refactor(infra): repurpose asepharyana-hub into infra-only reverse-proxy repo
- Remove app submodules (hub/scraper/tools/llm-api/plugins) — apps are now standalone repos with their own flake.nix + deploy.yml CI - Delete monorepo CI: nix-build.yml matrix, update-submodule.yml, lint, security, flakehub-publish — replaced by infra-only caddy-deploy.yml - Sync Caddyfile.prod with live /etc/caddy/Caddyfile (add wiki. + mcp. blocks) - Prune legacy Docker/Traefik/Dapr/NATS/otel + scripts/root tooling - Docs: rename ADR 0001 superseded, add ADR 0003 (repo rename + split CI), update add-new-app, infra README, troubleshooting
This commit is contained in:
@@ -0,0 +1,76 @@
|
||||
name: Deploy Caddy Config
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
paths:
|
||||
- 'infra/caddy/**'
|
||||
- 'infra/firewall/**'
|
||||
- 'infra/systemd/**'
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: caddy-deploy
|
||||
cancel-in-progress: false
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
VPS_HOST: ${{ secrets.VPS_HOST }}
|
||||
VPS_USER: ${{ secrets.VPS_USER }}
|
||||
|
||||
jobs:
|
||||
deploy-caddy:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
|
||||
- name: Setup SSH key
|
||||
env:
|
||||
SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
run: |
|
||||
mkdir -p ~/.ssh
|
||||
echo "$SSH_KEY" > ~/.ssh/id_ed25519
|
||||
chmod 600 ~/.ssh/id_ed25519
|
||||
sed -i 's/\r$//' ~/.ssh/id_ed25519
|
||||
ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; }
|
||||
ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null
|
||||
|
||||
- name: Validate Caddyfile syntax
|
||||
run: |
|
||||
# Basic sanity: no obviously empty file, brace count balanced
|
||||
test -s infra/caddy/Caddyfile.prod || { echo "Caddyfile.prod missing/empty"; exit 1; }
|
||||
opens=$(grep -c '{' infra/caddy/Caddyfile.prod || true)
|
||||
closes=$(grep -c '}' infra/caddy/Caddyfile.prod || true)
|
||||
echo "braces open=$opens close=$closes"
|
||||
[ "$opens" = "$closes" ] || { echo "unbalanced braces"; exit 1; }
|
||||
|
||||
- name: Sync Caddyfile to VPS
|
||||
run: |
|
||||
set -e
|
||||
# Backup current config, then push the new one
|
||||
ssh "$VPS_USER@$VPS_HOST" "sudo cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak-previous"
|
||||
scp -q infra/caddy/Caddyfile.prod "$VPS_USER@$VPS_HOST":/tmp/Caddyfile.new
|
||||
ssh "$VPS_USER@$VPS_HOST" "sudo cp /tmp/Caddyfile.new /etc/caddy/Caddyfile && sudo rm -f /tmp/Caddyfile.new"
|
||||
echo "✅ Caddyfile synced"
|
||||
|
||||
- name: Reload Caddy
|
||||
run: |
|
||||
ssh "$VPS_USER@$VPS_HOST" "sudo systemctl reload caddy || sudo systemctl restart caddy"
|
||||
sleep 3
|
||||
ssh "$VPS_USER@$VPS_HOST" "systemctl is-active caddy"
|
||||
|
||||
- name: Verify routes
|
||||
run: |
|
||||
set -e
|
||||
for u in hub.asepharyana.my.id scraper.asepharyana.my.id tools.asepharyana.my.id wiki.asepharyana.my.id upload.asepharyana.my.id ai.asepharyana.my.id; do
|
||||
code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "https://$u/" || true)
|
||||
echo "$u -> $code"
|
||||
# 000/000 means route didn't answer; 404 on root is fine for API-first apps
|
||||
case "$code" in
|
||||
000|502|503|504) echo "::error::$u bad status $code"; exit 1 ;;
|
||||
esac
|
||||
done
|
||||
echo "✅ All routes reachable"
|
||||
@@ -1,20 +0,0 @@
|
||||
name: Publish to FlakeHub
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main, master]
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
flakehub-publish:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
- uses: DeterminateSystems/determinate-nix-action@main
|
||||
- uses: DeterminateSystems/flakehub-push@main
|
||||
with:
|
||||
visibility: public
|
||||
rolling: true
|
||||
@@ -1,28 +0,0 @@
|
||||
name: Lint
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
paths:
|
||||
- 'biome.json'
|
||||
- '*.json'
|
||||
- '*.js'
|
||||
push:
|
||||
branches: [main]
|
||||
paths:
|
||||
- 'biome.json'
|
||||
- '*.json'
|
||||
- '*.js'
|
||||
|
||||
jobs:
|
||||
biome:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
with:
|
||||
submodules: recursive
|
||||
- uses: oven-sh/setup-bun@v2
|
||||
- run: bun install --frozen-lockfile
|
||||
- run: bun run ci
|
||||
@@ -1,103 +0,0 @@
|
||||
name: Nix Build & Deploy — All Services
|
||||
|
||||
on:
