Overhaul deployment to Gitea Actions CI/CD, remove update.sh
Production no longer builds from source or self-updates via cron/git pull:
setup.sh now only provisions the server once (Docker, /opt/anouma, a
restricted `anouma-deploy` SSH user whose key can only ever run
deploy.sh, generated secrets). All future deployments run through
.gitea/workflows/ci.yml (lint/typecheck/test/build on every push) and
release.yml (on a vX.Y.Z tag: build the image, push it to the Gitea
registry, then SSH-trigger deploy.sh on the server), which pulls,
migrates, restarts, healthchecks, backs up the database first, and
automatically rolls back the code on a failed healthcheck.
docker-compose.yml's app service now runs a registry image
(${ANOUMA_IMAGE}) instead of building locally.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+6
-2
@@ -29,7 +29,11 @@ services:
|
||||
retries: 20
|
||||
|
||||
app:
|
||||
build: .
|
||||
# Production never builds from source — the image is built once by
|
||||
# Gitea Actions on release and pushed to the registry; this host only
|
||||
# ever pulls a specific, already-tested tag (see deploy.sh, which is the
|
||||
# only thing that ever changes ANOUMA_IMAGE in .env).
|
||||
image: ${ANOUMA_IMAGE:-git.maro.run/maro/anouma:latest}
|
||||
restart: unless-stopped
|
||||
networks:
|
||||
- anouma-network
|
||||
@@ -45,7 +49,7 @@ services:
|
||||
depends_on:
|
||||
postgres:
|
||||
condition: service_healthy
|
||||
# Container-level healthcheck is inherited from the Dockerfile's
|
||||
# Container-level healthcheck is inherited from the image's own
|
||||
# HEALTHCHECK instruction (GET /api/health, which itself checks Postgres
|
||||
# connectivity) — nothing to duplicate here.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user