asepharyana and Asep Haryana
d02989f1a7
ci: add Nix GC cleanup job on VPS after deploy
2026-08-04 13:58:10 +07:00
aseph
49123c08b3
ci: use free GHA Nix cache (disable FlakeHub cache, not subscribed)
2026-08-03 16:44:32 +07:00
asepharyana and Asep Haryana
539b5b8320
ci: enable FlakeHub Cache (id-token: write + use-flakehub)
2026-08-03 16:24:48 +07:00
Asep Haryana and Claude Opus 5
fdbdcbc1ec
fix(ci): trigger nix deploy on every push to main
...
GitHub path filters do not match submodule gitlink changes, so the
`paths: apps/**` filter meant a submodule pointer update never triggered
the deploy. Drop the filter so any push to main deploys (matches the
documented "Push to main -> nix build -> systemctl restart").
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-03 09:35:56 +07:00
ceeac5c02f
chore(deps): bump the github-actions group across 1 directory with 3 updates ( #9 )
...
Bumps the github-actions group with 3 updates in the / directory: [actions/checkout](https://github.com/actions/checkout ), [DeterminateSystems/nix-installer-action](https://github.com/determinatesystems/nix-installer-action ) and [DeterminateSystems/magic-nix-cache-action](https://github.com/determinatesystems/magic-nix-cache-action ).
Updates `actions/checkout` from 4 to 7
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v7 )
Updates `DeterminateSystems/nix-installer-action` from 16 to 22
- [Release notes](https://github.com/determinatesystems/nix-installer-action/releases )
- [Commits](https://github.com/determinatesystems/nix-installer-action/compare/v16...v22 )
Updates `DeterminateSystems/magic-nix-cache-action` from 8 to 14
- [Release notes](https://github.com/determinatesystems/magic-nix-cache-action/releases )
- [Commits](https://github.com/determinatesystems/magic-nix-cache-action/compare/v8...v14 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: DeterminateSystems/magic-nix-cache-action
dependency-version: '14'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: DeterminateSystems/nix-installer-action
dependency-version: '22'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-30 22:34:36 +07:00
Asep Haryana
33b999d2b7
fix(ci): disable Determinate Nix / FlakeHub (no flakehub flakes used)
...
DeterminateSystems/nix-installer-action defaults to determinate:true
which tries to auth with FlakeHub via GitHub JWT. We don't use any
FlakeHub flakes, so disable it — skipping the auth entirely.
2026-07-30 22:05:41 +07:00
Asep Haryana
59f131f951
fix(ci): combine build+deploy per-service, pass exact store path
...
Separate deploy job failed because it used ls to find store paths
by name, finding OLD local paths instead of the freshly copied CI
paths. Now each service builds, copies, and updates its profile
in a single job using the exact store path from the build output.
No more guessing which path is the right one.
2026-07-30 21:42:39 +07:00
Asep Haryana
cc8c5088a4
fix(ci): use SSH_PRIVATE_KEY secret, sanitize key format
...
- Ganti secret name: VPS_SSH_KEY → SSH_PRIVATE_KEY (nama yg ada)
- Fix nix copy URL: ***@ → $VPS_USER@
- Sanitize SSH key: strip \r\n, validasi dengan ssh-keygen
- Cegah libcrypto error dari key format broken
2026-07-30 21:32:40 +07:00
Asep Haryana
d15e8621a9
fix(ci): proper SSH user in nix copy, deploy job structure
...
- Fix nix copy URL: ***@ → $VPS_USER@
- Store path from build output, passed across jobs
- Deploy job waits for all builds via needs: build
- SSH key setup in its own step, guarded by main branch
- Only deploy on main branch pushes
- Remote deploy script fetches from VPS nix store
2026-07-30 21:14:20 +07:00
Asep Haryana
b5596e1398
feat(infra): full Nix migration — all 6 services + CI/CD
...
- flake.nix: 6 derivations (hub, scraper, tools-gateway, tools-workers, tools-frontend, llm-api)
- Fetch submodule source via builtins.fetchGit with pinned revs
- Fix cargo HOME/TMPDIR for Nix sandbox permission issues
- Fix llm-api: CMake/Clang deps for llama.cpp-sys2 bindgen
- Add LIBCLANG_PATH, LD_LIBRARY_PATH for Rust bindgen builds
- Systemd units: tools-gateway (3501), tools-frontend (3500), tools-workers, llm-api (8080)
- tools.target for grouped management
- Env configs: /etc/tools/env, /etc/llm-api/env
- GitHub Actions: nix-build.yml — matrix build + nix copy + deploy
- Update Traefik apps.yaml: tools/host.docker.internal:3500, llm-api/host.docker.internal:8080
- iptables: allow Docker→host on 3099, 4091, 3500, 3501, 8080
- Add scripts/nix-deploy.sh for CI/CD deploy step
2026-07-30 19:45:43 +07:00
Asep Haryana
46730ec07d
feat(infra): Nix build for scraper, GitHub Actions workflow
...
- Build scraper (Rust) with Nix — cargo build --release
- Create scraper systemd unit (port 4091), env from Docker config
- Fix HOME/CARGO_HOME for Rust/cargo in Nix sandbox
- Update Traefik apps.yaml: scraper -> host.docker.internal:4091
- Add iptables rules for port 4091 (Docker->host)
- Add GitHub Actions workflow: nix-build.yml (determinate-nix + deploy)
- Save iptables rules persistently
2026-07-30 18:46:45 +07:00