gitoria
All repositories: gitoria
8.5 KB
#!/usr/bin/env bash# deploy.sh — gitoria.worldapi.org: Loreana (this folder) → Byrodin. Run ON LOREANA.## ./deploy.sh gates → backup → rsync → restart the container → public URL 200# ./deploy.sh --dry-run gates → rsync -n (shows what WOULD be sent), no backup, no restart, no URL check# ./deploy.sh --skip-tests skips the gates (LOUD warning) — only when you know why# ./deploy.sh --target DIR|HOST:DIR another destination (default below); a local DIR is# how the script is tested without touching Byrodin# ./deploy.sh --url URL the URL that must answer 200 after the restart# (env: DEPLOY_TARGET, DEPLOY_URL, DEPLOY_SSH override the same defaults)# (backup: tars storage/.sessions/.env that exist on the target to Loreana's# /media/SLOW1TB2/deploy-backups/<app>/, keeps newest 5; --target DIR backs up DIR instead)## THE FIRST DEPLOY is done by the architect on Byrodin (folder, data, nginx vhost, cert,# DNS). This script only updates the CODE: storage/, .sessions/, .env, .scratch/, server.*,# testapp/ and logs are never sent, so live data on Byrodin is never touched.# No --delete: a file removed here stays on Byrodin (harmless — nothing imports it).set -euo pipefail# ---- the app ------------------------------------------------------------------------------APP=gitoria.worldapi.orgCONTAINER=gitoria.worldapi.org[email protected]:/CONTAINERS/projects/gitoria.worldapi.orgDEFAULT_URL=https://gitoria.worldapi.org/GATES=("node tests/browser.mjs")# NEVER SENT (rsync patterns; a leading / anchors at the app folder)EXCLUDES=(/.git/ /.gitignore/storage/ /.sessions/ /.env /.env.* /.scratch/ /server.* /testapp/'*.log' '*.pid' node_modules/)# ---------------------------------------------------------------------------------------------DRY=0SKIP=0TARGET=${DEPLOY_TARGET:-$DEFAULT_TARGET}URL=${DEPLOY_URL:-$DEFAULT_URL}# Loreana's ssh config may not apply to Byrodin: -F /dev/null (ident STATUS)SSH=${DEPLOY_SSH:-ssh -F /dev/null -o BatchMode=yes -o ConnectTimeout=15}usage() { sed -n '2,15p' "$0" | sed 's/^# \{0,1\}//'; }while [ $# -gt 0 ]; docase "$1" in--dry-run) DRY=1 ;;--skip-tests) SKIP=1 ;;--target) TARGET=${2:?--target needs a value}; shift ;;--target=*) TARGET=${1#--target=} ;;--url) URL=${2:?--url needs a value}; shift ;;--url=*) URL=${1#--url=} ;;-h|--help) usage; exit 0 ;;*) echo "deploy: unknown argument: $1" >&2; usage >&2; exit 2 ;;esacshiftdoneHERE=$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)cd "$HERE"step() { printf '\n==> %s\n' "$*"; }run() { printf ' $ %s\n' "$*" >&2; "$@"; }die() { printf '\ndeploy: REFUSED — %s\n' "$*" >&2; exit 1; }# a target `host:dir` is remote, a plain path is localif [[ "$TARGET" == *:* ]]; thenREMOTE_HOST=${TARGET%%:*}REMOTE_DIR=${TARGET#*:}elseREMOTE_HOST=REMOTE_DIR=$TARGETfistep "[0/5] $APP → $TARGET (dry run: $DRY, skip tests: $SKIP)"echo " from $HERE"echo " url $URL"[ -x bin/hybriel ] || die "bin/hybriel is missing here"[ -f docker-compose.yml ] || die "docker-compose.yml is missing here"[ -f project.hl ] || die "project.hl is missing here"command -v rsync >/dev/null || die "rsync is not installed"# ---- 1. the gates ---------------------------------------------------------------------------if [ "$SKIP" = 1 ]; thenstep "[1/5] GATES SKIPPED"printf ' !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n'printf ' !! --skip-tests: NOTHING WAS TESTED. You deploy untested code. !!\n'printf ' !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n'elsestep "[1/5] gates (${#GATES[@]})"# headless Chromes that exist BEFORE the gates are not ours (other sessions' test runs, e.g. Anton's)chromes() { ps -eo pid=,ppid=,args= | awk '/[h]l-browser-tier/ && /remote-debugging-port/ && !