import { spawnSync } from "node:child_process"; import { existsSync, mkdirSync, mkdtempSync, readFileSync, rmSync, writeFileSync, } from "node:fs"; import { tmpdir } from "node:os"; import { resolve } from "node:path"; import { describe, expect, it } from "vitest"; const liveVar = "${" + "LIVE}"; const stageVar = "${" + "STAGE}"; const userVar = "${" + "DEPLOY_USER}"; const groupVar = "${" + "DEPLOY_GROUP}"; const cutoverStartedVar = "${" + "CUTOVER_STARTED}"; function toContainLiteral(workflow: string, literal: string) { return workflow.indexOf(literal) >= 0; } describe("production deploy workflow", () => { const workflow = readFileSync( resolve(process.cwd(), ".gitea/workflows/ci.yaml"), "utf8", ); const deployStart = workflow.indexOf("\n deploy:"); const afterDeploy = workflow.indexOf("\n release:", deployStart + 1); const deployJob = afterDeploy > deployStart ? workflow.slice(deployStart, afterDeploy) : workflow.slice(deployStart); it("is gated behind the check job", () => { expect(deployJob).toContain("needs: check"); expect(deployJob).toContain( "gitea.event_name == 'push' && gitea.ref_name == 'main'", ); }); it("builds in a stage worktree while preserving live .env and storage", () => { expect(deployJob).toContain("worktree add --detach"); expect(deployJob).toContain("/var/tmp/atom-nexst-stage-"); expect(toContainLiteral(deployJob, `ln -sfn "${liveVar}/.env"`)).toBe(true); expect(deployJob).toContain("-e storage"); expect(deployJob).toContain("DATABASE_POOL_SIZE="); expect(deployJob).toContain("REDIS_URL is unset"); expect(deployJob).not.toContain("SKIP_ENV_VALIDATION=1"); expect(deployJob).toContain("pnpm install --frozen-lockfile"); }); it("preserves runtime furni assets when cleaning the live checkout", () => { const cleanStart = deployJob.indexOf("git clean -fd \\"); const commandLines: string[] = []; for (const line of deployJob.slice(cleanStart).split(/\r?\n/)) { commandLines.push(line); if (!line.trimEnd().endsWith("\\")) break; } const cleanLines = commandLines.join(" "); const excludes = Array.from( cleanLines.matchAll(/-e\s+([^\s\\]+)/g), ).flatMap(([, pattern]) => ["-e", pattern]); const work = mkdtempSync(resolve(tmpdir(), "epicnext-deploy-clean-")); const runtimeFiles = [ "public/swf/dcr/hof_furni/icons/runtime_icon.png", "public/swf/dcr/hof_furni/swf/runtime.swf", "public/nitro-assets/bundled/furniture/runtime.nitro", ]; try { spawnSync("git", ["init", "--quiet"], { cwd: work }); for (const file of [...runtimeFiles, "remove-me.tmp"]) { const absolute = resolve(work, file); mkdirSync(resolve(absolute, ".."), { recursive: true }); writeFileSync(absolute, "runtime"); } const clean = spawnSync("git", ["clean", "-fd", ...excludes], { cwd: work, encoding: "utf8", }); expect(clean.status, clean.stderr).toBe(0); for (const file of runtimeFiles) { expect(existsSync(resolve(work, file)), file).toBe(true); } expect(existsSync(resolve(work, "remove-me.tmp"))).toBe(false); } finally { rmSync(work, { recursive: true, force: true }); } }); it("reclaims ownership before git operations so www-data files can be overwritten", () => { const chownCmd = `sudo chown -R "${userVar}:${groupVar}"`; expect(toContainLiteral(workflow, chownCmd)).toBe(true); const reclaimAt = deployJob.indexOf(chownCmd); expect( toContainLiteral(deployJob, `git -C "${liveVar}" fetch origin --prune`), ).toBe(true); const fetchAt = deployJob.indexOf( `git -C "${liveVar}" fetch origin --prune`, ); expect(reclaimAt).toBeGreaterThan(-1); expect(fetchAt).toBeGreaterThan(reclaimAt); }); it("avoids nuclear src wipe and verifies live src after cutover reset", () => { expect(deployJob).not.toContain("rm -rf src"); expect(deployJob).not.toContain("Nuclear-replacing