diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0f7a530..244efaf 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -28,7 +28,7 @@ jobs: - name: Set up Bun uses: oven-sh/setup-bun@v2 with: - bun-version: "1.3.14" + bun-version: "1.4.0" - name: Install dependencies run: bun install --frozen-lockfile @@ -207,7 +207,7 @@ jobs: - name: Set up Bun uses: oven-sh/setup-bun@v2 with: - bun-version: "1.3.14" + bun-version: "1.4.0" - name: Install Nix uses: DeterminateSystems/nix-installer-action@v16 diff --git a/.hermes/plans/nix-ci-migration.md b/.hermes/plans/nix-ci-migration.md new file mode 100644 index 0000000..f6a56a9 --- /dev/null +++ b/.hermes/plans/nix-ci-migration.md @@ -0,0 +1,49 @@ +# MCPedia — Nix-based CI/CD Migration Plan + +## Goal +Migrate from tarball+SSH deploy to Nix-native build-and-deploy (like GMW). +CI builds with Nix in GitHub Actions → `nix copy` closure to VPS → +`nix-env --set` + `systemctl restart` on VPS. VPS never builds. + +## Services to migrate +| Service | Build | Runtime | systemd unit | +|---------|-------|---------|-------------| +| web (Next.js) | `bun run build` → `.next` | `next start` | `mcpedia-web` | +| api (Hono) | `bun build src/index.ts` → `dist/index.js` | `bun run src/index.ts` | `mcpedia-api` | +| mcp (MCP server) | `bun build src/http.ts` → `dist/http.js` | `bun run src/http.ts` | `mcpedia-mcp` | +| worker (BullMQ) | `bun build src/index.ts` → `dist/index.js` | `bun run src/index.ts` | `mcpedia-worker` | + +## Changes + +### 1. flake.nix (new) +- `nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable"` (Bun >=1.3) +- 4 packages: `web`, `api`, `mcp`, `worker` +- Each: `mkDerivation` with `bun` as nativeBuildInput, `sandbox=false` +- Filter source to exclude `.next`, `node_modules`, `.git` + +### 2. CI workflow (.github/workflows/ci.yml — rewrite) +- `test` job: typecheck + test (Bun, as before) +- `build-and-deploy` job: matrix [web, api, mcp, worker] + - `DeterminateSystems/nix-installer-action@v16` with `determinate: false`, `sandbox=false` + - `DeterminateSystems/magic-nix-cache-action@v14` with `use-flakehub: false` + - `nix build .#` → store path + - SSH setup (key sanitization) + - `nix copy --to ssh://...` + - `nix-env --profile /nix/var/nix/profiles/mcpedia- --set ` + - `systemctl restart mcpedia-` + +### 3. systemd units (update on VPS) +- Change `ExecStart` from `bun run` to Nix profile binary path +- Profile path: `/nix/var/nix/profiles/mcpedia-web/bin/mcpedia-web` +- Keep `EnvironmentFile` pointing to `.env` +- Keep `Restart=always` + +### 4. Deploy secrets +- `SSH_PRIVATE_KEY` (already exists as `SSH_DEPLOY_KEY`) +- `VPS_HOST`, `VPS_USER`, `VPS_SSH_PORT` + +## Verification +- `nix build .#web --impure` builds +- `gh run list` shows all 4 services `completed success` +- `curl https://wiki.asepharyana.my.id/` returns 200 +- `journalctl -u mcpedia-web` shows Next.js started diff --git a/flake.nix b/flake.nix index fa19d41..93ec130 100644 --- a/flake.nix +++ b/flake.nix @@ -12,6 +12,17 @@ pkgs = import nixpkgs { inherit system; config = { allowUnfree = true; }; + overlays = [ + (self: super: { + bun = super.bun.overrideAttrs (old: rec { + version = "1.4.0"; + src = super.fetchzip { + url = "https://github.com/oven-sh/bun/releases/download/bun-v1.4.0/bun-linux-x64.zip"; + sha256 = "sha256:Poy0vf7yJ/hzk33QiQj5gnshI5Q7dfbaMD7xgwiyDKw="; + }; + }); + }) + ]; }; bunBin = pkgs.bun + "/bin/bun"; diff --git a/package.json b/package.json index 1b698e1..0e6f387 100644 --- a/package.json +++ b/package.json @@ -2,7 +2,7 @@ "name": "mcpedia", "version": "0.1.0", "private": true, - "packageManager": "bun@1.3.14", + "packageManager": "bun@1.4.0", "workspaces": [ "apps/*", "packages/*",