name: Local Build and Deploy on: push: branches: - main jobs: deploy: runs-on: shell steps: - name: Run Deploy Scripts Locally run: | set -e # Define a lockfile to prevent double, concurrent deployments exec 9>/var/tmp/epic_web_control_deploy.lock flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; } echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---" # Fallback routine: If anything crashes during the steps below, # try to keep the current service running so the site doesn't stay down. error_handler() { echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2 echo "Attempting to keep the current service running..." >&2 sudo systemctl start atom-nexst.service || true exit 1 } trap 'error_handler $LINENO' ERR # 1. Clean up unused build images safely docker image prune -f # 2. Navigate to your website directory cd /var/www/atom-nexst/ DEPLOY_USER="$(id -un)" DEPLOY_GROUP="$(id -gn)" # CRITICAL: last deploy chowns the tree to www-data. Reclaim ownership # BEFORE git reset, otherwise stale sources can survive and break builds. sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/ # CRITICAL: Prevent Git permission blocks caused by the www-data ownership change git config --global --add safe.directory /var/www/atom-nexst # Point Git directly to the local Gitea folder path git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/ # 3. Fetch and update code git fetch origin --prune # Clear EVERY skip-worktree / assume-unchanged bit. Those bits make # `git reset --hard` and `git diff` lie: the working tree can keep # ancient file contents while git reports a clean checkout. STICKY=0 while IFS= read -r -d '' f; do if git ls-files -v -- "$f" | grep -qE '^[a-zS]'; then STICKY=$((STICKY + 1)) fi git update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true done < <(git ls-files -z) echo "Cleared skip-worktree/assume-unchanged bits (saw ${STICKY} sticky before clear)" git reset --hard origin/main # Nuclear: delete src/ on disk, then restore ONLY from git objects. # This is the only reliable way to drop host-local ghosts that survive # reset/checkout when index flags or permissions pin old bytes. rm -rf src git checkout -f HEAD -- src # Drop other stray untracked junk under the app root (keep secrets/env). git clean -fd -e .env -e .env.local -e .env.production -e .env*.local # Prove EVERY tracked file under src/ matches the HEAD blob (content hash). # `git diff` alone is not enough when skip-worktree was previously set. MISMATCH=0 while IFS= read -r -d '' f; do case "$f" in src/*) ;; *) continue ;; esac expected="$(git rev-parse "HEAD:${f}")" actual="$(git hash-object "${f}")" if [ "${expected}" != "${actual}" ]; then echo "ERROR: content hash mismatch: ${f}" >&2 echo " expected=${expected}" >&2 echo " actual=${actual}" >&2 MISMATCH=1 fi done < <(git ls-files -z) if [ "${MISMATCH}" -ne 0 ]; then echo "ERROR: src/ working tree does not match HEAD after nuclear checkout" >&2 exit 1 fi echo "Verified all tracked src/ blobs match HEAD" # Drop incremental TS caches that can hide real type errors. rm -f tsconfig.tsbuildinfo .tsbuildinfo find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true # Wipe .next entirely — partial cache has disagreed with clean sources. rm -rf .output dist .next # Release tag for Sentry / logs (short git sha) export APP_VERSION="$(git rev-parse --short HEAD)" export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}" echo "APP_VERSION=${APP_VERSION}" # 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml # (do not set a PNPM only-built-deps env override here). pnpm install --frozen-lockfile # 5. Apply versioned CMS migrations and generate the Prisma client safely pnpm db:migrate pnpm prisma:generate # 6. Pre-deploy quality gates (fail before build if broken) pnpm typecheck pnpm test # 7. Next.js Build # Skip env refine during compile/page-data; runtime still validates via env.ts. export SKIP_ENV_VALIDATION=1 pnpm build # 8. Fix ownership: Build first, THEN set permissions for the web server sudo chown -R www-data:www-data /var/www/atom-nexst/ # 9. Hard restart of the Systemd service to clear memory cache echo "Hard resetting systemd service..." sudo systemctl stop atom-nexst.service || true # Kill any lingering next-server processes holding port 3000 pkill -f 'next-server' || true sudo systemctl start atom-nexst.service # Extra health check: Ensure the service is actually running sleep 2 if ! systemctl is-active --quiet atom-nexst.service; then echo "ERROR: atom-nexst.service failed to start!" >&2 exit 1 fi echo "--- Deployment successfully completed ---"