Commit Graph
121 Commits
Author SHA1 Message Date
openhands 4b2d893905 feat: add deploy step in release workflow (build + PM2 restart) and set coverage thresholds to 100
CI / check (push) Failing after 22s
Deploy / release (push) Skipped
CI / deploy (push) Skipped
Deploy / deploy (push) Failing after 20s
2026-07-30 19:11:58 +02:00
SimoandCursor 540bce911f fix(deploy): free PORT before PM2 start to clear EADDRINUSE orphans
Co-authored-by: Cursor <[email protected]>
2026-07-30 18:40:42 +02:00
SimoandCursor 749dc237f1 fix(deploy): export PORT from .env before PM2 reload so health check matches
CI / check (push) Successful in 26s
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m6s
Co-authored-by: Cursor <[email protected]>
2026-07-30 18:33:38 +02:00
openhands 7cdb785218 Remove argon2id, use bcrypt-only password hashing 2026-07-29 22:50:17 +02:00
openhands 22a9fc13f7 fix(deploy): use correct PORT for health check (was hardcoded to 3000, env uses 3002)
The health check URL was hardcoded to http://127.0.0.1:3000 but the
production .env sets PORT=3002. Read the PORT from .env dynamically
so the health check matches the actual server port.
2026-07-28 23:00:19 +02:00
openhands 72079050f4 fix(deploy): use deploy user for file ownership instead of www-data
Changing ownership to www-data at end of deploy breaks permission
handling when pm2 runs as a different user (e.g., root or the deploy
user). Keep ownership as the deploy user throughout.
2026-07-28 22:36:39 +02:00
openhands 01a297884a Voeg Gitea workflows toe
Deploy / release (push) Successful in 7s
Deploy / deploy (push) Skipped
2026-07-28 18:07:26 +02:00
openhands 01196b0843 test: trigger geautomatiseerde pm2 deploy 2026-07-28 17:56:33 +02:00
openhands 48bdd6f2e6 ci: add workflows to correct repository path 2026-07-28 17:50:48 +02:00
openhands e8ade7afa3 fix(deploy): remove standalone logic, fix chown errors in workspace
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m10s
- Remove standalone static file verification (no longer needed)
- Make chown commands tolerate already-deleted temp files
- Update PM2 fallback to use pnpm start
2026-07-24 14:01:30 +02:00
openhands f6ee99801d Fix migration 'Too many connections' error during deploy
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m56s
- pm2 stop now uses --kill-timeout 10000 for graceful shutdown
- Wait 10s after stopping (was 3s) for MariaDB to reclaim connections
- Migration retries increased from 5 to 10 with 5s wait (was 3s)
- Total retry window: ~50s instead of ~15s
2026-07-23 20:04:34 +02:00
openhands dae381e07c Persist .next/cache across deploys for faster rebuilds
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m2s
Each deploy creates a fresh worktree and deletes .next, losing the
Turbopack build cache. Now restore .next/cache from the live site
into the stage before pnpm build, so Next.js can do incremental
compilation. After cutover the cache persists in the live .next/ for
the next deploy.
2026-07-23 19:33:12 +02:00
openhands 331a18e9c7 Add BCRYPT_ROUNDS env override, use 4 in CI
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m3s
- Bcrypt rounds now configurable via BCRYPT_ROUNDS env var (default 12)
- CI/deploy use BCRYPT_ROUNDS=4 for faster tests
- Argon2 test: 1161ms → 17ms (already done)
- Password test suite: 1860ms → 1330ms
2026-07-23 19:24:52 +02:00
openhands f7551166c5 Speed up tests: lower argon2 params in CI, env overrides
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m1s
- Allow ARGON2_MEMORY_SIZE, ARGON2_ITERATIONS, ARGON2_PARALLELISM env overrides
- Use m=1024,t=1 in tests (was m=65536,t=4 → ~1s per hash)
- Set fast params in CI and deploy workflows
2026-07-23 19:21:24 +02:00
openhands b6ba554386 Fix deploy error handler: cd to safe dir before pm2
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m58s
2026-07-23 19:16:34 +02:00
openhands 9226558aa0 Optimize deploy script
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 36s
- Zero-downtime PM2 reload instead of stop+start
- Keep .next.prev backup until after health check
- Add standalone static file verification
- Remove duplicate sleep
- Clean up naming
2026-07-23 19:13:06 +02:00
openhands d9e95c823a Update deploy to use PM2, add .next.prev to gitignore
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 38s
2026-07-23 19:09:05 +02:00
SimoandCursor 968ca15c27 feat: jwt cache, redis health, help-ticket admin, and write rate limits
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m33s
Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:58:48 +02:00
SimoandCursor fa40eebeed fix(deploy): migrate after stop and shrink DB pool
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
Stage migrate hit ER_CON_COUNT_ERROR while live still held the pool. Build in stage with DATABASE_POOL_SIZE=5, run db:migrate only after stopping the service (with retries), and lower the default pool from 40 to 10.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:44:06 +02:00
SimoandCursor 687e1f9fb0 fix(deploy): stage worktree build and short .next cutover
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 11s
Build install/test/migrate in a detached worktree while the live site keeps serving, then swap .next and node_modules during a brief stop. Drops nuclear rm -rf src and rolls back .next.prev on cutover failure.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:39:45 +02:00
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00
SimoandCursor c46dadeda4 chore: harden deps, env validation, admin errors, and redis warnings
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m39s
Align nodemailer with Auth.js peers, bump patch deps, validate env on deploy builds, add admin error boundary, and warn when Redis is missing in production.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:19:05 +02:00
