gitoriaLog in with ident

ident

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitfe183516fe183516ident mission 009 (3/4): let only where reassigned — 293 never-reassigned lets are plain declarations; kept: reassigned, loop bodies, names of a file member, a name declared twice in one function; same outputmrefe183516/deploy.sh

8.7 KB

  1. #!/usr/bin/env bash
  2. # deploy.sh — ident.worldapi.org: Loreana (this folder) → Byrodin. Run ON LOREANA.
  3. #
  4. # ./deploy.sh gates → backup → rsync → restart the container → public URL 200
  5. # ./deploy.sh --dry-run gates → rsync -n (shows what WOULD be sent), no backup, no restart, no URL check
  6. # ./deploy.sh --skip-tests skips the gates (LOUD warning) — only when you know why
  7. # ./deploy.sh --target DIR|HOST:DIR another destination (default below); a local DIR is
  8. # how the script is tested without touching Byrodin
  9. # ./deploy.sh --url URL the URL that must answer 200 after the restart
  10. # (env: DEPLOY_TARGET, DEPLOY_URL, DEPLOY_SSH override the same defaults)
  11. # (backup: tars storage/.sessions/.env that exist on the target to Loreana's
  12. # /media/SLOW1TB2/deploy-backups/<app>/, keeps newest 5; --target DIR backs up DIR instead)
  13. #
  14. # THE FIRST DEPLOY is done by the architect on Byrodin (folder, .env with SMTP, nginx vhost,
  15. # cert, DNS). This script only updates the CODE: storage/, .sessions/, .env, .scratch/,
  16. # server.*, testapp/ and logs are never sent, so live data on Byrodin is never touched.
  17. # No --delete: a file removed here stays on Byrodin (harmless — nothing imports it).
  18. set -euo pipefail
  19. # ---- the app ------------------------------------------------------------------------------
  20. APP=ident.worldapi.org
  21. CONTAINER=ident.worldapi.org
  22. [email protected]:/CONTAINERS/projects/ident.worldapi.org
  23. DEFAULT_URL=https://ident.worldapi.org/
  24. GATES=(
  25. "node tests/browser.mjs"
  26. "node tests/apps.mjs"
  27. "node tests/selector.mjs"
  28. "node tests/migration.mjs"
  29. "node tests/iplimit.mjs"
  30. "node tests/notify.mjs"
  31. )
  32. # NEVER SENT (rsync patterns; a leading / anchors at the app folder)
  33. EXCLUDES=(
  34. /.git/ /.gitignore
  35. /storage/ /.sessions/ /.env /.env.* /.scratch/ /server.* /testapp/
  36. '*.log' '*.pid' node_modules/
  37. )
  38. # ---------------------------------------------------------------------------------------------
  39. DRY=0
  40. SKIP=0
  41. TARGET=${DEPLOY_TARGET:-$DEFAULT_TARGET}
  42. URL=${DEPLOY_URL:-$DEFAULT_URL}
  43. # Loreana's ssh config may not apply to Byrodin: -F /dev/null (ident STATUS)
  44. SSH=${DEPLOY_SSH:-ssh -F /dev/null -o BatchMode=yes -o ConnectTimeout=15}
  45. usage() { sed -n '2,15p' "$0" | sed 's/^# \{0,1\}//'; }
  46. while [ $# -gt 0 ]; do
  47. case "$1" in
  48. --dry-run) DRY=1 ;;
  49. --skip-tests) SKIP=1 ;;
  50. --target) TARGET=${2:?--target needs a value}; shift ;;
  51. --target=*) TARGET=${1#--target=} ;;
  52. --url) URL=${2:?--url needs a value}; shift ;;
  53. --url=*) URL=${1#--url=} ;;
  54. -h|--help) usage; exit 0 ;;
  55. *) echo "deploy: unknown argument: $1" >&2; usage >&2; exit 2 ;;
  56. esac
  57. shift
  58. done
  59. HERE=$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)
  60. cd "$HERE"
  61. step() { printf '\n==> %s\n' "$*"; }
  62. run() { printf ' $ %s\n' "$*" >&2; "$@"; }
  63. die() { printf '\ndeploy: REFUSED — %s\n' "$*" >&2; exit 1; }
  64. # a target `host:dir` is remote, a plain path is local
  65. if [[ "$TARGET" == *:* ]]; then
  66. REMOTE_HOST=${TARGET%%:*}
  67. REMOTE_DIR=${TARGET#*:}
  68. else
  69. REMOTE_HOST=
  70. REMOTE_DIR=$TARGET
  71. fi
  72. step "[0/5] $APP → $TARGET (dry run: $DRY, skip tests: $SKIP)"
  73. echo " from $HERE"
  74. echo " url $URL"
  75. [ -x bin/hybriel ] || die "bin/hybriel is missing here"
  76. [ -f docker-compose.yml ] || die "docker-compose.yml is missing here"
  77. [ -f project.hl ] || die "project.hl is missing here"
  78. command -v rsync >/dev/null || die "rsync is not installed"
  79. # ---- 1. the gates ---------------------------------------------------------------------------
  80. if [ "$SKIP" = 1 ]; then
  81. step "[1/5] GATES SKIPPED"
  82. printf ' !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n'
  83. printf ' !! --skip-tests: NOTHING WAS TESTED. You deploy untested code. !!\n'
  84. printf ' !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n'
  85. else
  86. step "[1/5] gates (${#GATES[@]})"
  87. # headless Chromes that exist BEFORE the gates are not ours (other sessions' test runs, e.g. Anton's)
  88. chromes() { ps -eo pid=,ppid=,args= | awk '/[h]l-browser-tier/ && /remote-debugging-port/ && !/--type=/ {print $1, $2}'; }
  89. before=" $(chromes | awk '{print $1}' | tr '\n' ' ') "
  90. for g in "${GATES[@]}"; do
  91. printf ' $ %s\n' "$g"
  92. out=$(mktemp)
  93. if ! $g > "$out" 2>&1; then
  94. grep -E '^FAIL|passed,' "$out" | sed 's/^/ /' || true
  95. echo " (full output: $out)"
  96. die "gate failed: $g"
  97. fi
