762b226a81
Deploy / deploy (push) Failing after 2m45s
The runner shares the host's Docker daemon across every repo's CI jobs, so a hardcoded host port (8080) is a shared resource, not scoped to this job — that's what was actually colliding, not a leftover vu-smoke container (the previous fix's cleanup didn't help because the conflicting container wasn't named vu-smoke at all). Curl the container's own bridge IP instead, so nothing is published to the host and there's nothing to contend over. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
58 lines
2.0 KiB
YAML
58 lines
2.0 KiB
YAML
name: Deploy
|
|
on:
|
|
push:
|
|
branches: [master]
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "26"
|
|
|
|
- name: Install
|
|
run: npm ci
|
|
|
|
- name: Build
|
|
run: npm run build
|
|
|
|
- name: Test
|
|
run: npm test
|
|
|
|
- name: Build and smoke-test the container
|
|
# vu has no server-side logic, so there's nothing an integration
|
|
# test would exercise beyond "does the built bundle actually get
|
|
# served correctly under the /vu/ base path" — this is that check,
|
|
# run against the exact image that ships.
|
|
#
|
|
# The runner shares the host's Docker daemon, so a hardcoded host
|
|
# port (this used to be -p 8080:80) is contended across every repo's
|
|
# CI on the same host, not scoped to this job — hence the previous
|
|
# "port already allocated" failures even after cleaning up any
|
|
# leftover vu-smoke container. Curl the container's own bridge IP
|
|
# instead, so no host port is published at all.
|
|
run: |
|
|
docker rm -f vu-smoke 2>/dev/null || true
|
|
docker build -t vu:ci .
|
|
docker run -d --name vu-smoke vu:ci
|
|
sleep 1
|
|
container_ip=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' vu-smoke)
|
|
curl -sf "http://${container_ip}/" | grep -q 'vu — Divine Office'
|
|
docker stop vu-smoke
|
|
docker rm vu-smoke
|
|
|
|
- name: Trigger redeploy via SSH
|
|
run: |
|
|
mkdir -p ~/.ssh
|
|
printf '%s\n' "$VU_DEPLOY_SSH_KEY" > ~/.ssh/deploy_key
|
|
chmod 600 ~/.ssh/deploy_key
|
|
# Forced-command key, same pattern as eec/bookshop/drip: the
|
|
# server-side sudoers grant runs the vu redeploy script regardless
|
|
# of what's requested here — see the vu Ansible role.
|
|
ssh -i ~/.ssh/deploy_key -o StrictHostKeyChecking=accept-new vu-deploy@reground.org true
|
|
env:
|
|
VU_DEPLOY_SSH_KEY: ${{ secrets.VU_DEPLOY_SSH_KEY }}
|