Workflow (3 jobs, all on the local netork-runner on 10.7.224.11):
typecheck (ubuntu-latest)
→ npm ci + tsc --noEmit on every push/PR
publish (ubuntu-latest, main only)
→ docker build + push to registry.netork.io/netork/website:latest
and registry.netork.io/netork/website:main-<sha>
deploy (build/host, after publish)
→ runs directly on the host (no SSH needed)
→ copies docker-compose.yml to /opt/netork-website/
→ docker compose pull + up -d --remove-orphans
docker-compose.yml: replaced local build: . with
registry.netork.io/netork/website:latest so the deploy job
pulls the just-published image instead of building again.
Required Gitea secrets: REGISTRY_USER, REGISTRY_PASSWORD
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
74 lines
1.9 KiB
YAML
74 lines
1.9 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: ['**']
|
|
tags: ['v*']
|
|
pull_request:
|
|
branches: ['**']
|
|
|
|
jobs:
|
|
typecheck:
|
|
name: TypeScript — type-check
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '20'
|
|
cache: 'npm'
|
|
|
|
- name: Install
|
|
run: npm ci
|
|
|
|
- name: Type-check (tsc)
|
|
run: npx tsc --noEmit
|
|
|
|
publish:
|
|
name: Publish — build & push image
|
|
runs-on: ubuntu-latest
|
|
needs: [typecheck]
|
|
if: github.ref == 'refs/heads/main' && github.event_name == 'push'
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Login to registry
|
|
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.netork.io -u "${{ secrets.REGISTRY_USER }}" --password-stdin
|
|
|
|
- name: Build & push
|
|
run: |
|
|
SHA=$(git rev-parse --short HEAD)
|
|
docker build \
|
|
-t registry.netork.io/netork/website:latest \
|
|
-t registry.netork.io/netork/website:main-${SHA} \
|
|
.
|
|
docker push registry.netork.io/netork/website:latest
|
|
docker push registry.netork.io/netork/website:main-${SHA}
|
|
|
|
- name: Logout
|
|
if: always()
|
|
run: docker logout registry.netork.io
|
|
|
|
deploy:
|
|
name: Deploy — pull & restart on host
|
|
runs-on: build
|
|
needs: [publish]
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Login to registry
|
|
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.netork.io -u "${{ secrets.REGISTRY_USER }}" --password-stdin
|
|
|
|
- name: Deploy
|
|
run: |
|
|
mkdir -p /opt/netork-website
|
|
cp docker-compose.yml /opt/netork-website/docker-compose.yml
|
|
cd /opt/netork-website
|
|
docker compose pull
|
|
docker compose up -d --remove-orphans
|
|
|
|
- name: Logout
|
|
if: always()
|
|
run: docker logout registry.netork.io
|