CI / typecheck + tests (push) Canceled after 0s
CI / build + deploy (Nix) — api (push) Canceled after 0s
CI / build + deploy (Nix) — mcp (push) Canceled after 0s
CI / build + deploy (Nix) — worker (push) Canceled after 0s
CI / build + deploy (web) (push) Canceled after 0s
- Update Nix flake.nix overlay to use Bun 1.4.0 (overrideAttrs) - Update CI (setup-bun) to pin bun-version: 1.4.0 - Update package.json packageManager/Dockerfile/vercel.json - sha256: sha256:Poy0vf7yJ/hzk33QiQj5gnshI5Q7dfbaMD7xgwiyDKw=
2.1 KiB
2.1 KiB
MCPedia — Nix-based CI/CD Migration Plan
Goal
Migrate from tarball+SSH deploy to Nix-native build-and-deploy (like GMW).
CI builds with Nix in GitHub Actions → nix copy closure to VPS →
nix-env --set + systemctl restart on VPS. VPS never builds.
Services to migrate
| Service | Build | Runtime | systemd unit |
|---|---|---|---|
| web (Next.js) | bun run build → .next |
next start |
mcpedia-web |
| api (Hono) | bun build src/index.ts → dist/index.js |
bun run src/index.ts |
mcpedia-api |
| mcp (MCP server) | bun build src/http.ts → dist/http.js |
bun run src/http.ts |
mcpedia-mcp |
| worker (BullMQ) | bun build src/index.ts → dist/index.js |
bun run src/index.ts |
mcpedia-worker |
Changes
1. flake.nix (new)
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable"(Bun >=1.3)- 4 packages:
web,api,mcp,worker - Each:
mkDerivationwithbunas nativeBuildInput,sandbox=false - Filter source to exclude
.next,node_modules,.git
2. CI workflow (.github/workflows/ci.yml — rewrite)
testjob: typecheck + test (Bun, as before)build-and-deployjob: matrix [web, api, mcp, worker]DeterminateSystems/nix-installer-action@v16withdeterminate: false,sandbox=falseDeterminateSystems/magic-nix-cache-action@v14withuse-flakehub: falsenix build .#<service>→ store path- SSH setup (key sanitization)
nix copy --to ssh://...nix-env --profile /nix/var/nix/profiles/mcpedia-<service> --set <path>systemctl restart mcpedia-<service>
3. systemd units (update on VPS)
- Change
ExecStartfrombun runto Nix profile binary path - Profile path:
/nix/var/nix/profiles/mcpedia-web/bin/mcpedia-web - Keep
EnvironmentFilepointing to.env - Keep
Restart=always
4. Deploy secrets
SSH_PRIVATE_KEY(already exists asSSH_DEPLOY_KEY)VPS_HOST,VPS_USER,VPS_SSH_PORT
Verification
nix build .#web --impurebuildsgh run listshows all 4 servicescompleted successcurl https://wiki.asepharyana.my.id/returns 200journalctl -u mcpedia-webshows Next.js started