/--type=/ {print $1, $2}'; }before=" $(chromes | awk '{print $1}' | tr '\n' ' ') "for g in "${GATES[@]}"; doprintf ' $ %s\n' "$g"out=$(mktemp)if ! $g > "$out" 2>&1; thengrep -E '^FAIL|passed,' "$out" | sed 's/^/ /' || trueecho " (full output: $out)"die "gate failed: $g"figrep -E 'passed,' "$out" | tail -1 | sed 's/^/ /'rm -f "$out"done# a Chrome our gates LEFT: new since the gates began AND no longer owned by a running node test# (a Chrome whose parent is a live node process belongs to another session's test run right now)leaked=""while read -r pid ppid; do[ -z "$pid" ] && continuecase "$before" in *" $pid "*) continue ;; esacps -o args= -p "$ppid" 2>/dev/null | grep -q '^node\|/node ' && continueleaked="$leaked $pid"done < <(chromes)if [ -n "$leaked" ]; thendie "a gate left a headless Chrome (pids:$leaked; ps -eo pid,args | grep hl-browser-tier)"fifi# ---- 2. pre-deploy backup of the LIVE data (before anything is sent) ------------------------BACKUP_ROOT=${DEPLOY_BACKUP_ROOT:-/media/SLOW1TB2/deploy-backups}BACKUP_DIR="$BACKUP_ROOT/$APP"BACKUP_FILE="$BACKUP_DIR/$APP-$(date +%Y%m%d-%H%M).tgz"if [ "$DRY" = 1 ]; thenstep "[2/5] DRY RUN: backup skipped"elsestep "[2/5] backup live data ($APP) → $BACKUP_FILE"mkdir -p "$BACKUP_DIR"if [ -n "$REMOTE_HOST" ]; thenpresent=$($SSH "$REMOTE_HOST" "cd '$REMOTE_DIR' 2>/dev/null && for p in storage .sessions .env; do [ -e \"\$p\" ] && echo \"\$p\"; done; true")elsepresent=$(cd "$REMOTE_DIR" 2>/dev/null && for p in storage .sessions .env; do [ -e "$p" ] && echo "$p"; done; true)fipresent=$(printf '%s' "$present" | tr '\n' ' ' | sed 's/ *$//')if [ -z "$present" ]; thenecho " nothing to back up yet (no storage/.sessions/.env on the target)"elseecho " taring: $present"if [ -n "$REMOTE_HOST" ]; thenrun $SSH "$REMOTE_HOST" "tar czf - -C '$REMOTE_DIR' $present" > "$BACKUP_FILE" \|| { rm -f "$BACKUP_FILE"; die "backup failed (tar/ssh error) — refusing to deploy"; }elserun tar czf "$BACKUP_FILE" -C "$REMOTE_DIR" $present \|| { rm -f "$BACKUP_FILE"; die "backup failed (tar error) — refusing to deploy"; }fi[ -s "$BACKUP_FILE" ] || { rm -f "$BACKUP_FILE"; die "backup is empty — refusing to deploy"; }echo " $(du -h "$BACKUP_FILE" | cut -f1) $BACKUP_FILE"ls -1t "$BACKUP_DIR/$APP"-*.tgz 2>/dev/null | tail -n +6 | xargs -r rm -f --echo " keeping $(ls -1 "$BACKUP_DIR/$APP"-*.tgz 2>/dev/null | wc -l) archive(s) of $APP"fifi# ---- 3. rsync the code ----------------------------------------------------------------------RSYNC=(rsync -az --no-owner --no-group --itemize-changes)for e in "${EXCLUDES[@]}"; do RSYNC+=("--exclude=$e"); doneif [ -n "$REMOTE_HOST" ]; thenRSYNC+=(-e "$SSH")elsemkdir -p "$REMOTE_DIR"fi# the preview is ALWAYS made first (rsync -n): nothing that must stay on Byrodin may be in itstep "[3/5] rsync preview (what would be sent)"preview=$(mktemp)run "${RSYNC[@]}" -n ./ "$TARGET/" > "$preview"sed 's/^/ /' "$preview"echo " ($(grep -c . "$preview" || true) lines)"if awk '{print $2}' "$preview" | grep -E '^(storage/|\.sessions/|\.env|\.scratch/|server\.|testapp/)|\.log$|\.pid$' ; thendie "the preview holds a path that must never be sent (see above)"firm -f "$preview"if [ "$DRY" = 1 ]; thenstep "[3/5] DRY RUN: nothing sent"elsestep "[3/5] rsync"run "${RSYNC[@]}" ./ "$TARGET/" | sed 's/^/ /'fi# ---- 4. restart the container ---------------------------------------------------------------RESTART="cd '$REMOTE_DIR' && docker compose up -d --build && docker compose restart && docker compose ps"if [ "$DRY" = 1 ]; thenstep "[4/5] DRY RUN: would restart $CONTAINER"if [ -n "$REMOTE_HOST" ]; then echo " would run: $SSH $REMOTE_HOST \"$RESTART\""; else echo " would run: bash -c \"$RESTART\""; fielsestep "[4/5] restart $CONTAINER"if [ -n "$REMOTE_HOST" ]; thenrun $SSH "$REMOTE_HOST" "$RESTART"elserun bash -c "$RESTART"fifi# ---- 5. the URL answers 200 -----------------------------------------------------------------if [ "$DRY" = 1 ]; thenstep "[5/5] DRY RUN: would check $URL answers 200"step "dry run done — nothing was sent, nothing restarted"exit 0fistep "[5/5] $URL must answer 200"code=000for i in $(seq 1 20); docode=$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "$URL" || true)echo " try $i: $code"[ "$code" = 200 ] && breaksleep 1doneif [ "$code" != 200 ]; thenif [ -n "$REMOTE_HOST" ]; then die "$URL answered $code, not 200 — look: $SSH $REMOTE_HOST docker logs --tail 50 $CONTAINER"; fidie "$URL answered $code, not 200 — look: docker logs --tail 50 $CONTAINER"fistep "deployed $APP → $TARGET, $URL answers 200"
