From 59f131f951fde0e7b4fceda86bd2127ae918a822 Mon Sep 17 00:00:00 2001 From: Asep Haryana Date: Thu, 30 Jul 2026 21:42:39 +0700 Subject: [PATCH] fix(ci): combine build+deploy per-service, pass exact store path Separate deploy job failed because it used ls to find store paths by name, finding OLD local paths instead of the freshly copied CI paths. Now each service builds, copies, and updates its profile in a single job using the exact store path from the build output. No more guessing which path is the right one. --- .github/workflows/nix-build.yml | 58 ++++++--------------------------- 1 file changed, 10 insertions(+), 48 deletions(-) diff --git a/.github/workflows/nix-build.yml b/.github/workflows/nix-build.yml index 476c4e5..a1c1349 100644 --- a/.github/workflows/nix-build.yml +++ b/.github/workflows/nix-build.yml @@ -23,16 +23,13 @@ env: VPS_USER: ${{ secrets.VPS_USER }} jobs: - build: + build-and-deploy: runs-on: ubuntu-latest strategy: fail-fast: false matrix: service: [hub, scraper, tools-gateway, tools-workers, tools-frontend, llm-api] - outputs: - store-paths: ${{ steps.store-paths.outputs.paths }} - steps: - name: Checkout uses: actions/checkout@v4 @@ -66,56 +63,21 @@ jobs: mkdir -p ~/.ssh echo "$SSH_KEY" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 - # Strip \r\n and validate key format sed -i 's/\r$//' ~/.ssh/id_ed25519 ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null - - name: Nix copy to VPS + - name: Deploy ${{ matrix.service }} to VPS if: github.ref == 'refs/heads/main' run: | - nix copy --to "ssh://$VPS_USER@$VPS_HOST" "${{ steps.build.outputs.store-path }}" + STORE_PATH="${{ steps.build.outputs.store-path }}" + echo "=== Copying ${{ matrix.service }}: $STORE_PATH ===" + nix copy --to "ssh://$VPS_USER@$VPS_HOST" "$STORE_PATH" - deploy: - needs: build - if: github.ref == 'refs/heads/main' - runs-on: ubuntu-latest - steps: - - name: Setup SSH key - env: - SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }} - run: | - mkdir -p ~/.ssh - echo "$SSH_KEY" > ~/.ssh/id_ed25519 - chmod 600 ~/.ssh/id_ed25519 - sed -i 's/\r$//' ~/.ssh/id_ed25519 - ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } - ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null + echo "=== Updating profile ===" + ssh "$VPS_USER@$VPS_HOST" "sudo /nix/var/nix/profiles/default/bin/nix-env --profile /nix/var/nix/profiles/${{ matrix.service }} --set '$STORE_PATH'" - - name: Deploy all services on VPS - run: | - ssh "$VPS_USER@$VPS_HOST" " - set -e - for service in hub scraper tools-gateway tools-workers tools-frontend llm-api; do - PROFILE=\"/nix/var/nix/profiles/\$service\" - LATEST=\$(ls -1td /nix/store/*-\$service-0.1.0 2>/dev/null | head -1) - if [ -n \"\$LATEST\" ]; then - echo \"=== Deploying \$service: \$LATEST ===\" - sudo /nix/var/nix/profiles/default/bin/nix-env --profile \"\$PROFILE\" --set \"\$LATEST\" 2>&1 - sudo systemctl restart \"\$service\" 2>&1 || echo \" ⚠️ restart failed (may not be enabled yet)\" - echo \" ✅ \$service deployed\" - else - echo \" ⚠️ \$service: no store path found\" - fi - done - " + echo "=== Restarting service ===" + ssh "$VPS_USER@$VPS_HOST" "sudo systemctl restart ${{ matrix.service }}" || echo " ⚠️ restart failed (may not be enabled yet)" - - name: Verify services - run: | - echo "=== Service Status ===" - ssh "$VPS_USER@$VPS_HOST" " - for service in hub scraper tools-gateway tools-workers tools-frontend llm-api; do - state=\$(systemctl is-active \$service 2>/dev/null || echo 'not-found') - echo \" \$service: \$state\" - done - " + echo "✅ ${{ matrix.service }} deployed"