Production no longer builds from source or self-updates via cron/git pull:
setup.sh now only provisions the server once (Docker, /opt/anouma, a
restricted `anouma-deploy` SSH user whose key can only ever run
deploy.sh, generated secrets). All future deployments run through
.gitea/workflows/ci.yml (lint/typecheck/test/build on every push) and
release.yml (on a vX.Y.Z tag: build the image, push it to the Gitea
registry, then SSH-trigger deploy.sh on the server), which pulls,
migrates, restarts, healthchecks, backs up the database first, and
automatically rolls back the code on a failed healthcheck.
docker-compose.yml's app service now runs a registry image
(${ANOUMA_IMAGE}) instead of building locally.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
26 lines
819 B
TypeScript
26 lines
819 B
TypeScript
import { NextResponse } from "next/server";
|
|
import { sql } from "drizzle-orm";
|
|
import { getPayload } from "payload";
|
|
import config from "@payload-config";
|
|
|
|
export const dynamic = "force-dynamic";
|
|
|
|
/**
|
|
* Used by the Docker healthcheck (see docker-compose.yml) and by
|
|
* setup.sh/deploy.sh to confirm the app can actually reach Postgres before
|
|
* being considered "up" — not just that the Node process is listening.
|
|
*/
|
|
export async function GET() {
|
|
try {
|
|
const payload = await getPayload({ config });
|
|
await payload.db.drizzle.execute(sql`SELECT 1`);
|
|
return NextResponse.json({ status: "ok", database: "connected" });
|
|
} catch (error) {
|
|
console.error("healthcheck failed", error);
|
|
return NextResponse.json(
|
|
{ status: "error", database: "unreachable" },
|
|
{ status: 503 },
|
|
);
|
|
}
|
|
}
|