import { readFileSync } from "node:fs"; import { resolve } from "node:path"; import { describe, expect, it } from "vitest"; describe("production deploy workflow", () => { const workflow = readFileSync( resolve(process.cwd(), ".gitea/workflows/deploy.yaml"), "utf8", ); const deployJob = workflow.slice(workflow.indexOf("\n deploy:")); it("builds in a stage worktree while preserving live .env and storage", () => { expect(deployJob).toContain("worktree add --detach"); expect(deployJob).toContain("/var/tmp/atom-nexst-stage-"); expect(deployJob).toContain('ln -sfn "${LIVE}/.env"'); expect(deployJob).toContain("-e storage"); expect(deployJob).toContain("DATABASE_POOL_SIZE="); expect(deployJob).not.toContain("SKIP_ENV_VALIDATION=1"); expect(deployJob).toContain("pnpm install --frozen-lockfile"); }); it("reclaims ownership before git operations so www-data files can be overwritten", () => { expect(workflow).toContain( 'sudo chown -R "$' + "{DEPLOY_USER}:" + '$' + '{DEPLOY_GROUP}"', ); const reclaimAt = deployJob.indexOf( 'sudo chown -R "$' + "{DEPLOY_USER}:" + '$' + '{DEPLOY_GROUP}"', ); const fetchAt = deployJob.indexOf('git -C "${LIVE}" fetch origin --prune'); expect(reclaimAt).toBeGreaterThan(-1); expect(fetchAt).toBeGreaterThan(reclaimAt); }); it("avoids nuclear src wipe and verifies live src after cutover reset", () => { expect(deployJob).not.toContain("rm -rf src"); expect(deployJob).not.toContain("Nuclear-replacing src/"); expect(deployJob).toContain("no-skip-worktree"); expect(deployJob).toContain("no-assume-unchanged"); expect(deployJob).toContain("Verified live src/ matches HEAD"); expect(deployJob).toContain("ls-files -v"); expect(deployJob).not.toContain("git ls-files -z"); expect(deployJob).toContain("pnpm typecheck"); }); it("swaps a built .next artifact during a short service cutover", () => { expect(deployJob).toContain("mv .next .next.prev"); expect(deployJob).toContain('mv "${STAGE}/.next" .next'); expect(deployJob).toContain('mv "${STAGE}/node_modules" node_modules'); expect(deployJob).toContain("Rolling back .next to previous artifact"); const buildAt = deployJob.indexOf("pnpm build"); const stopAt = deployJob.indexOf("sudo systemctl stop atom-nexst.service"); const migrateAt = deployJob.indexOf("pnpm db:migrate"); const startLabelAt = deployJob.indexOf("Starting systemd service..."); const startAt = deployJob.indexOf( "sudo systemctl start atom-nexst.service", startLabelAt, ); expect(buildAt).toBeGreaterThan(-1); expect(stopAt).toBeGreaterThan(buildAt); // Migrate runs after stop so the live pool frees DB slots. expect(migrateAt).toBeGreaterThan(stopAt); expect(startLabelAt).toBeGreaterThan(migrateAt); expect(startAt).toBeGreaterThan(startLabelAt); }); it("does not override onlyBuiltDependencies (uses pnpm-workspace.yaml)", () => { expect(workflow).not.toContain("PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES"); }); it("runs typecheck and tests before build in the stage", () => { const typecheckAt = deployJob.indexOf("pnpm typecheck"); const testAt = deployJob.indexOf("pnpm test"); const buildAt = deployJob.indexOf("pnpm build"); expect(typecheckAt).toBeGreaterThan(-1); expect(testAt).toBeGreaterThan(typecheckAt); expect(buildAt).toBeGreaterThan(testAt); }); it("exports APP_VERSION from git for Sentry releases", () => { expect(workflow).toContain( 'export APP_VERSION="$(git -C "${LIVE}" rev-parse --short origin/main)"', ); expect(workflow).toContain( 'export NEXT_PUBLIC_APP_VERSION="$' + "{APP_VERSION}\"", ); }); it("runs an HTTP health check before declaring deploy success", () => { expect(workflow).toContain("/api/health"); expect(workflow).toContain('"database":true'); const startAt = deployJob.indexOf("systemctl start atom-nexst.service"); const healthAt = deployJob.indexOf("/api/health"); const successAt = deployJob.indexOf("--- Deployed successfully ---"); expect(startAt).toBeGreaterThan(-1); expect(healthAt).toBeGreaterThan(startAt); expect(successAt).toBeGreaterThan(healthAt); }); });