name: Build & Deploy (Bun) on: push: branches: [main] workflow_dispatch: concurrency: group: deploy cancel-in-progress: false permissions: contents: read id-token: write env: VPS_HOST: ${{ secrets.VPS_HOST }} VPS_USER: ${{ secrets.VPS_USER }} jobs: build-and-deploy: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v7 with: fetch-depth: 0 - name: Setup Bun uses: oven-sh/setup-bun@v2 with: bun-version: 1.3.14 - name: Typecheck + tests working-directory: server run: | bun install --frozen-lockfile bunx tsc --noEmit bun test - name: Build single binary working-directory: server run: | bun build --compile src/index.ts --outfile pr-agent-bun ls -lh pr-agent-bun - name: Setup SSH key env: SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }} run: | mkdir -p ~/.ssh echo "$SSH_KEY" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 sed -i 's/\r$//' ~/.ssh/id_ed25519 ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null - name: Deploy to VPS run: | echo "=== Uploading pr-agent-bun binary ===" scp server/pr-agent-bun "$VPS_USER@$VPS_HOST:/tmp/pr-agent-bun.new" echo "=== Staging swap + restart ===" ssh "$VPS_USER@$VPS_HOST" ' set -e sudo cp /opt/pr-agent-server/bin/pr-agent-bun /opt/pr-agent-server/bin/pr-agent-bun.prev sudo mv /tmp/pr-agent-bun.new /opt/pr-agent-server/bin/pr-agent-bun sudo chown root:root /opt/pr-agent-server/bin/pr-agent-bun sudo chmod 755 /opt/pr-agent-server/bin/pr-agent-bun sudo systemctl restart pr-agent-bun.service sleep 3 systemctl is-active pr-agent-bun.service curl -fsS http://127.0.0.1:4023/health ' echo "✅ pr-agent-bun deployed" cleanup: # Bersihkan sampah Nix di VPS SETELAH deploy: hapus generasi profile lama # + nix store gc. Profil yang sedang dipakai tidak disentuh. needs: build-and-deploy if: always() runs-on: ubuntu-latest steps: - name: Nix GC on VPS env: VPS_HOST: ${{ secrets.VPS_HOST }} VPS_USER: ${{ secrets.VPS_USER }} SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }} run: | mkdir -p ~/.ssh echo "$SSH_KEY" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null ssh "$VPS_USER@$VPS_HOST" "sudo /usr/local/bin/nix-gc-vps.sh" || echo "⚠️ Nix GC gagal (non-fatal)"