CI / typecheck + build (turbo) (push) Canceled after 0s
- apps/api: assertWebhookAuth now verifies GitHub X-Hub-Signature-256 HMAC (raw-body HMAC-SHA256) AND the manual x-webhook-secret header. GitHub does not send a custom header, so only the HMAC path made the push webhook work. - root package.json: api/worker scripts use absolute bun path + direct-file form (bun --cwd apps/api run dev errored in bun 1.3.14). - deploy/*.service: ExecStart uses /home/code/.bun/bin/bun (systemd PATH lacks bun). - GitHub push webhook created -> https://wiki.asepharyana.my.id/hooks/reindex (verified: ping + push deliveries return 200, worker drains, 0 failed). - Caddy: expose /hooks/* + /health on wiki.asepharyana.my.id -> :4020. Services mcpedia-api + mcpedia-worker now enabled + active on host.
1.6 KiB
1.6 KiB
Phase 3 — Deploy + git-sync wiring (remaining work)
Status: Phase 3/4 code is DONE and e2e-verified (webhook enqueue -> worker drain, 0 failed).
What was missing on the host: API + worker never ran as systemd services, and the GitHub
push webhook was never created. Also a real integration bug: assertWebhookAuth only
accepts a plain x-webhook-secret header, which GitHub does NOT send (GitHub delivers
X-Hub-Signature-256 = HMAC-SHA256 of raw body). So a real GitHub webhook would 401.
Changes
apps/api/src/index.ts—assertWebhookAuthnow verifies GitHubX-Hub-Signature-256(HMAC-SHA256 of raw body w/ WEBHOOK_SECRET) and still acceptsx-webhook-secretfor manual tests.- root
package.jsonscripts —api:bun --cwd apps/api run dev->bun --cwd apps/api src/index.ts(therun devform errors in bun 1.3.14; direct-file form verified booting + health).worker-> same form for consistency. - systemd —
cp deploy/*.service /etc/systemd/system,daemon-reload,enable --now mcpedia-api mcpedia-worker. - Caddy — expose
/hooks/*onwiki.asepharyana.my.id-> :4020 (no new DNS). Keep web on :4016. - GitHub webhook —
gh api repos/asepharyana/mcpedia/hooksPOST:https://wiki.asepharyana.my.id/hooks/reindex, content_type json, secret=WEBHOOK_SECRET, events=push.
Verification
systemctl is-active mcpedia-api mcpedia-worker== active.curl /healthon :4020 -> ok.curl -X POST https://wiki.asepharyana.my.id/hooks/reindex -H "X-Hub-Signature-256: ..."(or x-webhook-secret) -> 200 + jobId; worker drains.gh api .../hookslists the webhook.turbo run typecheckgreen; commit + push.