Branches
- mainmain branch
Latest commits
- 4f47843egate: ticket links use the tickets short URL (/<slug>/<n>, tickets#25)mre
- 86605446mission 002 (code order) 4/4: README file map + import order + 'Same output' test + gate run with a tickets HEAD copy, STATUS (entry, lessons), LOG, report; tests/realdata-baseline.mjs + realdata-compare.py (a cleanup answers the same on live data: pages, modules, API, git over HTTPS and SSH, faces), tests/letcount.pymre
- cc7bf7bamission 002 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (289 lets → plain declarations; 213 left: 125 reassigned, 88 loop-bound; no member/import/param clash). gates 200/0, 46/0, 44/0; real-data reads + writes identical (browser modules: var → const only)mre
- 090a20c6mission 002 (code order) 2/4: one lib/ file per topic — git.hl split into git (calls, branches, init, temp folder) / homepage / code / pulls / releases (+ git-helpers: paths, ids, |||PR/|||RL markers); repos-helpers, tickets-helpers, transport-helpers; util.hl = localtime + env, storage dir, addresses, lists, text checks, one newest-first sort (was 3 copies); the function routes out of project.hl into lib/api.hl (thin; plumbing in api-helpers.hl), sshgate.hl folded into api.hl + sshkeys.hl keyLine + repos.hl mayPush; 'Make main' and the merge answer out of the faces (code.hl makeMain, pulls.hl pullsView), one login helper (users.hl userOfLoginCode); project.hl is the map. Session-writing routes get &req + &server.sessions. gates 200/0, 46/0, 44/0; real-data identical except /login/failed now shows the parked reason for a browser that already had a session (the old copy-of-req lost it)mre
- 110c2799mission 002 (code order) 1/4: .hl files out of the root — lib/ (api, git, localtime, markdown, repos, sshgate, sshkeys, tickets, tokens, transport, users), components/styles.hl; jsoncheck.hl removed (imported nowhere); import paths only. gates 200/0, 46/0, 44/0; real-data reads + writes identicalmre
- fdfb4b1bgitoria: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 200/0, 46/0, 44/0mre
- 5b46ac84antcolony#40: LOG.md — missions 069/072 are antcolony missions (report paths on Byrodin)mre
- 5602ff41gitoria: Hybriel master 190aa11d (fc838894 GC correctness, #127 mountKids by reference, #126, #48) — tracker README flat; gates 200/0, 46/0, 44/0mre
- e85eaf01gitoria: 069 round 2 — hybriel 1a096ad3 not adopted (Markdown SSR still grows); browser gate waits for the server-side logout before restartmre
- 09ce4f3fgitoria: mission 069 re-vendor hybriel 8efba065 stopped (big SSR pages grow + slow down); lambda audit clean; old vendor keptmre
- 3dc43108antcolony#40: mission references point to the moved missionsmre
- 8d9450fdantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
- 205d5fe4gitoria: Hybriel master ff51cf46; ssh keys/tokens no double rows (session sync); gates follow #20mre
- 9b27cb26gitoria#21: installable app (manifest, service worker, offline start page), own iconmre
- 68dcb603deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
- e2deed6dgitoria#20: "Add code" only on the Code page of an empty repository, no collapsiblemre
- 8bb97ffddeploy.sh: never send .git or .gitignore to Byrodinmre
- fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
- 4a2d7125initial commitmre