name: CI on: push: branches: [main] pull_request: branches: [main] concurrency: group: ci-${{ github.ref }} cancel-in-progress: true env: VPS_HOST: ${{ secrets.SSH_DEPLOY_HOST }} VPS_USER: ${{ secrets.SSH_DEPLOY_USER }} permissions: contents: read jobs: test: name: typecheck + tests runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v5 - name: Set up Bun uses: oven-sh/setup-bun@v2 with: bun-version: "1.3.14" - name: Install dependencies run: bun install --frozen-lockfile - name: Typecheck run: bun run typecheck - name: Test run: bun run test build-and-deploy: name: build + deploy (Nix) needs: test if: github.ref == 'refs/heads/main' runs-on: ubuntu-latest strategy: fail-fast: false matrix: service: [web, api, mcp, worker] steps: - name: Checkout uses: actions/checkout@v5 with: fetch-depth: 0 - name: Install Nix uses: DeterminateSystems/nix-installer-action@v16 with: determinate: false extra-conf: | sandbox = false accept-flake-config = true - name: Cache Nix uses: DeterminateSystems/magic-nix-cache-action@v14 with: use-flakehub: false - name: Build ${{ matrix.service }} id: build run: | nix build .#${{ matrix.service }} --impure --option sandbox false --print-build-logs STORE_PATH=$(readlink result) echo "store-path=$STORE_PATH" >> "$GITHUB_OUTPUT" echo "Build OK ${{ matrix.service }}: $STORE_PATH" - name: Setup SSH key env: SSH_KEY: ${{ secrets.SSH_DEPLOY_KEY }} run: | mkdir -p ~/.ssh echo "$SSH_KEY" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 sed -i 's/\r$//' ~/.ssh/id_ed25519 ssh-keygen -y -f ~/.ssh/id_ed25519 >/dev/null 2>&1 || { echo "SSH key invalid"; exit 1; } ssh-keyscan -H "$VPS_HOST" >> ~/.ssh/known_hosts 2>/dev/null - name: Copy to VPS & deploy env: SSH_KEY: ${{ secrets.SSH_DEPLOY_KEY }} run: | STORE_PATH="${{ steps.build.outputs.store-path }}" SERVICE="${{ matrix.service }}" PROFILE="mcpedia-${SERVICE}" # Copy Nix closure to VPS nix copy --to "ssh://***@$VPS_HOST" "$STORE_PATH" # Deploy: set profile + restart ssh "$VPS_USER@$VPS_HOST" \ "sudo /nix/var/nix/profiles/default/bin/nix-env \ --profile /nix/var/nix/profiles/$PROFILE \ --set '$STORE_PATH' && \ sudo systemctl restart $PROFILE && \ sleep 3 && \ sudo systemctl status $PROFILE --no-pager --no-legend | head -5" - name: Verify service run: | SERVICE="${{ matrix.service }}" PORT_MAP="web:4016 api:4017 mcp:4021 worker:4018" PORT=$(echo "$PORT_MAP" | grep "$SERVICE" | awk -F: '{print $2}') ssh "$VPS_USER@$VPS_HOST" "curl -s -o /dev/null -w '%{http_code}' http://localhost:$PORT/health 2>/dev/null || systemctl is-active $PROFILE"