Remote Build and Deploy / deploy (push) Failing after 16s
Signed-off-by: Simo <[email protected]>
140 lines
3.9 KiB
YAML
140 lines
3.9 KiB
YAML
name: Remote Build and Deploy
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
|
|
concurrency:
|
|
group: atomcms-production-deploy
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
|
|
steps:
|
|
- name: Check out exact commit
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 1
|
|
|
|
- name: Create release archive
|
|
shell: bash
|
|
run: |
|
|
set -Eeuo pipefail
|
|
|
|
git archive \
|
|
--format=tar.gz \
|
|
--output=atomcms-release.tar.gz \
|
|
HEAD
|
|
|
|
test -s atomcms-release.tar.gz
|
|
sha256sum atomcms-release.tar.gz > atomcms-release.tar.gz.sha256
|
|
|
|
- name: Upload release to VPS
|
|
uses: appleboy/[email protected]
|
|
with:
|
|
host: "172.20.2.1"
|
|
username: "root"
|
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
|
port: 22
|
|
source: "atomcms-release.tar.gz,atomcms-release.tar.gz.sha256"
|
|
target: "/tmp"
|
|
overwrite: true
|
|
timeout: 120s
|
|
command_timeout: 10m
|
|
|
|
- name: Deploy through SSH
|
|
uses: appleboy/[email protected]
|
|
with:
|
|
host: "172.20.2.1"
|
|
username: "root"
|
|
key: ${{ secrets.SSH_PRIVATE_KEY }}
|
|
port: 22
|
|
timeout: 120s
|
|
command_timeout: 25m
|
|
script: |
|
|
set -Eeuo pipefail
|
|
|
|
readonly APP_DIR="/var/www/atom-nexst"
|
|
readonly RELEASE="/tmp/atomcms-release.tar.gz"
|
|
readonly CHECKSUM="/tmp/atomcms-release.tar.gz.sha256"
|
|
readonly BACKUP_DIR="/var/backups/atom-nexst"
|
|
readonly TIMESTAMP="$(date +%Y%m%d-%H%M%S)"
|
|
|
|
failure() {
|
|
local exit_code=$?
|
|
echo "--- DEPLOYMENT FAILED with code ${exit_code} ---"
|
|
systemctl status atom-nexst.service --no-pager || true
|
|
exit "$exit_code"
|
|
}
|
|
|
|
trap failure ERR
|
|
|
|
echo "--- Starting EPIC WEB CONTROL Deployment ---"
|
|
|
|
test "$APP_DIR" = "/var/www/atom-nexst"
|
|
test -d "$APP_DIR"
|
|
test -f "$APP_DIR/.env"
|
|
test -s "$RELEASE"
|
|
test -s "$CHECKSUM"
|
|
|
|
cd /tmp
|
|
sha256sum --check "$CHECKSUM"
|
|
|
|
mkdir -p "$BACKUP_DIR"
|
|
|
|
echo "--- Creating rollback backup ---"
|
|
tar \
|
|
--exclude=".next" \
|
|
--exclude="node_modules" \
|
|
--exclude="storage" \
|
|
--exclude=".env" \
|
|
-czf "$BACKUP_DIR/release-$TIMESTAMP.tar.gz" \
|
|
-C "$APP_DIR" .
|
|
|
|
cd "$APP_DIR"
|
|
test "$PWD" = "$APP_DIR"
|
|
|
|
echo "--- Replacing tracked application files ---"
|
|
|
|
# These directories come entirely from Git.
|
|
# Persistent .env, storage and node_modules remain untouched.
|
|
rm -rf -- src public prisma scripts .gitea
|
|
|
|
tar -xzf "$RELEASE" -C "$APP_DIR"
|
|
|
|
rm -f -- "$RELEASE" "$CHECKSUM"
|
|
|
|
echo "--- Preparing pnpm ---"
|
|
corepack enable
|
|
corepack prepare [email protected] --activate
|
|
|
|
echo "--- Installing locked dependencies ---"
|
|
pnpm install --frozen-lockfile --prod=false
|
|
|
|
echo "--- Generating Prisma client ---"
|
|
pnpm prisma:generate
|
|
|
|
echo "--- Running database migrations ---"
|
|
pnpm db:migrate
|
|
|
|
echo "--- Building application ---"
|
|
rm -rf -- "$APP_DIR/.next"
|
|
pnpm build
|
|
|
|
echo "--- Restarting service ---"
|
|
systemctl restart atom-nexst.service
|
|
systemctl is-active --quiet atom-nexst.service
|
|
|
|
echo "--- Cleaning old backups ---"
|
|
find "$BACKUP_DIR" \
|
|
-maxdepth 1 \
|
|
-type f \
|
|
-name "release-*.tar.gz" \
|
|
-mtime +7 \
|
|
-delete
|
|
|
|
echo "--- Deployment Completed Successfully ---" |