src/"); expect(deployJob).toContain("no-skip-worktree"); expect(deployJob).toContain("no-assume-unchanged"); expect(deployJob).toContain("Verified live src/ matches HEAD"); expect(deployJob).toContain("ls-files -v"); expect(deployJob).not.toContain("git ls-files -z"); expect(deployJob).toContain("pnpm typecheck"); }); it("migrates while the current app is online, then swaps the built artifact", () => { expect(deployJob).toContain("mv .next .next.prev"); expect(toContainLiteral(deployJob, `mv "${stageVar}/.next" .next`)).toBe( true, ); expect( toContainLiteral(deployJob, `mv "${stageVar}/node_modules" node_modules`), ).toBe(true); expect(deployJob).toContain("mv node_modules node_modules.prev"); expect(deployJob).toContain("Rolling back .next to previous artifact"); expect(deployJob).toContain( "Rolling back node_modules to previous artifact", ); const buildAt = deployJob.indexOf("pnpm build"); const stopAt = deployJob.indexOf("pm2 stop next"); const migrateAt = deployJob.indexOf("pnpm db:migrate"); const resetAt = deployJob.indexOf("git reset --hard origin/main"); const startLabelAt = deployJob.indexOf("Starting PM2"); const startAt = deployJob.indexOf( "pm2 start pnpm --name next -- start", startLabelAt, ); expect(buildAt).toBeGreaterThan(-1); expect(migrateAt).toBeGreaterThan(buildAt); expect(resetAt).toBeGreaterThan(migrateAt); expect(stopAt).toBeGreaterThan(resetAt); expect(startLabelAt).toBeGreaterThan(stopAt); expect(startAt).toBeGreaterThan(startLabelAt); expect(deployJob.match(/pm2 stop next/g)).toHaveLength(1); expect(deployJob.slice(stopAt, startAt)).not.toContain("sleep "); }); it("does not restart the healthy app when deployment fails before cutover", () => { const handlerStart = deployJob.indexOf("error_handler() {"); const handlerEnd = deployJob.indexOf("trap 'error_handler", handlerStart); const handler = deployJob.slice(handlerStart, handlerEnd); const cutoverGuardAt = handler.indexOf( `if [ "${cutoverStartedVar}" = "1" ]; then`, ); const restartAt = handler.indexOf("pm2 restart next", cutoverGuardAt); const stageCleanupAt = handler.indexOf(`if [ -n "${stageVar}"`, restartAt); expect(handlerStart).toBeGreaterThan(-1); expect(cutoverGuardAt).toBeGreaterThan(-1); expect(restartAt).toBeGreaterThan(cutoverGuardAt); expect(stageCleanupAt).toBeGreaterThan(restartAt); expect(handler.slice(restartAt, stageCleanupAt)).toContain( "\n fi", ); }); it("does not override onlyBuiltDependencies (uses pnpm-workspace.yaml)", () => { expect(workflow).not.toContain("PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES"); }); it("runs typecheck before build in the stage", () => { const typecheckAt = deployJob.indexOf("pnpm typecheck"); const buildAt = deployJob.indexOf("pnpm build"); expect(typecheckAt).toBeGreaterThan(-1); expect(buildAt).toBeGreaterThan(typecheckAt); expect(deployJob).not.toContain("pnpm test"); }); it("exports APP_VERSION from git for the deployment ID fallback", () => { const exportCmd = `export APP_VERSION="$(git -C "${liveVar}" rev-parse --short origin/main)"`; expect(toContainLiteral(workflow, exportCmd)).toBe(true); }); it("runs an HTTP health check before declaring deploy success", () => { expect(workflow).toContain("/api/health"); expect(workflow).toContain('"database":true'); expect(deployJob).toContain("export PORT="); expect(deployJob).toContain("free_tcp_port"); const startAt = deployJob.indexOf("pm2 start pnpm --name next -- start"); const healthAt = deployJob.indexOf("/api/health"); const successAt = deployJob.indexOf("--- Deployed successfully ---"); expect(startAt).toBeGreaterThan(-1); expect(healthAt).toBeGreaterThan(startAt); expect(successAt).toBeGreaterThan(healthAt); }); });