  98. grep -E 'passed,' "$out" | tail -1 | sed 's/^/ /'
  99. rm -f "$out"
  100. done
  101. # a Chrome our gates LEFT: new since the gates began AND no longer owned by a running node test
  102. # (a Chrome whose parent is a live node process belongs to another session's test run right now)
  103. leaked=""
  104. while read -r pid ppid; do
  105. [ -z "$pid" ] && continue
  106. case "$before" in *" $pid "*) continue ;; esac
  107. ps -o args= -p "$ppid" 2>/dev/null | grep -q '^node\|/node ' && continue
  108. leaked="$leaked $pid"
  109. done < <(chromes)
  110. if [ -n "$leaked" ]; then
  111. die "a gate left a headless Chrome (pids:$leaked; ps -eo pid,args | grep hl-browser-tier)"
  112. fi
  113. fi
  114. # ---- 2. pre-deploy backup of the LIVE data (before anything is sent) ------------------------
  115. BACKUP_ROOT=${DEPLOY_BACKUP_ROOT:-/media/SLOW1TB2/deploy-backups}
  116. BACKUP_DIR="$BACKUP_ROOT/$APP"
  117. BACKUP_FILE="$BACKUP_DIR/$APP-$(date +%Y%m%d-%H%M).tgz"
  118. if [ "$DRY" = 1 ]; then
  119. step "[2/5] DRY RUN: backup skipped"
  120. else
  121. step "[2/5] backup live data ($APP) → $BACKUP_FILE"
  122. mkdir -p "$BACKUP_DIR"
  123. if [ -n "$REMOTE_HOST" ]; then
  124. present=$($SSH "$REMOTE_HOST" "cd '$REMOTE_DIR' 2>/dev/null && for p in storage .sessions .env; do [ -e \"\$p\" ] && echo \"\$p\"; done; true")
  125. else
  126. present=$(cd "$REMOTE_DIR" 2>/dev/null && for p in storage .sessions .env; do [ -e "$p" ] && echo "$p"; done; true)
  127. fi
  128. present=$(printf '%s' "$present" | tr '\n' ' ' | sed 's/ *$//')
  129. if [ -z "$present" ]; then
  130. echo " nothing to back up yet (no storage/.sessions/.env on the target)"
  131. else
  132. echo " taring: $present"
  133. if [ -n "$REMOTE_HOST" ]; then
  134. run $SSH "$REMOTE_HOST" "tar czf - -C '$REMOTE_DIR' $present" > "$BACKUP_FILE" \
  135. || { rm -f "$BACKUP_FILE"; die "backup failed (tar/ssh error) — refusing to deploy"; }
  136. else
  137. run tar czf "$BACKUP_FILE" -C "$REMOTE_DIR" $present \
  138. || { rm -f "$BACKUP_FILE"; die "backup failed (tar error) — refusing to deploy"; }
  139. fi
  140. [ -s "$BACKUP_FILE" ] || { rm -f "$BACKUP_FILE"; die "backup is empty — refusing to deploy"; }
  141. echo " $(du -h "$BACKUP_FILE" | cut -f1) $BACKUP_FILE"
  142. ls -1t "$BACKUP_DIR/$APP"-*.tgz 2>/dev/null | tail -n +6 | xargs -r rm -f --
  143. echo " keeping $(ls -1 "$BACKUP_DIR/$APP"-*.tgz 2>/dev/null | wc -l) archive(s) of $APP"
  144. fi
  145. fi
  146. # ---- 3. rsync the code ----------------------------------------------------------------------
  147. RSYNC=(rsync -az --no-owner --no-group --itemize-changes)
  148. for e in "${EXCLUDES[@]}"; do RSYNC+=("--exclude=$e"); done
  149. if [ -n "$REMOTE_HOST" ]; then
  150. RSYNC+=(-e "$SSH")
  151. else
  152. mkdir -p "$REMOTE_DIR"
  153. fi
  154. # the preview is ALWAYS made first (rsync -n): nothing that must stay on Byrodin may be in it
  155. step "[3/5] rsync preview (what would be sent)"
  156. preview=$(mktemp)
  157. run "${RSYNC[@]}" -n ./ "$TARGET/" > "$preview"
  158. sed 's/^/ /' "$preview"
  159. echo " ($(grep -c . "$preview" || true) lines)"
  160. if awk '{print $2}' "$preview" | grep -E '^(storage/|\.sessions/|\.env|\.scratch/|server\.|testapp/)|\.log$|\.pid$' ; then
  161. die "the preview holds a path that must never be sent (see above)"
  162. fi
  163. rm -f "$preview"
  164. if [ "$DRY" = 1 ]; then
  165. step "[3/5] DRY RUN: nothing sent"
  166. else
  167. step "[3/5] rsync"
  168. run "${RSYNC[@]}" ./ "$TARGET/" | sed 's/^/ /'
  169. fi
  170. # ---- 4. restart the container ---------------------------------------------------------------
  171. RESTART="cd '$REMOTE_DIR' && docker compose up -d --build && docker compose restart && docker compose ps"
  172. if [ "$DRY" = 1 ]; then
  173. step "[4/5] DRY RUN: would restart $CONTAINER"
  174. if [ -n "$REMOTE_HOST" ]; then echo " would run: $SSH $REMOTE_HOST \"$RESTART\""; else echo " would run: bash -c \"$RESTART\""; fi
  175. else
  176. step "[4/5] restart $CONTAINER"
  177. if [ -n "$REMOTE_HOST" ]; then
  178. run $SSH "$REMOTE_HOST" "$RESTART"
  179. else
  180. run bash -c "$RESTART"
  181. fi
  182. fi
  183. # ---- 5. the URL answers 200 -----------------------------------------------------------------
  184. if [ "$DRY" = 1 ]; then
  185. step "[5/5] DRY RUN: would check $URL answers 200"
  186. step "dry run done — nothing was sent, nothing restarted"
  187. exit 0
  188. fi
  189. step "[5/5] $URL must answer 200"
  190. code=000
  191. for i in $(seq 1 20); do
  192. code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "$URL" || true)
  193. echo " try $i: $code"
  194. [ "$code" = 200 ] && break
  195. sleep 1
  196. done
  197. if [ "$code" != 200 ]; then
  198. if [ -n "$REMOTE_HOST" ]; then die "$URL answered $code, not 200 — look: $SSH $REMOTE_HOST docker logs --tail 50 $CONTAINER"; fi
  199. die "$URL answered $code, not 200 — look: docker logs --tail 50 $CONTAINER"
  200. fi
  201. step "deployed $APP → $TARGET, $URL answers 200"

