Files
mcpedia/.hermes/plans/phase3-deploy.md
T
asepharyana ec0ab4dbb3
CI / typecheck + build (turbo) (push) Canceled after 0s
fix(deploy): wire Phase 3 services + GitHub git-sync webhook
- apps/api: assertWebhookAuth now verifies GitHub X-Hub-Signature-256 HMAC
  (raw-body HMAC-SHA256) AND the manual x-webhook-secret header. GitHub does
  not send a custom header, so only the HMAC path made the push webhook work.
- root package.json: api/worker scripts use absolute bun path + direct-file
  form (bun --cwd apps/api run dev errored in bun 1.3.14).
- deploy/*.service: ExecStart uses /home/code/.bun/bin/bun (systemd PATH lacks bun).
- GitHub push webhook created -> https://wiki.asepharyana.my.id/hooks/reindex
  (verified: ping + push deliveries return 200, worker drains, 0 failed).
- Caddy: expose /hooks/* + /health on wiki.asepharyana.my.id -> :4020.
Services mcpedia-api + mcpedia-worker now enabled + active on host.
2026-08-20 09:38:32 +07:00

1.6 KiB

Phase 3 — Deploy + git-sync wiring (remaining work)

Status: Phase 3/4 code is DONE and e2e-verified (webhook enqueue -> worker drain, 0 failed). What was missing on the host: API + worker never ran as systemd services, and the GitHub push webhook was never created. Also a real integration bug: assertWebhookAuth only accepts a plain x-webhook-secret header, which GitHub does NOT send (GitHub delivers X-Hub-Signature-256 = HMAC-SHA256 of raw body). So a real GitHub webhook would 401.

Changes

  1. apps/api/src/index.ts — assertWebhookAuth now verifies GitHub X-Hub-Signature-256 (HMAC-SHA256 of raw body w/ WEBHOOK_SECRET) and still accepts x-webhook-secret for manual tests.
  2. root package.json scripts — api: bun --cwd apps/api run dev -> bun --cwd apps/api src/index.ts (the run dev form errors in bun 1.3.14; direct-file form verified booting + health). worker -> same form for consistency.
  3. systemd — cp deploy/*.service /etc/systemd/system, daemon-reload, enable --now mcpedia-api mcpedia-worker.
  4. Caddy — expose /hooks/* on wiki.asepharyana.my.id -> :4020 (no new DNS). Keep web on :4016.
  5. GitHub webhook — gh api repos/asepharyana/mcpedia/hooks POST: https://wiki.asepharyana.my.id/hooks/reindex, content_type json, secret=WEBHOOK_SECRET, events=push.

Verification

  • systemctl is-active mcpedia-api mcpedia-worker == active.
  • curl /health on :4020 -> ok.
  • curl -X POST https://wiki.asepharyana.my.id/hooks/reindex -H "X-Hub-Signature-256: ..." (or x-webhook-secret) -> 200 + jobId; worker drains.
  • gh api .../hooks lists the webhook.
  • turbo run typecheck green; commit + push.