Overhaul deployment to Gitea Actions CI/CD, remove update.sh
Production no longer builds from source or self-updates via cron/git pull:
setup.sh now only provisions the server once (Docker, /opt/anouma, a
restricted `anouma-deploy` SSH user whose key can only ever run
deploy.sh, generated secrets). All future deployments run through
.gitea/workflows/ci.yml (lint/typecheck/test/build on every push) and
release.yml (on a vX.Y.Z tag: build the image, push it to the Gitea
registry, then SSH-trigger deploy.sh on the server), which pulls,
migrates, restarts, healthchecks, backs up the database first, and
automatically rolls back the code on a failed healthcheck.
docker-compose.yml's app service now runs a registry image
(${ANOUMA_IMAGE}) instead of building locally.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+6
-3
@@ -49,9 +49,12 @@ next-env.d.ts
|
||||
*.deb
|
||||
*.AppImage
|
||||
|
||||
# docker / deployment (machine-specific, generated by setup.sh)
|
||||
# docker / deployment (machine-specific, generated by setup.sh — production
|
||||
# artifacts actually live in /opt/anouma on the server, never inside this
|
||||
# repo checkout, but these are ignored here too in case of local testing)
|
||||
docker-compose.override.yml
|
||||
/backups
|
||||
.update.lock
|
||||
.installed-version
|
||||
.deploy.lock
|
||||
.current-version
|
||||
.deploy/
|
||||
|
||||
|
||||
Reference in New Issue
Block a user