Repository navigation
170 lines (142 loc) · 5.71 KB
/
Copy pathci.yml
File metadata and controls
170 lines (142 loc) · 5.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
name: CI/CD
on:
push:
branches: ["main"]
pull_request:
branches: ["main"]
workflow_dispatch:
inputs:
deploy_ref:
description: >
Git ref to deploy (commit SHA for rollback, or branch name).
Defaults to main (latest).
required: false
default: "main"
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install dependencies
run: bun install
- name: Typecheck
run: bunx turbo check-types
- name: Build
run: bun run build
- name: Package frontend build
run: tar -czf frontend-build.tar.gz -C apps/frontend dist
- uses: actions/upload-artifact@v4
with:
name: frontend-build
path: frontend-build.tar.gz
retention-days: 1
deploy:
runs-on: ubuntu-latest
needs: build
if: ${{ github.event_name == 'workflow_dispatch' || (github.event_name == 'push' && github.ref == 'refs/heads/main') }}
concurrency:
group: deploy-ec2
cancel-in-progress: false
permissions:
contents: read
env:
APP_DIR: ${{ vars.APP_DIR || '/opt/codraw' }}
REPO_URL: ${{ vars.REPO_URL }}
DEPLOY_REF: ${{ github.event.inputs.deploy_ref || 'main' }}
SITE_URL: ${{ vars.SITE_URL || 'https://codraw.nerdev.in' }}
steps:
- uses: actions/checkout@v4
- uses: actions/download-artifact@v4
with:
name: frontend-build
- uses: webfactory/ssh-agent@v0.9.1
with:
ssh-private-key: ${{ secrets.EC2_SSH_KEY }}
- name: SSH connectivity probe
run: |
ssh -o StrictHostKeyChecking=no \
-o ConnectTimeout=15 \
-o BatchMode=yes \
${{ secrets.EC2_USER }}@${{ secrets.EC2_HOST }} \
'echo SSH_OK; hostname; uptime' || {
echo "::error::SSH to EC2 failed (exit $?) — check instance is running,"
echo "::error::security group allows inbound TCP 22, and EC2_HOST is the public IP"
exit 1
}
- name: Upload build artifact
run: scp -o StrictHostKeyChecking=no frontend-build.tar.gz ${{ secrets.EC2_USER }}@${{ secrets.EC2_HOST }}:/tmp/frontend-build.tar.gz
- name: Deploy
run: |
ssh -o StrictHostKeyChecking=no ${{ secrets.EC2_USER }}@${{ secrets.EC2_HOST }} "APP_DIR='$APP_DIR' REPO_URL='$REPO_URL' DEPLOY_REF='$DEPLOY_REF' bash -s" << 'DEPLOY'
set -euo pipefail
export PATH="$HOME/.bun/bin:$PATH"
export BUN_INSTALL="$HOME/.bun"
echo ">>> Pulling latest code ($DEPLOY_REF)..."
if [ ! -d "$APP_DIR/.git" ]; then
git clone "$REPO_URL" "$APP_DIR"
else
cd "$APP_DIR"
git fetch origin
if [ "$DEPLOY_REF" = "main" ]; then
git reset --hard origin/main
else
git reset --hard "$DEPLOY_REF"
fi
fi
cd "$APP_DIR"
echo ">>> Removing docs (.md files) from server (kept on GitHub)..."
find "$APP_DIR" -type f -name '*.md' ! -path "$APP_DIR/.git/*" -delete
rm -rf "$APP_DIR/docs"
echo ">>> Loading env..."
if [ -f .env ]; then
set -a
source .env
set +a
fi
echo ">>> Installing dependencies..."
bun install
echo ">>> Deploying built frontend..."
mkdir -p "$APP_DIR/apps/frontend"
tar -xzf /tmp/frontend-build.tar.gz -C "$APP_DIR/apps/frontend"
echo ">>> Generating Prisma client..."
cd packages/db && bun prisma generate && cd ../..
echo ">>> Running Prisma migrations..."
cd packages/db && bun prisma migrate deploy && cd ../..
echo ">>> Restarting services..."
pm2 start deploy/pm2/ecosystem.config.js --update-env
pm2 save
echo ">>> Configuring nginx..."
if ! command -v nginx >/dev/null 2>&1; then
sudo apt-get install -y nginx >/dev/null 2>&1
fi
sudo cp -f "$APP_DIR/deploy/nginx/codraw.conf" /etc/nginx/sites-available/codraw
sudo ln -sf /etc/nginx/sites-available/codraw /etc/nginx/sites-enabled/codraw
sudo rm -f /etc/nginx/sites-enabled/default
if sudo nginx -t >/dev/null 2>&1; then
sudo systemctl reload nginx
echo ">>> nginx reloaded."
else
echo ">>> nginx config test failed (Let's Encrypt certs missing?)"
echo ">>> Run once: sudo certbot certonly --nginx -d codraw.nerdev.in -d www.codraw.nerdev.in"
echo ">>> Then: sudo nginx -t && sudo systemctl reload nginx"
fi
echo ">>> Recording deployed commit marker..."
git rev-parse HEAD > .deployed-commit
echo "Deployed commit: $(cat .deployed-commit)"
echo ">>> Deploy complete."
DEPLOY
- name: Post-deploy health check
run: |
ssh -o StrictHostKeyChecking=no ${{ secrets.EC2_USER }}@${{ secrets.EC2_HOST }} bash -s << 'HEALTH'
set -euo pipefail
echo ">>> Backend health (http://localhost:3001/health):"
curl -fsS --max-time 20 http://localhost:3001/health
echo
echo ">>> Frontend via nginx (http://localhost):"
curl -fsS -o /dev/null -w "status %{http_code}\n" --max-time 20 http://localhost/
HEALTH
echo ">>> Public site ($SITE_URL):"
curl -fsS -o /dev/null -w "status %{http_code}\n" --max-time 25 "$SITE_URL"