diff --git a/.gitea/workflows/nix-deploy.yml b/.gitea/workflows/nix-deploy.yml deleted file mode 100644 index 8a43398..0000000 --- a/.gitea/workflows/nix-deploy.yml +++ /dev/null @@ -1,78 +0,0 @@ -name: Build & Deploy (Nix) - -on: - push: - branches: - - main - workflow_dispatch: - -jobs: - build-and-deploy: - strategy: - fail-fast: false - max-parallel: 1 - matrix: - service: [api, ml-service, web] - runs-on: ubuntu-latest - - steps: - - name: Check out repository - run: | - git clone https://git.imrnes.team/MythEclipse/zeavis-edu.git . - git checkout ${{ github.sha }} - - - name: Build & Deploy ${{ matrix.service }} - env: - VPS_HOST: ${{ secrets.VPS_HOST }} - VPS_USER: ${{ secrets.VPS_USER }} - VPS_SSH_KEY: ${{ secrets.VPS_SSH_KEY }} - run: | - set -eu - - # --- Install Nix & Build --- - curl -fsSL https://install.determinate.systems/nix \ - | sh -s -- install linux --no-confirm --init none 2>&1 - - mkdir -p /etc/nix - echo "experimental-features = nix-command flakes" >> /etc/nix/nix.conf - - . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh - - echo "=== Building: zeavis-${{ matrix.service }} ===" - STORE_PATH=$(nix build .#${{ matrix.service }} --impure --option sandbox false --no-link --print-out-paths | tail -1) - echo "=== Store path: $STORE_PATH" - - # --- Deploy --- - key_file=$(mktemp /tmp/deploy-key.XXXXXX) - if printf '%s' "$VPS_SSH_KEY" | base64 -d 2>/dev/null | head -c 6 | grep -q "BEGIN"; then - printf '%s' "$VPS_SSH_KEY" | base64 -d > "$key_file" - else - printf '%s\n' "$VPS_SSH_KEY" > "$key_file" - fi - chmod 600 "$key_file" - sed -i 's/\r$//' "$key_file" - ssh-keygen -y -f "$key_file" >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } - - export NIX_SSHOPTS="-i $key_file -o StrictHostKeyChecking=no" - nix copy --to "ssh://${VPS_USER}@${VPS_HOST}" "$STORE_PATH" 2>&1 - - ssh -i "$key_file" -o StrictHostKeyChecking=no "${VPS_USER}@${VPS_HOST}" " - set -eu - if [ -d /nix/var/nix/profiles/zeavis-${{ matrix.service }} ] && [ ! -L /nix/var/nix/profiles/zeavis-${{ matrix.service }} ]; then - rm -rf /nix/var/nix/profiles/zeavis-${{ matrix.service }} - fi - nix-env --profile /nix/var/nix/profiles/zeavis-${{ matrix.service }} --set $STORE_PATH - systemctl daemon-reload - systemctl enable zeavis-${{ matrix.service }} 2>/dev/null || true - systemctl restart zeavis-${{ matrix.service }} - for i in \$(seq 1 30); do - systemctl is-active --quiet zeavis-${{ matrix.service }} && break - sleep 1 - done - systemctl is-active zeavis-${{ matrix.service }} || { - echo \"=== SERVICE FAILED — journal ===\" - journalctl -u zeavis-${{ matrix.service }} -n 40 --no-pager - exit 1 - } - systemctl status zeavis-${{ matrix.service }} --no-pager 2>&1 | head -8 - " 2>&1 diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml new file mode 100644 index 0000000..de128c3 --- /dev/null +++ b/.github/workflows/deploy.yml @@ -0,0 +1,90 @@ +name: Build & Deploy (Nix) + +on: + push: + branches: [main] + workflow_dispatch: + +concurrency: + group: zeavis-deploy + cancel-in-progress: false + +permissions: + contents: read + +env: + VPS_HOST: ${{ secrets.VPS_HOST }} + VPS_USER: ${{ secrets.VPS_USER }} + +jobs: + build-and-deploy: + runs-on: ubuntu-latest + strategy: + fail-fast: false + max-parallel: 1 + matrix: + service: [api, ml-service, web] + steps: + - name: Checkout + uses: actions/checkout@v7 + with: + fetch-depth: 0 + submodules: false + + - name: Install Nix + uses: DeterminateSystems/nix-installer-action@v22 + with: + determinate: false + extra-conf: | + sandbox = false + accept-flake-config = true + + - name: Cache Nix + uses: DeterminateSystems/magic-nix-cache-action@v14 + + - name: Build zeavis-${{ matrix.service }} + id: build + run: | + STORE_PATH=$(nix build .#${{ matrix.service }} --impure --option sandbox false --no-link --print-out-paths | tail -1) + echo "store-path=$STORE_PATH" >> "$GITHUB_OUTPUT" + echo "Build OK zeavis-${{ matrix.service }}: $STORE_PATH" + + - name: Setup SSH key + env: + SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }} + run: | + mkdir -p ~/.ssh + echo "$SSH_KEY" > ~/.ssh/id_ed25519 + chmod 600 ~/.ssh/id_ed25519 + sed -i 's/\r$//' ~/.ssh/id_ed25519 + ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } + ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null + + - name: Deploy zeavis-${{ matrix.service }} to VPS + run: | + STORE_PATH="${{ steps.build.outputs.store-path }}" + echo "=== Copying zeavis-${{ matrix.service }}: $STORE_PATH ===" + nix copy --to "ssh://$VPS_USER@$VPS_HOST" "$STORE_PATH" + + echo "=== Updating profile + restarting ===" + ssh "$VPS_USER@$VPS_HOST" " + set -eu + if [ -d /nix/var/nix/profiles/zeavis-${{ matrix.service }} ] && [ ! -L /nix/var/nix/profiles/zeavis-${{ matrix.service }} ]; then + rm -rf /nix/var/nix/profiles/zeavis-${{ matrix.service }} + fi + sudo /nix/var/nix/profiles/default/bin/nix-env --profile /nix/var/nix/profiles/zeavis-${{ matrix.service }} --set '$STORE_PATH' + sudo systemctl daemon-reload + sudo systemctl enable zeavis-${{ matrix.service }} 2>/dev/null || true + sudo systemctl restart zeavis-${{ matrix.service }} + for i in \$(seq 1 30); do + systemctl is-active --quiet zeavis-${{ matrix.service }} && break + sleep 1 + done + systemctl is-active zeavis-${{ matrix.service }} || { + echo '=== SERVICE FAILED — journal ===' + journalctl -u zeavis-${{ matrix.service }} -n 40 --no-pager + exit 1 + } + systemctl status zeavis-${{ matrix.service }} --no-pager 2>&1 | head -8 + " + echo "✅ zeavis-${{ matrix.service }} deployed" diff --git a/.github/workflows/mirror-gitea.yml b/.github/workflows/mirror-gitea.yml new file mode 100644 index 0000000..0547d3f --- /dev/null +++ b/.github/workflows/mirror-gitea.yml @@ -0,0 +1,26 @@ +name: Mirror to Gitea + +on: + push: + branches: [main, master] + workflow_dispatch: + +permissions: + contents: write + +jobs: + mirror: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v7 + with: + fetch-depth: 0 + + - name: Mirror to Gitea + env: + GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} + run: | + git remote add gitea "https://oauth2:${GITEA_TOKEN}@git.imrnes.team/MythEclipse/zeavis-edu.git" + git push --mirror gitea + echo "✅ Mirrored to Gitea (MythEclipse/zeavis-edu)"