Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 33s
CI / tests-unit (push) Failing after 2m4s
CI / tests-integration (push) Successful in 2m6s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Docker 29.1.3 ships BuildKit v0.26, which refuses to grant a build host networking unless each caller passes --allow=network.host. All three rebuild paths asked for it, and `docker compose build` has no flag to grant it, so a rebuild failed immediately with "additional privileges requested". The live container was never replaced, which is exactly the reported symptom: the site kept serving the previous release after a rebuild. Nothing in the build actually needs host networking. It uses the network only for apk, pnpm and next/font/google — all outbound internet, which the default bridge provides. Verified by building both the full runner image and the migrations stage with --no-cache after dropping the flag. Runtime `network_mode: host` stays: blue/green needs per-release host ports (3002/3003) and nginx reaches each slot over 127.0.0.1. The second gap is how a rebuild could still ship the wrong code. ci-deploy.sh stamped every image with HEAD's revision label, and verify-deployed-release.mjs only re-checks that same label, so a dirty working tree produced an image that claimed to be release $sha while containing uncommitted code. docker-update.sh already refused this; ci-deploy.sh now does too, before any build work.
72 lines
2.5 KiB
YAML
72 lines
2.5 KiB
YAML
# ─────────────────────────────────────────────────────────────────────────────
|
|
# Next.js CMS — blue/green
|
|
# ─────────────────────────────────────────────────────────────────────────────
|
|
x-cms: &cms
|
|
image: epicnext-cms:${CMS_RELEASE:-local}
|
|
# No `network: host` on the build. BuildKit (v0.26, Docker 29) refuses to grant
|
|
# host networking unless every caller passes --allow=network.host, and
|
|
# `docker compose build` has no such flag — so asking for it here turned every
|
|
# rebuild into an immediate "additional privileges requested" failure, which
|
|
# left the previous release serving traffic. The build only needs outbound
|
|
# internet (apk, pnpm, next/font/google), which the default bridge provides.
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
args:
|
|
NEXT_DEPLOYMENT_ID: ${CMS_RELEASE:-unknown}
|
|
# Runtime host networking IS required: blue/green needs per-release host ports
|
|
# (3002/3003) and nginx reaches the slot over 127.0.0.1.
|
|
network_mode: host
|
|
stop_grace_period: 15s
|
|
restart: unless-stopped
|
|
env_file:
|
|
- .env
|
|
volumes:
|
|
- ./public/nitro-assets:/app/public/nitro-assets
|
|
- ./public/swf:/app/public/swf
|
|
- ./storage:/app/storage
|
|
- /var/www/Gamedata:/var/www/Gamedata
|
|
|
|
# ── Resource limits ──
|
|
mem_limit: 6g
|
|
memswap_limit: 7g
|
|
cpus: 2.0
|
|
pids_limit: 512
|
|
|
|
healthcheck:
|
|
test: ["CMD", "node", "-e", "fetch('http://127.0.0.1:'+(process.env.PORT||'3002')+'/api/health').then(r=>{process.exit(r.ok?0:1)}).catch(()=>process.exit(1))"]
|
|
interval: 15s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 40s
|
|
|
|
services:
|
|
cms:
|
|
<<: *cms
|
|
container_name: epicnext-cms
|
|
environment:
|
|
- HOSTNAME=0.0.0.0
|
|
- PORT=3002
|
|
|
|
cms-green:
|
|
<<: *cms
|
|
container_name: epicnext-cms-green
|
|
profiles: ["green"]
|
|
environment:
|
|
- HOSTNAME=0.0.0.0
|
|
- PORT=3003
|
|
|
|
byparr:
|
|
image: ghcr.io/thephaseless/byparr:latest
|
|
container_name: byparr
|
|
network_mode: host
|
|
restart: unless-stopped
|
|
environment:
|
|
- LOG_LEVEL=INFO
|
|
pids_limit: 256
|
|
healthcheck:
|
|
test: ["CMD", "curl", "http://localhost:8191/health"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 30s |