ci: validate Caddyfile with real caddy binary instead of naive brace count
Deploy Caddy Config / deploy-caddy (push) Canceled after 0s

This commit is contained in:
asepharyana
2026-08-27 19:50:24 +07:00
parent 4c6c368764
commit 6ac562a869
+8 -10
View File
@@ -27,6 +27,14 @@ jobs:
steps:
- uses: actions/checkout@v7
- name: Validate Caddyfile syntax
run: |
# Real Caddy parser (better than naive brace counting)
curl -fsSL https://caddyserver.com/api/download?os=linux\&arch=amd64 -o /tmp/caddy
chmod +x /tmp/caddy
/tmp/caddy validate --config infra/caddy/Caddyfile.prod --adapter caddyfile 2>&1 | tail -5
echo "✅ Caddyfile valid"
- name: Setup SSH key
env:
SSH_KEY: ${{ secrets.SSH_PRIVATE_KEY }}
@@ -38,15 +46,6 @@ jobs:
ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; }
ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null
- name: Validate Caddyfile syntax
run: |
# Basic sanity: no obviously empty file, brace count balanced
test -s infra/caddy/Caddyfile.prod || { echo "Caddyfile.prod missing/empty"; exit 1; }
opens=$(grep -c '{' infra/caddy/Caddyfile.prod || true)
closes=$(grep -c '}' infra/caddy/Caddyfile.prod || true)
echo "braces open=$opens close=$closes"
[ "$opens" = "$closes" ] || { echo "unbalanced braces"; exit 1; }
- name: Sync Caddyfile to VPS
run: |
set -e
@@ -68,7 +67,6 @@ jobs:
for u in hub.asepharyana.my.id scraper.asepharyana.my.id tools.asepharyana.my.id wiki.asepharyana.my.id upload.asepharyana.my.id ai.asepharyana.my.id; do
code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "https://$u/" || true)
echo "$u -> $code"
# 000/000 means route didn't answer; 404 on root is fine for API-first apps
case "$code" in
000|502|503|504) echo "::error::$u bad status $code"; exit 1 ;;
esac