From 18cf0d26aafe297961c0b7953b3784e824df3d37 Mon Sep 17 00:00:00 2001 From: asepharyana Date: Sat, 1 Aug 2026 16:41:46 +0700 Subject: [PATCH] ci: migrate CI to GitHub Actions (deploy nix + mirror ke Gitea backup) --- .gitea/workflows/nix-deploy.yml | 71 ------------------------------ .github/workflows/deploy.yml | 70 +++++++++++++++++++++++++++++ .github/workflows/mirror-gitea.yml | 26 +++++++++++ 3 files changed, 96 insertions(+), 71 deletions(-) delete mode 100644 .gitea/workflows/nix-deploy.yml create mode 100644 .github/workflows/deploy.yml create mode 100644 .github/workflows/mirror-gitea.yml diff --git a/.gitea/workflows/nix-deploy.yml b/.gitea/workflows/nix-deploy.yml deleted file mode 100644 index d0d5b88..0000000 --- a/.gitea/workflows/nix-deploy.yml +++ /dev/null @@ -1,71 +0,0 @@ -name: Build & Deploy (Nix) - -on: - push: - branches: - - main - workflow_dispatch: - -jobs: - build-and-deploy: - runs-on: ubuntu-latest - - steps: - - name: Check out repository - run: | - git clone https://git.imrnes.team/MythEclipse/pr-agent-server.git . - git checkout ${{ github.sha }} - - - name: Build & Deploy - env: - VPS_HOST: ${{ secrets.VPS_HOST }} - VPS_USER: ${{ secrets.VPS_USER }} - VPS_SSH_KEY: ${{ secrets.VPS_SSH_KEY }} - run: | - set -eu - - # --- Install Nix & Build --- - curl -fsSL https://install.determinate.systems/nix \ - | sh -s -- install linux --no-confirm --init none 2>&1 - - mkdir -p /etc/nix - echo "experimental-features = nix-command flakes" >> /etc/nix/nix.conf - - . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh - - echo "=== Building: pr-agent-server ===" - nix build .#default --impure --option sandbox false 2>&1 - - STORE_PATH=$(readlink result) - echo "=== Store path: $STORE_PATH" - - # --- Deploy --- - NIX_BIN="/nix/var/nix/profiles/default/bin" - PROFILE="/nix/var/nix/profiles/pr-agent-server" - - key_file=$(mktemp /tmp/deploy-key.XXXXXX) - # VPS_SSH_KEY may be stored base64-encoded (multiline corruption workaround) - if printf '%s' "$VPS_SSH_KEY" | base64 -d 2>/dev/null | head -c 6 | grep -q "BEGIN"; then - printf '%s' "$VPS_SSH_KEY" | base64 -d > "$key_file" - else - printf '%s\n' "$VPS_SSH_KEY" > "$key_file" - fi - chmod 600 "$key_file" - sed -i 's/\r$//' "$key_file" # strip DOS line endings if any - ssh-keygen -y -f "$key_file" >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } - - export NIX_SSHOPTS="-i $key_file -o StrictHostKeyChecking=no" - nix copy --to "ssh://${VPS_USER}@${VPS_HOST}" "$STORE_PATH" 2>&1 - - ssh -i "$key_file" -o StrictHostKeyChecking=no \ - "${VPS_USER}@${VPS_HOST}" " - export PATH=\$PATH:$NIX_BIN - if [ -d $PROFILE ] && [ ! -L $PROFILE ]; then - rm -rf $PROFILE - fi - nix-env --profile $PROFILE --set $STORE_PATH - systemctl daemon-reload - systemctl restart pr-agent-server - sleep 3 - systemctl status pr-agent-server --no-pager 2>&1 | head -12 - " 2>&1 diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml new file mode 100644 index 0000000..60d5667 --- /dev/null +++ b/.github/workflows/deploy.yml @@ -0,0 +1,70 @@ +name: Build & Deploy (Nix) + +on: + push: + branches: [main] + workflow_dispatch: + +concurrency: + group: deploy + cancel-in-progress: false + +permissions: + contents: read + +env: + VPS_HOST: ${{ secrets.VPS_HOST }} + VPS_USER: ${{ secrets.VPS_USER }} + +jobs: + build-and-deploy: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v7 + with: + fetch-depth: 0 + submodules: false + + - name: Install Nix + uses: DeterminateSystems/nix-installer-action@v22 + with: + determinate: false + extra-conf: | + sandbox = false + accept-flake-config = true + + - name: Cache Nix + uses: DeterminateSystems/magic-nix-cache-action@v14 + + - name: Build pr-agent-server + id: build + run: | + nix build .#default --impure --option sandbox false --print-build-logs + STORE_PATH=$(readlink result) + echo "store-path=$STORE_PATH" >> "$GITHUB_OUTPUT" + echo "Build OK: $STORE_PATH" + + - name: Setup SSH key + env: + SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }} + run: | + mkdir -p ~/.ssh + echo "$SSH_KEY" > ~/.ssh/id_ed25519 + chmod 600 ~/.ssh/id_ed25519 + sed -i 's/\r$//' ~/.ssh/id_ed25519 + ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } + ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null + + - name: Deploy pr-agent-server to VPS + run: | + STORE_PATH="${{ steps.build.outputs.store-path }}" + echo "=== Copying pr-agent-server: $STORE_PATH ===" + nix copy --to "ssh://$VPS_USER@$VPS_HOST" "$STORE_PATH" + + echo "=== Updating profile ===" + ssh "$VPS_USER@$VPS_HOST" "sudo /nix/var/nix/profiles/default/bin/nix-env --profile /nix/var/nix/profiles/pr-agent-server --set '$STORE_PATH'" + + echo "=== Restarting service ===" + ssh "$VPS_USER@$VPS_HOST" "sudo systemctl daemon-reload && sudo systemctl restart pr-agent-server && sleep 3 && sudo systemctl is-active pr-agent-server" + echo "✅ pr-agent-server deployed" diff --git a/.github/workflows/mirror-gitea.yml b/.github/workflows/mirror-gitea.yml new file mode 100644 index 0000000..5f099f9 --- /dev/null +++ b/.github/workflows/mirror-gitea.yml @@ -0,0 +1,26 @@ +name: Mirror to Gitea + +on: + push: + branches: [main, master] + workflow_dispatch: + +permissions: + contents: write + +jobs: + mirror: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v7 + with: + fetch-depth: 0 + + - name: Mirror to Gitea + env: + GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} + run: | + git remote add gitea "https://oauth2:${GITEA_TOKEN}@git.imrnes.team/MythEclipse/pr-agent-server.git" + git push --mirror gitea + echo "✅ Mirrored to Gitea (MythEclipse/pr-agent-server)"