|
||||
# No `paths` filter: GitHub's path filters do not match submodule gitlink
|
||||
# changes, so a submodule pointer update (e.g. from update-submodule.yml)
|
||||
# would never trigger this deploy. Run on every push to main instead.
|
||||
push:
|
||||
branches: [main]
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: nix-deploy
|
||||
cancel-in-progress: false
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
|
||||
env:
|
||||
VPS_HOST: ${{ secrets.VPS_HOST }}
|
||||
VPS_USER: ${{ secrets.VPS_USER }}
|
||||
|
||||
jobs:
|
||||
build-and-deploy:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
service: [hub, scraper, tools-gateway, tools-workers, tools-frontend, llm-api]
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v7
|
||||
with:
|
||||
submodules: recursive
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Install Nix
|
||||
uses: DeterminateSystems/nix-installer-action@v22
|
||||
with:
|
||||
determinate: false
|
||||
extra-conf: |
|
||||
sandbox = false
|
||||
accept-flake-config = true
|
||||
|
||||
- name: Cache Nix
|
||||
uses: DeterminateSystems/magic-nix-cache-action@v14
|
||||
with:
|
||||
use-flakehub: false
|
||||
|
||||
- name: Build ${{ matrix.service }}
|
||||
id: build
|
||||
run: |
|
||||
nix build .#${{ matrix.service }} --impure --option sandbox false --print-build-logs
|
||||
STORE_PATH=$(readlink result)
|
||||
echo "store-path=$STORE_PATH" >> "$GITHUB_OUTPUT"
|
||||
echo "✅ ${{ matrix.service }}: $STORE_PATH"
|
||||
|
||||
- name: Setup SSH key
|
||||
if: github.ref == 'refs/heads/main'
|
||||
env:
|
||||
SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
run: |
|
||||
mkdir -p ~/.ssh
|
||||
echo "$SSH_KEY" > ~/.ssh/id_ed25519
|
||||
chmod 600 ~/.ssh/id_ed25519
|
||||
sed -i 's/\r$//' ~/.ssh/id_ed25519
|
||||
ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; }
|
||||
ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null
|
||||
|
||||
- name: Deploy ${{ matrix.service }} to VPS
|
||||
if: github.ref == 'refs/heads/main'
|
||||
run: |
|
||||
STORE_PATH="${{ steps.build.outputs.store-path }}"
|
||||
echo "=== Copying ${{ matrix.service }}: $STORE_PATH ==="
|
||||
nix copy --to "ssh://$VPS_USER@$VPS_HOST" "$STORE_PATH"
|
||||
|
||||
echo "=== Updating profile ==="
|
||||
ssh "$VPS_USER@$VPS_HOST" "sudo /nix/var/nix/profiles/default/bin/nix-env --profile /nix/var/nix/profiles/${{ matrix.service }} --set '$STORE_PATH'"
|
||||
|
||||
echo "=== Restarting service ==="
|
||||
ssh "$VPS_USER@$VPS_HOST" "sudo systemctl restart ${{ matrix.service }}" || echo " ⚠️ restart failed (may not be enabled yet)"
|
||||
|
||||
echo "✅ ${{ matrix.service }} deployed"
|
||||
|
||||
cleanup:
