CI / typecheck + build (turbo) (push) Canceled after 0s
- apps/api: assertWebhookAuth now verifies GitHub X-Hub-Signature-256 HMAC (raw-body HMAC-SHA256) AND the manual x-webhook-secret header. GitHub does not send a custom header, so only the HMAC path made the push webhook work. - root package.json: api/worker scripts use absolute bun path + direct-file form (bun --cwd apps/api run dev errored in bun 1.3.14). - deploy/*.service: ExecStart uses /home/code/.bun/bin/bun (systemd PATH lacks bun). - GitHub push webhook created -> https://wiki.asepharyana.my.id/hooks/reindex (verified: ping + push deliveries return 200, worker drains, 0 failed). - Caddy: expose /hooks/* + /health on wiki.asepharyana.my.id -> :4020. Services mcpedia-api + mcpedia-worker now enabled + active on host.
25 lines
654 B
Desktop File
25 lines
654 B
Desktop File
[Unit]
|
|
Description=MCPedia indexing/embedding worker (BullMQ)
|
|
After=network-online.target redis.service
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
WorkingDirectory=/home/code/mcpedia
|
|
# Loads DATABASE_URL, REDIS_*, EMBED_* from the repo .env
|
|
# (.env is gitignored; for prod, point this at a deployed secret file).
|
|
EnvironmentFile=/home/code/mcpedia/.env
|
|
# Absolute bun path (systemd has a minimal PATH; /usr/bin/env bun fails).
|
|
ExecStart=/home/code/.bun/bin/bun --cwd apps/worker src/index.ts
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
User=code
|
|
Group=code
|
|
NoNewPrivileges=true
|
|
PrivateTmp=true
|
|
MemoryMax=1G
|
|
TasksMax=256
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|