Files
mcpedia/deploy/mcpedia-api.service
asepharyana ec0ab4dbb3
CI / typecheck + build (turbo) (push) Canceled after 0s
fix(deploy): wire Phase 3 services + GitHub git-sync webhook
- apps/api: assertWebhookAuth now verifies GitHub X-Hub-Signature-256 HMAC
  (raw-body HMAC-SHA256) AND the manual x-webhook-secret header. GitHub does
  not send a custom header, so only the HMAC path made the push webhook work.
- root package.json: api/worker scripts use absolute bun path + direct-file
  form (bun --cwd apps/api run dev errored in bun 1.3.14).
- deploy/*.service: ExecStart uses /home/code/.bun/bin/bun (systemd PATH lacks bun).
- GitHub push webhook created -> https://wiki.asepharyana.my.id/hooks/reindex
  (verified: ping + push deliveries return 200, worker drains, 0 failed).
- Caddy: expose /hooks/* + /health on wiki.asepharyana.my.id -> :4020.
Services mcpedia-api + mcpedia-worker now enabled + active on host.
2026-08-20 09:38:32 +07:00

26 lines
737 B
Desktop File

[Unit]
Description=MCPedia API (tRPC/Hono + git-sync webhooks)
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
WorkingDirectory=/home/code/mcpedia
# Loads DATABASE_URL, REDIS_*, EMBED_*, WEBHOOK_SECRET from the repo .env
# (.env is gitignored; for prod, point this at a deployed secret file).
EnvironmentFile=/home/code/mcpedia/.env
# Absolute bun path (systemd has a minimal PATH; /usr/bin/env bun fails).
ExecStart=/home/code/.bun/bin/bun --cwd apps/api src/index.ts
Restart=on-failure
RestartSec=5
User=code
Group=code
# The API needs WEBHOOK_SECRET; fail-fast is built into the app if it's missing.
NoNewPrivileges=true
PrivateTmp=true
MemoryMax=512M
TasksMax=256
[Install]
WantedBy=multi-user.target