docker:27-cli is Alpine with no Node.js, but actions/checkout@v4 is a
JS action that needs a Node runtime in the job container — it failed
at Checkout with exit 127. node:22-bookworm-slim already has Node
(same reason the test job's node:22-alpine works); Docker CLI and
openssh-client are added via apt instead.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The runner (gitea-anouma-runner) runs as a Docker container itself
(gitea/runner:3) with the host's docker.sock mounted in, but no
`docker` CLI binary. A job with no `container:` runs directly inside
that minimal runner image, so `docker login/build/push` failed with
"docker: command not found". Using docker:27-cli gives the job the
CLI; the runner mounts the same host socket into it automatically
(sibling containers), and openssh-client is installed for the deploy
step's ssh call.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This Next.js version generates LayoutProps/PageProps/RouteContext
into .next/types only via `next dev`, `next build`, or `next typegen`
(see node_modules/next/dist/docs .../06-cli/next.md). Typecheck ran
`tsc --noEmit` standalone before Build, so those globals didn't exist
yet, failing with "Cannot find name 'LayoutProps'".
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Setting it job-wide made `npm ci` treat NODE_ENV=production as an
implicit --omit=dev, silently skipping eslint/typescript/test
devDependencies and failing Lint with "eslint: not found".
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Production no longer builds from source or self-updates via cron/git pull:
setup.sh now only provisions the server once (Docker, /opt/anouma, a
restricted `anouma-deploy` SSH user whose key can only ever run
deploy.sh, generated secrets). All future deployments run through
.gitea/workflows/ci.yml (lint/typecheck/test/build on every push) and
release.yml (on a vX.Y.Z tag: build the image, push it to the Gitea
registry, then SSH-trigger deploy.sh on the server), which pulls,
migrates, restarts, healthchecks, backs up the database first, and
automatically rolls back the code on a failed healthcheck.
docker-compose.yml's app service now runs a registry image
(${ANOUMA_IMAGE}) instead of building locally.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Customer accounts now require email verification (hashed, single-use,
time-limited tokens) before they can request/confirm bookings, with
resend flows on login/account/booking widget and rate limiting.
- Admins get a private, rotatable iCalendar (ICS) subscription feed of
their confirmed bookings and public events, timezone-correct for
Europe/Berlin including DST, never exposing meeting passwords.
- Adds a full SEO layer: per-page canonical/OG/Twitter metadata with
CMS-editable overrides and content-derived fallbacks, a dynamic
sitemap.xml and robots.txt driven by real published content, JSON-LD
(Organization/LocalBusiness, WebSite, WebPage, BreadcrumbList, Service,
Event, BlogPosting) that never fabricates data, and a CMS-managed
redirect table for changed slugs.
- Global ANOUMA-naming audit: the brand name is never used to label
personal account/calendar areas anywhere in the app, CMS, or emails.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- setup.sh: interactive/non-interactive one-shot installer (build, DB
healthcheck, migrate, seed, start), idempotent secret generation, NPM
reverse-proxy network auto-detection and optional join, optional
AUTO_UPDATE cron install.
- update.sh: release-tag-gated updates only (never bare main), DB backup
with retention before every update, lock file against concurrent runs,
automatic code rollback on failed post-update healthcheck.
- Dockerfile: multi-stage build, non-root user, built-in HEALTHCHECK against
the new /api/health route, wholesale COPY so new source dirs (e.g.
scripts/) never silently go missing at runtime.
- docker-compose.yml: internal anouma-network (configurable), named volume
for Postgres, app depends_on postgres healthy, no unnecessary published
ports; docker-compose.override.yml.example documents joining an existing
NPM network without ever touching NPM itself.
- Fix host-detection: isHost was Boolean(user), wrongly granting host
privileges to logged-in customers; now checks user.collection === "users".
- Wire configurable STUN/TURN servers through to the WebRTC client
(lib/meeting/iceServers.ts) so a TURN server can be added later via env
vars only, no code changes.
- DEPLOYMENT.md, updated README.md and .env.example documenting the whole
flow: NPM integration, env vars, WebRTC, updates, backups, rollback.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>