Files
EpicNext-Cms/.gitea/workflows/deploy.yaml
T
SimoandCursor 968f6ff7db
Local Build and Deploy / deploy (push) Failing after 1m21s
fix(deploy): unstick nitro Json typecheck and wipe poisoned .next cache
Host next build still saw Json on nitro while tsc passed; use any helpers, verify blob hash, and delete .next entirely before build.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:14:50 +02:00

133 lines
5.4 KiB
YAML

name: Local Build and Deploy
on:
push:
branches:
- main
jobs:
deploy:
runs-on: shell
steps:
- name: Run Deploy Scripts Locally
run: |
set -e
# Define a lockfile to prevent double, concurrent deployments
exec 9>/var/tmp/epic_web_control_deploy.lock
flock -n 9 || { echo "ERROR: Another deployment is already running! Cancelling."; exit 1; }
echo "--- EPIC WEB CONTROL: Starting Auto-Cleanup & Deploy ---"
# Fallback routine: If anything crashes during the steps below,
# try to keep the current service running so the site doesn't stay down.
error_handler() {
echo "!!! DEPLOYMENT FAILED on line $1 !!!" >&2
echo "Attempting to keep the current service running..." >&2
sudo systemctl start atom-nexst.service || true
exit 1
}
trap 'error_handler $LINENO' ERR
# 1. Clean up unused build images safely
docker image prune -f
# 2. Navigate to your website directory
cd /var/www/atom-nexst/
DEPLOY_USER="$(id -un)"
DEPLOY_GROUP="$(id -gn)"
# CRITICAL: last deploy chowns the tree to www-data. Reclaim ownership
# BEFORE git reset, otherwise stale sources can survive and break builds.
sudo chown -R "${DEPLOY_USER}:${DEPLOY_GROUP}" /var/www/atom-nexst/
# CRITICAL: Prevent Git permission blocks caused by the www-data ownership change
git config --global --add safe.directory /var/www/atom-nexst
# Point Git directly to the local Gitea folder path
git remote set-url origin /docker/gitea/gitea/git/repositories/remco/epicnext-cms.git/
# 3. Fetch and update code
git fetch origin --prune
# Clear bits that can pin host-local stale copies over origin/main.
git ls-files -v | awk '/^[a-zS]/ {print substr($0,3)}' | while IFS= read -r f; do
[ -n "$f" ] || continue
git update-index --no-skip-worktree --no-assume-unchanged -- "$f" 2>/dev/null || true
done
git reset --hard origin/main
# Drop stray untracked sources left on the host (keep secrets/env).
git clean -fd -e .env -e .env.local -e .env.production -e .env*.local -- src
git checkout -f HEAD -- src
# Working tree under src/ must match HEAD exactly (catches sticky host edits).
if ! git diff --exit-code -- src >/dev/null; then
echo "ERROR: src/ still differs from HEAD after reset/checkout:" >&2
git diff --stat -- src >&2 || true
git checkout -f HEAD -- src
git diff --exit-code -- src
fi
# Prove critical sources match the git object (not just index timestamps).
NITRO_SRC="src/app/admin/import/furni/nitro-editor-dialog.tsx"
NITRO_EXPECTED="$(git rev-parse "HEAD:${NITRO_SRC}")"
NITRO_ACTUAL="$(git hash-object "${NITRO_SRC}")"
echo "nitro-editor-dialog blob expected=${NITRO_EXPECTED} actual=${NITRO_ACTUAL}"
if [ "${NITRO_EXPECTED}" != "${NITRO_ACTUAL}" ]; then
echo "ERROR: ${NITRO_SRC} content hash mismatch after checkout" >&2
exit 1
fi
if grep -nE '(^|[[:space:]])type Json\b|:\s*Json\b' "${NITRO_SRC}"; then
echo "ERROR: ${NITRO_SRC} still has a Json type annotation after checkout" >&2
exit 1
fi
# Drop incremental TS caches that can hide real type errors.
rm -f tsconfig.tsbuildinfo .tsbuildinfo
find . -maxdepth 3 -name '*.tsbuildinfo' -delete 2>/dev/null || true
# Wipe .next entirely — partial cache has caused next build TS to disagree
# with a clean `tsc` on the same sources (stale nitro/rooms typings).
rm -rf .output dist .next
# Release tag for Sentry / logs (short git sha)
export APP_VERSION="$(git rev-parse --short HEAD)"
export NEXT_PUBLIC_APP_VERSION="${APP_VERSION}"
echo "APP_VERSION=${APP_VERSION}"
# 4. Install — onlyBuiltDependencies comes from pnpm-workspace.yaml
# (do not set a PNPM only-built-deps env override here).
pnpm install --frozen-lockfile
# 5. Apply versioned CMS migrations and generate the Prisma client safely
pnpm db:migrate
pnpm prisma:generate
# 6. Pre-deploy quality gates (fail before build if broken)
pnpm typecheck
pnpm test
# 7. Next.js Build
# Skip env refine during compile/page-data; runtime still validates via env.ts.
export SKIP_ENV_VALIDATION=1
pnpm build
# 8. Fix ownership: Build first, THEN set permissions for the web server
sudo chown -R www-data:www-data /var/www/atom-nexst/
# 9. Hard restart of the Systemd service to clear memory cache
echo "Hard resetting systemd service..."
sudo systemctl stop atom-nexst.service || true
# Kill any lingering next-server processes holding port 3000
pkill -f 'next-server' || true
sudo systemctl start atom-nexst.service
# Extra health check: Ensure the service is actually running
sleep 2
if ! systemctl is-active --quiet atom-nexst.service; then
echo "ERROR: atom-nexst.service failed to start!" >&2
exit 1
fi
echo "--- Deployment successfully completed ---"