From 5d9e60902fb8eeb37f8fc632706952484b22c029 Mon Sep 17 00:00:00 2001 From: asepharyana Date: Thu, 20 Aug 2026 11:57:11 +0700 Subject: [PATCH] ci: add deploy.yml workflow (SSH deploy triggered on CI success) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CI only builds/tests. Deploy is a separate workflow triggered via workflow_run after CI passes: pull → bun install → web build → restart all 4 systemd services (web/api/mcp/worker) over SSH. Secrets (stored in GitHub): - SSH_DEPLOY_HOST=100.79.111.61 - SSH_DEPLOY_PORT=22 - SSH_DEPLOY_USER=code - SSH_DEPLOY_KEY= --- .github/workflows/deploy.yml | 59 ++++++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 .github/workflows/deploy.yml diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml new file mode 100644 index 0000000..f60d9cc --- /dev/null +++ b/.github/workflows/deploy.yml @@ -0,0 +1,59 @@ +name: Deploy + +# Only run after the CI workflow succeeds on the same push to main. +on: + workflow_run: + workflows: ["CI"] + types: [completed] + branches: [main] + +# Skip if CI failed — the condition below gates on workflow_run's conclusion. +concurrency: + group: deploy-${{ github.ref }} + cancel-in-progress: true + +jobs: + deploy: + name: build + deploy + if: ${{ github.event.workflow_run.conclusion == 'success' }} + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Set up Bun + uses: oven-sh/setup-bun@v2 + with: + bun-version: "1.3.14" + + - name: Install dependencies + run: bun install --frozen-lockfile + + - name: Typecheck + run: bun run typecheck + + - name: Build web app + run: bun --cwd apps/web run build + + - name: Deploy to VPS over SSH + env: + SSH_DEPLOY_HOST: ${{ secrets.SSH_DEPLOY_HOST }} + SSH_DEPLOY_PORT: ${{ secrets.SSH_DEPLOY_PORT }} + SSH_DEPLOY_USER: ${{ secrets.SSH_DEPLOY_USER }} + SSH_DEPLOY_KEY: ${{ secrets.SSH_DEPLOY_KEY }} + run: | + mkdir -p ~/.ssh + echo "$SSH_DEPLOY_KEY" > ~/.ssh/deploy_key + chmod 600 ~/.ssh/deploy_key + # Add VPS host key (non-interactive) + ssh-keyscan -p "$SSH_DEPLOY_PORT" "$SSH_DEPLOY_HOST" >> ~/.ssh/known_hosts 2>/dev/null + # Deploy: pull latest, reinstall, rebuild web, restart all 4 services + ssh -i ~/.ssh/deploy_key -p "$SSH_DEPLOY_PORT" "$SSH_DEPLOY_USER@$SSH_DEPLOY_HOST" \ + 'set -e; + cd /home/code/mcpedia && + git pull origin main && + /home/code/.bun/bin/bun install --frozen-lockfile && + /home/code/.bun/bin/bun --cwd apps/web run build && + sudo systemctl restart mcpedia-web mcpedia-api mcpedia-mcp mcpedia-worker && + sleep 3 && + systemctl --no-pager status mcpedia-web mcpedia-api mcpedia-mcp mcpedia-worker --no-legend'