name: Deploy on: push: branches: - main tags: - "v*" jobs: release: if: startsWith(gitea.ref_name, 'v') runs-on: shell steps: - name: Create Release env: VERSION: ${{ gitea.ref_name }} GITEA_API: ${{ gitea.api_url }} GITEA_REPO: ${{ gitea.repository }} run: | set -e exec 2>&1 BARE="/docker/gitea/gitea/git/repositories/remco/epicnext-cms.git" echo "=== Creating release for ${VERSION} ===" PREV_TAG="$(git -C "$BARE" tag --sort=-creatordate | head -2 | tail -1 || echo '')" if [ -n "$PREV_TAG" ] && [ "$PREV_TAG" != "$VERSION" ]; then CHANGELOG="$(git -C "$BARE" log --oneline --no-decorate --max-count=50 "${PREV_TAG}..${VERSION}")" [ -z "$CHANGELOG" ] && CHANGELOG="No commit changes since ${PREV_TAG}" else TOTAL="$(git -C "$BARE" rev-list --count "${VERSION}" 2>/dev/null || echo '?')" CHANGELOG="Initial release of EpicNext-CMS (${TOTAL} commits)." fi [ -z "$CHANGELOG" ] && CHANGELOG="Initial release" # Pin the other components at their current commits so the release is reproducible. CAT_REF="$(git ls-remote https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily.git Beta-3 2>/dev/null | awk '{print $1}')" NITRO_REF="$(git ls-remote https://github.com/duckietm/Nitro-V3.git main 2>/dev/null | awk '{print $1}')" RENDER_REF="$(git ls-remote https://github.com/duckietm/Nitro_Render_V3.git main 2>/dev/null | awk '{print $1}')" EMU_REF="$(git ls-remote https://github.com/duckietm/Polaris-Emulator.git main 2>/dev/null | awk '{print $1}')" { echo "## EpicNext-CMS ${VERSION}" echo "" echo "### Changes" echo '```' echo "${CHANGELOG}" echo '```' echo "" echo "### Linked repositories (exact commits)" echo "" echo "| Component | Repository | Commit |" echo "|-----------|------------|--------|" echo "| Catalogus | https://gitlab.epicnabbo.nl/remco/Epicnabbo-Catalogus-Updated-Daily | ${CAT_REF:-?} |" echo "| Nitro-V3 | https://github.com/duckietm/Nitro-V3 | ${NITRO_REF:-?} |" echo "| Nitro-Render-V3 | https://github.com/duckietm/Nitro_Render_V3 | ${RENDER_REF:-?} |" echo "| Polaris Emulator | https://github.com/duckietm/Polaris-Emulator | ${EMU_REF:-?} |" echo "" echo "---" echo "*Automated release from Gitea Actions*" } > /tmp/release-body.md PAYLOAD="$(jq -Rs --arg v "${VERSION}" '{tag_name: $v, name: $v, body: ., draft: false, prerelease: false}' < /tmp/release-body.md)" TOKEN="${GITEA_TOKEN:-${{ secrets.GITEA_TOKEN }}}" HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ -X POST "${GITEA_API}/repos/${GITEA_REPO}/releases" \ -H "Authorization: token ${TOKEN}" \ -H "Content-Type: application/json" \ -d "$PAYLOAD")" if [ "${HTTP_CODE}" = "409" ]; then RELEASES="$(curl -sf "${GITEA_API}/repos/${GITEA_REPO}/releases" \ -H "Authorization: token ${TOKEN}")" REL_ID="$(echo "$RELEASES" | jq -r ".[] | select(.tag_name==\"${VERSION}\") | .id")" HTTP_CODE="$(curl -s -w '%{http_code}' -o /tmp/release-resp.json \ -X PATCH "${GITEA_API}/repos/${GITEA_REPO}/releases/${REL_ID}" \ -H "Authorization: token ${TOKEN}" \ -H "Content-Type: application/json" \ -d "$PAYLOAD")" fi if [ "${HTTP_CODE:-0}" -ge 200 ] && [ "${HTTP_CODE:-0}" -lt 300 ]; then echo "SUCCESS: Release ${VERSION} created/updated" cat /tmp/release-resp.json | jq -r '.html_url // .id' else echo "FAILED HTTP ${HTTP_CODE}" cat /tmp/release-resp.json exit 1 fi deploy: if: startsWith(gitea.ref_name, 'v') == false runs-on: shell steps: - name: Deploy run: | set -e exec 9>/var/tmp/epic_web_control_deploy.lock flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; } echo "--- Deploying ---" error_handler() { echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2 sudo systemctl start atom-nexst.service || true exit 1 } trap 'error_handler $LINENO' ERR docker image prune -f cd /var/www/atom-nexst/ DEPLOY_USER="$(id -un)" DEPLOY_GROUP="$(id -gn)" sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/ git config --global --add safe.directory /var/www/atom-nexst git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/ echo "Fetching origin/main..." git fetch origin --prune echo "Clearing sticky git index bits (if any)..." STICKY_LIST="$(git ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' || true)" if [ -n "${STICKY_LIST}" ]; then echo "${STICKY_LIST}" | while IFS= read -r f; do [ -n "$f" ] || continue git update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true done fi echo "Hard reset to origin/main..." git reset --hard origin/main echo "Nuclear-replacing src/ from HEAD..." rm -rf src git checkout -f HEAD -- src git clean -fd -e .env -e .env.local -e .env.production -e .env*.local if ! git diff --exit-code HEAD -- src >/dev/null; then echo "ERROR: src/ still differs from HEAD after nuclear checkout:" >&2 git diff --stat HEAD -- src >&2 || true exit 1 fi echo "Verified src/ matches HEAD" rm -f tsconfig.tsbuildinfo .tsbuildinfo find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true rm -rf .output dist .next/types .next/dev export APP_VERSION="$(git rev-parse --short HEAD)" export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}" echo "APP_VERSION=${APP_VERSION}" pnpm install --frozen-lockfile pnpm db:migrate pnpm prisma:generate pnpm typecheck pnpm test export SKIP_ENV_VALIDATION=1 pnpm build sudo chown -R www-data:www-data /var/www/atom-nexst/ echo "Hard resetting systemd service..." sudo systemctl stop atom-nexst.service || true pkill -f 'next-server' || true sudo systemctl start atom-nexst.service sleep 2 if ! systemctl is-active --quiet atom-nexst.service; then echo "ERROR: atom-nexst.service failed to start!" >&2 exit 1 fi echo "--- Deployed successfully ---"