ci: add Gitea Actions workflow + fix docker-compose for registry pull
CI / TypeScript — type-check (push) Successful in 8s
CI / Publish — build & push image (push) Successful in 7s
CI / Deploy — pull & restart on host (push) Failing after 1s

Workflow (3 jobs, all on the local netork-runner on 10.7.224.11):

  typecheck (ubuntu-latest)
    → npm ci + tsc --noEmit on every push/PR

  publish (ubuntu-latest, main only)
    → docker build + push to registry.netork.io/netork/website:latest
      and registry.netork.io/netork/website:main-<sha>

  deploy (build/host, after publish)
    → runs directly on the host (no SSH needed)
    → copies docker-compose.yml to /opt/netork-website/
    → docker compose pull + up -d --remove-orphans

docker-compose.yml: replaced local build: . with
registry.netork.io/netork/website:latest so the deploy job
pulls the just-published image instead of building again.

Required Gitea secrets: REGISTRY_USER, REGISTRY_PASSWORD

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-06-28 10:23:31 +02:00
co-authored by Claude Sonnet 4.6
parent efa01b5f41
commit 3ddf3b78b4
2 changed files with 11 additions and 18 deletions
+10 -16
View File
@@ -52,28 +52,22 @@ jobs:
deploy:
name: Deploy — pull & restart on host
runs-on: ubuntu-latest
runs-on: build
needs: [publish]
steps:
- uses: actions/checkout@v4
- name: Write SSH key
run: |
mkdir -p ~/.ssh
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
ssh-keyscan -H "${{ secrets.DEPLOY_HOST }}" >> ~/.ssh/known_hosts 2>/dev/null
- name: Login to registry
run: echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login registry.netork.io -u "${{ secrets.REGISTRY_USER }}" --password-stdin
- name: Deploy
run: |
ssh -i ~/.ssh/deploy_key -o StrictHostKeyChecking=no \
"${{ secrets.DEPLOY_USER }}@${{ secrets.DEPLOY_HOST }}" \
"cd /opt/netork-website && \
echo '${{ secrets.REGISTRY_PASSWORD }}' | docker login registry.netork.io -u '${{ secrets.REGISTRY_USER }}' --password-stdin && \
docker compose pull && \
docker compose up -d --remove-orphans && \
docker logout registry.netork.io"
mkdir -p /opt/netork-website
cp docker-compose.yml /opt/netork-website/docker-compose.yml
cd /opt/netork-website
docker compose pull
docker compose up -d --remove-orphans
- name: Clean up SSH key
- name: Logout
if: always()
run: rm -f ~/.ssh/deploy_key
run: docker logout registry.netork.io
+1 -2
View File
@@ -1,7 +1,6 @@
services:
netork-website:
build: .
image: netork-website:latest
image: registry.netork.io/netork/website:latest
container_name: netork-website
restart: unless-stopped
expose: