name: Deploy Infra Config on: push: branches: [main] paths: - 'infra/caddy/**' - 'infra/firewall/**' - 'infra/systemd/**' - 'infra/prometheus/**' workflow_dispatch: concurrency: group: infra-deploy cancel-in-progress: false permissions: contents: read env: VPS_HOST: ${{ secrets.VPS_HOST }} VPS_USER: ${{ secrets.VPS_USER }} jobs: deploy-infra: runs-on: ubuntu-latest timeout-minutes: 15 steps: - uses: actions/checkout@v7 - name: Validate Caddyfile syntax run: | curl -fsSL "https://caddyserver.com/api/download?os=linux&arch=amd64" -o /tmp/caddy chmod +x /tmp/caddy /tmp/caddy validate --config infra/caddy/Caddyfile.prod --adapter caddyfile 2>&1 | tail -5 echo "✅ Caddyfile valid" - name: Setup SSH key env: SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }} run: | mkdir -p ~/.ssh echo "$SSH_KEY" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 sed -i 's/\r$//' ~/.ssh/id_ed25519 ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null - name: Sync Caddyfile to VPS run: | set -e ssh "$VPS_USER@$VPS_HOST" "sudo cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak-previous" scp -q infra/caddy/Caddyfile.prod "$VPS_USER@$VPS_HOST":/tmp/Caddyfile.new ssh "$VPS_USER@$VPS_HOST" "sudo cp /tmp/Caddyfile.new /etc/caddy/Caddyfile && sudo rm -f /tmp/Caddyfile.new" echo "✅ Caddyfile synced" - name: Sync systemd drop-ins to VPS run: | set -e if [ -d infra/systemd ]; then for f in infra/systemd/*; do [ -f "$f" ] || continue base=$(basename "$f") echo " syncing $base" scp -q "$f" "$VPS_USER@$VPS_HOST":/tmp/"$base" ssh "$VPS_USER@$VPS_HOST" "sudo mkdir -p /etc/systemd/system && sudo cp /tmp/$base /etc/systemd/system/$base && sudo rm -f /tmp/$base" done ssh "$VPS_USER@$VPS_HOST" "sudo systemctl daemon-reload" echo "✅ systemd drop-ins synced" else echo "no infra/systemd/ files" fi - name: Sync prometheus targets to VPS run: | set -e if [ -f infra/prometheus/targets.yml ]; then scp -q infra/prometheus/targets.yml "$VPS_USER@$VPS_HOST":/tmp/targets.yml ssh "$VPS_USER@$VPS_HOST" "sudo cp /tmp/targets.yml /etc/prometheus/targets.yml 2>/dev/null && sudo rm -f /tmp/targets.yml && sudo systemctl reload prometheus 2>/dev/null || true" echo "✅ prometheus targets synced" else echo "no infra/prometheus/targets.yml" fi - name: Reload Caddy run: | ssh "$VPS_USER@$VPS_HOST" "sudo systemctl reload caddy || sudo systemctl restart caddy" sleep 3 ssh "$VPS_USER@$VPS_HOST" "systemctl is-active caddy" - name: Verify routes run: | set -e for u in hub.asepharyana.my.id scraper.asepharyana.my.id tools.asepharyana.my.id wiki.asepharyana.my.id upload.asepharyana.my.id ai.asepharyana.my.id; do code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "https://$u/" || true) echo "$u -> $code" case "$code" in 000|502|503|504) echo "::error::$u bad status $code"; exit 1 ;; esac done echo "✅ All routes reachable"