Files
infra/.github/workflows/infra-deploy.yml
T

102 lines
3.5 KiB
YAML

name: Deploy Infra Config
on:
push:
branches: [main]
paths:
- 'infra/caddy/**'
- 'infra/firewall/**'
- 'infra/systemd/**'
- 'infra/prometheus/**'
workflow_dispatch:
concurrency:
group: infra-deploy
cancel-in-progress: false
permissions:
contents: read
env:
VPS_HOST: ${{ secrets.VPS_HOST }}
VPS_USER: ${{ secrets.VPS_USER }}
jobs:
deploy-infra:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v7
- name: Validate Caddyfile syntax
run: |
curl -fsSL "https://caddyserver.com/api/download?os=linux&arch=amd64" -o /tmp/caddy
chmod +x /tmp/caddy
/tmp/caddy validate --config infra/caddy/Caddyfile.prod --adapter caddyfile 2>&1 | tail -5
echo "✅ Caddyfile valid"
- name: Setup SSH key
env:
SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }}
run: |
mkdir -p ~/.ssh
echo "$SSH_KEY" > ~/.ssh/id_ed25519
chmod 600 ~/.ssh/id_ed25519
sed -i 's/\r$//' ~/.ssh/id_ed25519
ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; }
ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null
- name: Sync Caddyfile to VPS
run: |
set -e
ssh "$VPS_USER@$VPS_HOST" "sudo cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak-previous"
scp -q infra/caddy/Caddyfile.prod "$VPS_USER@$VPS_HOST":/tmp/Caddyfile.new
ssh "$VPS_USER@$VPS_HOST" "sudo cp /tmp/Caddyfile.new /etc/caddy/Caddyfile && sudo rm -f /tmp/Caddyfile.new"
echo "✅ Caddyfile synced"
- name: Sync systemd drop-ins to VPS
run: |
set -e
if [ -d infra/systemd ]; then
for f in infra/systemd/*; do
[ -f "$f" ] || continue
base=$(basename "$f")
echo " syncing $base"
scp -q "$f" "$VPS_USER@$VPS_HOST":/tmp/"$base"
ssh "$VPS_USER@$VPS_HOST" "sudo mkdir -p /etc/systemd/system && sudo cp /tmp/$base /etc/systemd/system/$base && sudo rm -f /tmp/$base"
done
ssh "$VPS_USER@$VPS_HOST" "sudo systemctl daemon-reload"
echo "✅ systemd drop-ins synced"
else
echo "no infra/systemd/ files"
fi
- name: Sync prometheus targets to VPS
run: |
set -e
if [ -f infra/prometheus/targets.yml ]; then
scp -q infra/prometheus/targets.yml "$VPS_USER@$VPS_HOST":/tmp/targets.yml
ssh "$VPS_USER@$VPS_HOST" "sudo cp /tmp/targets.yml /etc/prometheus/targets.yml 2>/dev/null && sudo rm -f /tmp/targets.yml && sudo systemctl reload prometheus 2>/dev/null || true"
echo "✅ prometheus targets synced"
else
echo "no infra/prometheus/targets.yml"
fi
- name: Reload Caddy
run: |
ssh "$VPS_USER@$VPS_HOST" "sudo systemctl reload caddy || sudo systemctl restart caddy"
sleep 3
ssh "$VPS_USER@$VPS_HOST" "systemctl is-active caddy"
- name: Verify routes
run: |
set -e
for u in hub.asepharyana.my.id scraper.asepharyana.my.id tools.asepharyana.my.id wiki.asepharyana.my.id upload.asepharyana.my.id ai.asepharyana.my.id; do
code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "https://$u/" || true)
echo "$u -> $code"
case "$code" in
000|502|503|504) echo "::error::$u bad status $code"; exit 1 ;;
esac
done
echo "✅ All routes reachable"