name: Local Build and Deploy on: push: branches: - main jobs: deploy: runs-on: shell steps: - name: Run Deploy Scripts Locally run: | set -e # Define a lockfile to prevent double, concurrent deployments exec 9>/var/tmp/epic_web_control_deploy.lock flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; } echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---" # Fallback routine: If anything crashes during the steps below, # try to keep the current service running so the site doesn't stay down. error_handler() { echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2 echo "Attempting to keep the current service running..." >&2 sudo systemctl start atom-nexst.service || true exit 1 } trap 'error_handler $LINENO' ERR # 1. Clean up unused build images safely docker image prune -f # 2. Navigate to your website directory cd /var/www/atom-nexst/ # CRITICAL: Prevent Git permission blocks caused by the www-data ownership change git config --global --add safe.directory /var/www/atom-nexst # Point Git directly to the local Gitea folder path git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/ # 3. Fetch and update code git fetch origin --prune git reset --hard origin/main # Preserve .next/cache so Next.js can reuse its incremental build cache. rm -rf .output dist # 4. Configure trusted dependencies globally and install cleanly export PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES="@parcel/watcher,@swc/core,sharp" pnpm install --frozen-lockfile # 5. [SAFETY] Database Backup with Rotation (Keeps only last 5 backups) echo "Creating database backup..." BACKUP_DIR="/var/www/atom-nexst/backups" mkdir -p "$BACKUP_DIR" TIMESTAMP=$(date +%Y%m%d_%H%M%S) BACKUP_FILE="$BACKUP_DIR/db_backup_$TIMESTAMP.sql" # ----------------- DATABASE CONFIGURATION ----------------- # Read credentials directly from your .env file or environment if available, # or customize these variables to match your system. DB_USER="root" DB_NAME="epicnext" # ---------------------------------------------------------- # Create a secure, compressed backup using mysqldump # Note: If your MySQL requires a password, add '-pYourPassword' (no space after -p) # or configure a secure /home/user/.my.cnf file to read credentials automatically. mysqldump -u "$DB_USER" "$DB_NAME" > "$BACKUP_FILE" echo "Rotating older backups (keeping only the 5 newest files)..." # Lists backup files newest first, skips the first 5, and deletes any remaining older files ls -dt "$BACKUP_DIR"/db_backup_*.sql | tail -n +6 | xargs -r rm # Apply versioned CMS migrations and generate the Prisma client safely pnpm db:migrate pnpm prisma:generate # 6. Next.js Build pnpm build # 7. Fix ownership: Build first, THEN set permissions for the web server sudo chown -R www-data:www-data /var/www/atom-nexst/ # 8. Hard restart of the Systemd service to clear memory cache echo "Hard resetting systemd service..." sudo systemctl stop atom-nexst.service || true # Kill any lingering next-server processes holding port 3000 pkill -f 'next-server' || true sudo systemctl start atom-nexst.service # Extra health check: Ensure the service is actually running sleep 2 if ! systemctl is-active --quiet atom-nexst.service; then echo "ERROR: atom-nexst.service failed to start!" >&2 exit 1 fi echo "--- Deployment successfully completed ---"