openhands 7fc53396b4 fix: menu links use bare slugs (Gitea auto-prefixes href with user-content-)
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 21:03:02 +02:00
openhands c0975f8a43 fix: scope deploy contract test to deploy job; menu links use Gitea user-content anchors
Deploy / release (push) Successful in 12s
Deploy / deploy (push) Skipped
2026-07-20 20:59:37 +02:00
openhands 43a624bbe7 docs: add self-contained setup reference configs (emulator + nitro) and bold-link buttons
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 33s
2026-07-20 20:54:26 +02:00
openhands c4532dd340 style: use inline style for release buttons (Gitea strips class)
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:47:07 +02:00
openhands 039b46d12b docs: expand release wizard with emulator/Nitro/Catalogus steps + buttons
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:43:43 +02:00
openhands 43ca6dc4b0 fix: add explicit plain-id anchors so the release menu jumps to sections
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:38:50 +02:00
openhands 45b7a1d9ef test: add explicit anchor for System Requirements to verify Gitea keeps id
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:35:38 +02:00
openhands a741e6103d fix: menu anchors use Gitea user-content- prefix so TOC links work
Deploy / release (push) Successful in 13s
Deploy / deploy (push) Skipped
2026-07-20 20:31:34 +02:00
openhands 6e27d9c4fe docs: expand release notes with menu, requirements, install wizard, usage
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:25:45 +02:00
openhands e5de0b53d4 fix: single JSON-encode release body so newlines render (no literal \n)
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:21:33 +02:00
openhands cb91fbef6c chore: cleaner release notes (cap changelog, concise initial release)
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:15:44 +02:00
openhands d103316945 refactor: drop pack.yaml; v*-tag release now includes linked repo URLs + commits
Trigger Site Pack / notify (push) Successful in 0s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m35s
2026-07-20 20:04:45 +02:00
openhands dd66a5ba2e fix: use TOKEN from env with fallback to secret
Deploy / release (push) Successful in 22s
Deploy / deploy (push) Skipped
2026-07-20 16:03:13 +02:00
openhands 0c0540cf59 fix: yaml syntax in deploy workflow
Deploy / release (push) Successful in 4s
Deploy / deploy (push) Skipped
2026-07-20 15:52:40 +02:00
openhands 0913e9d529 fix: merge release into deploy workflow for Gitea compatibility 2026-07-20 15:50:03 +02:00
SimoandCursor 224ccd654b perf(deploy): keep .next/cache while clearing stale generated types
Nuclear src replace already guarantees clean sources; restoring the build cache speeds deploys without reintroducing sticky typecheck ghosts.

Co-authored-by: Cursor <[email protected]>
2026-07-18 21:15:52 +02:00
SimoandCursor 80c6559143 fix(deploy): stop hanging on per-file sticky-bit scan
Local Build and Deploy / deploy (push) Successful in 1m48s
Only clear paths that already have skip-worktree/assume-unchanged; keep nuclear src replace and content verify.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:34:34 +02:00
SimoandCursor d0f9b3ef95 fix(deploy): nuclear-replace src to defeat skip-worktree ghosts
Local Build and Deploy / deploy (push) Canceled after 9m26s
Host built a different event-form than HEAD while git looked clean; delete src, restore from git objects, and hash-verify every tracked blob.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:30:21 +02:00
SimoandCursor 968f6ff7db fix(deploy): unstick nitro Json typecheck and wipe poisoned .next cache
Local Build and Deploy / deploy (push) Failing after 1m21s
Host next build still saw Json on nitro while tsc passed; use any helpers, verify blob hash, and delete .next entirely before build.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:14:50 +02:00
SimoandCursor 1abbf3fde7 fix(deploy): sync rooms Prisma types and harden checkout against stale host files
Local Build and Deploy / deploy (push) Failing after 1m19s
next build failed on host-local rooms.ts using Prisma without import while tsc incremental passed; force non-incremental typecheck and verify src matches HEAD.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:06:34 +02:00
SimoandCursor c053b8de87 fix(deploy): reclaim www-data ownership before git reset
Local Build and Deploy / deploy (push) Failing after 1m16s
Stale host sources survived reset when files were owned by www-data, leaving an old nitro editor with a removed Json type that failed typecheck.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:01:25 +02:00
SimoandCursor b22725d3a9 fix: type-safe nitro editor helpers and stabilize deploy build
Local Build and Deploy / deploy (push) Failing after 29s
Rewrite getNested/updateNested without fragile any/Json inference, clear stale .next types before build, and skip env refine during compile.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:57:33 +02:00
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
SimoandCursor bb7d581084 Add exportPermissions and clean stray untracked src on deploy.
Local Build and Deploy / deploy (push) Successful in 1m13s
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:48:34 +02:00
remco 15966bcf6d Update .gitea/workflows/deploy.yaml
Local Build and Deploy / deploy (push) Successful in 55s
2026-07-15 21:57:02 +02:00
remco 64db83c5d3 Update .gitea/workflows/deploy.yaml
Local Build and Deploy / deploy (push) Failing after 15s
2026-07-15 21:54:27 +02:00
remco 3802a1cfb0 Update .gitea/workflows/deploy.yaml
Local Build and Deploy / deploy (push) Successful in 56s
2026-07-15 21:52:39 +02:00
openhands 1908136071 ci: kill lingering next-server before restarting service to avoid EADDRINUSE
Local Build and Deploy / deploy (push) Successful in 1m5s
2026-07-13 22:16:20 +02:00