by: Cursor <[email protected]>
2026-07-31 21:03:54 +02:00
openhands c0bbcae5d6 ci: update CI for Drizzle ORM migration
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m36s
- Update CI comments to reference Drizzle ORM + Prisma facade (not legacy Prisma runtime)
- Clarify that src/db/schema.ts is committed (no drizzle-kit generate needed in CI)
- Update release notes template: 'Prisma 7' -> 'Drizzle ORM'
- Rename release 'Generate Prisma Client' section to 'Generate Prisma Type Stubs (Dev Only)'
- Note that Prisma type stubs are for facade type-checking only (no runtime engine)
2026-07-31 14:39:36 +02:00
SimoandCursor 3e584aadaf ci: unify check and production deploy into one workflow
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m8s
Co-authored-by: Cursor <[email protected]>
2026-07-30 20:58:40 +02:00
SimoandCursor bfbc02c75d fix(ci): remove duplicate deploy job that raced production Deploy
CI / check (push) Successful in 21s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 58s
Co-authored-by: Cursor <[email protected]>
2026-07-30 20:50:05 +02:00
openhands 7138ae4445 fix: correct indentation in deploy workflow shell block
CI / check (push) Successful in 27s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m19s
CI / deploy (push) Failing after 9s
The prisma:generate block had inconsistent indentation (11 spaces
instead of 10), causing YAML to misinterpret the shell block structure.
2026-07-30 20:29:19 +02:00
openhands fe46bd0544 fix: unset placeholder DATABASE_URL after prisma:generate so build/migrate use real .env
CI / check (push) Successful in 25s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m13s
CI / deploy (push) Failing after 9s
prisma:generate needs DATABASE_URL to resolve the schema but doesn't
connect to the DB. After generate, unset the placeholder so that
pnpm build and pnpm db:migrate pick up the real DATABASE_URL from
the live .env (symlinked into the stage directory).
2026-07-30 20:20:39 +02:00
openhands 822dfd6a1c fix: use real DATABASE_URL from .env for migrations in deploy workflow
CI / check (push) Successful in 24s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m12s
CI / deploy (push) Failing after 10s
The deploy job was overwriting DATABASE_URL with a placeholder for
prisma:generate, but this persisted when db:migrate ran later, causing
ER_ACCESS_DENIED_ERROR. Since the stage directory already symlinks to
the live .env, the real DATABASE_URL is available without override.
2026-07-30 20:16:24 +02:00
openhands 525f58cd24 fix: provide dummy DATABASE_URL for prisma generate during deploy
CI / check (push) Successful in 29s
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m8s
CI / deploy (push) Failing after 10s
2026-07-30 20:07:49 +02:00
openhands 686279eb25 fix: remove test from deploy job (runs in CI already)
CI / check (push) Failing after 21s
Deploy / release (push) Skipped
CI / deploy (push) Skipped
Deploy / deploy (push) Successful in 56s
2026-07-30 19:17:22 +02:00
openhands 4b2d893905 feat: add deploy step in release workflow (build + PM2 restart) and set coverage thresholds to 100
CI / check (push) Failing after 22s
Deploy / release (push) Skipped
CI / deploy (push) Skipped
Deploy / deploy (push) Failing after 20s
2026-07-30 19:11:58 +02:00