|
||||
# Bersihkan sampah Nix di VPS SETELAH deploy: hapus generasi profile lama
|
||||
# + nix store gc. Profil yang sedang dipakai tidak disentuh.
|
||||
needs: build-and-deploy
|
||||
if: always()
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Nix GC on VPS
|
||||
env:
|
||||
VPS_HOST: ${{ secrets.VPS_HOST }}
|
||||
VPS_USER: ${{ secrets.VPS_USER }}
|
||||
SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
run: |
|
||||
mkdir -p ~/.ssh
|
||||
echo "$SSH_KEY" > ~/.ssh/id_ed25519
|
||||
chmod 600 ~/.ssh/id_ed25519
|
||||
ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null
|
||||
ssh "$VPS_USER@$VPS_HOST" "sudo /usr/local/bin/nix-gc-vps.sh" || echo "⚠️ Nix GC gagal (non-fatal)"
|
||||
@@ -1,30 +0,0 @@
|
||||
name: Security
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
schedule:
|
||||
- cron: '0 6 * * 1' # Every Monday
|
||||
|
||||
jobs:
|
||||
codeql:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
permissions:
|
||||
security-events: write
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
with:
|
||||
fetch-depth: 2
|
||||
submodules: recursive
|
||||
|
||||
- uses: github/codeql-action/init@v4
|
||||
with:
|
||||
languages: rust
|
||||
|
||||
- name: Build Rust projects for CodeQL analysis
|
||||
run: |
|
||||
cargo build --manifest-path apps/scraper/Cargo.toml
|
||||
cargo build --manifest-path apps/llm-api/Cargo.toml
|
||||
|
||||
- uses: github/codeql-action/analyze@v4
|
||||
@@ -1,86 +0,0 @@
|
||||
name: Update Submodule Pointer
|
||||
on:
|
||||
repository_dispatch:
|
||||
types: [submodule-updated]
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
jobs:
|
||||
update:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
|
||||
- name: Validate payload
|
||||
env:
|
||||
SERVICE: ${{ github.event.client_payload.service }}
|
||||
SHA: ${{ github.event.client_payload.sha }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
if [ -z "${SERVICE:-}" ]; then
|
||||
echo "::error::Missing service in payload"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ -z "${SHA:-}" ]; then
|
||||
echo "::error::Missing sha in payload"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if ! [[ "$SHA" =~ ^[0-9a-fA-F]{40}$ ]]; then
|
||||
echo "::error::Invalid sha '$SHA'. Expected 40 hex characters."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
case "$SERVICE" in
|
||||
scraper-api|hub|llm-api|tools) ;;
|
||||
*)
|
||||
echo "::error::Unsupported service '$SERVICE'"
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
echo "Payload validated: $SERVICE → $SHA"
|
||||
|
||||
- name: Update submodule pointer
|
||||
env:
|
||||
SERVICE: ${{ github.event.client_payload.service }}
|
||||
SHA: ${{ github.event.client_payload.sha }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
# Map service name to submodule path
|
||||
case "$SERVICE" in
|
||||
scraper-api) SUBMODULE_PATH="apps/scraper" ;;
|
||||
llm-api) SUBMODULE_PATH="apps/llm-api" ;;
|
||||
*) SUBMODULE_PATH="apps/${SERVICE}" ;;
|
||||
esac
|
||||
|
||||
echo "Updating ${SUBMODULE_PATH} to ${SHA}"
|
||||
git submodule update --init "${SUBMODULE_PATH}"
|
||||
cd "${SUBMODULE_PATH}"
|
||||
git fetch --depth=1 origin master 2>/dev/null || git fetch --depth=1 origin main
|
||||
git checkout "${SHA}"
|
||||
cd "${GITHUB_WORKSPACE}"
|
||||
git add "${SUBMODULE_PATH}"
|
||||
git diff --cached --quiet && exit 0
|
||||
|
||||
git config user.name "monrepo-bot"
|
||||
git config user.email "monrepo-bot@users.noreply.github.com"
|
||||
git commit -m "chore: update ${SERVICE} to ${SHA:0:12}"
|
||||
|
||||
for attempt in {1..3}; do
|
||||
if git pull --rebase origin main && git push origin main; then
|
||||
echo "✅ Push succeeded on attempt $attempt"
|
||||
exit 0
|
||||
fi
|
||||
echo "⚠️ Push attempt $attempt/3 failed; retrying..."
|
||||
git rebase --abort 2>/dev/null || true
|
||||
sleep 3
|
||||
done
|
||||
|
||||
echo "::error::Failed to push submodule update after 3 attempts"
|
||||
exit 1
|
||||
Reference in New Issue
Block a user