Branches

Latest commits

  • fe183516ident mission 009 (3/4): let only where reassigned — 293 never-reassigned lets are plain declarations; kept: reassigned, loop bodies, names of a file member, a name declared twice in one function; same outputmre
  • d2e7f91bident mission 009 (2/4): one lib file per topic (login, accounts, identities, apps, invites, selector, notify + helpers, util), function routes as thin wrappers in lib/api.hl, project.hl = the map; same outputmre
  • 91017164ident mission 009 (1/4): file moves — the root .hl files into lib/ (api.hl → lib/api-helpers.hl), styles.hl → components/styles.hl; imports adjusted, no other changemre
  • f8bdcbc2ident: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); all gates greenmre
  • ff78726cident: Hybriel master 190aa11d (fc838894 GC correctness, #127, #126 closure scopes); gates all greenmre
  • a3a7d21aident: Hybriel master 8efba065 (#126 GC by bytes, #48 lambda params copy); session-writing lambdas take &sessionmre
  • 98226b41antcolony#40: mission references point to the moved missionsmre
  • ff805b9aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 51a7bcdfident: Hybriel master 73267707 (#122); /code uses the new page() signature; pending address passed as parameter; once-checksmre
  • 836f644fident#24: installable app (manifest, service worker, data-free offline /start), own iconmre
  • 8bebbbf2deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • cc063ea2deploy.sh: never send .git or .gitignore to Byrodinmre
  • 81b15b7bState of 2026-09-27, before the move to gitoriamre