Workflow (3 jobs, all on the local netork-runner on 10.7.224.11):
typecheck (ubuntu-latest)
→ npm ci + tsc --noEmit on every push/PR
publish (ubuntu-latest, main only)
→ docker build + push to registry.netork.io/netork/website:latest
and registry.netork.io/netork/website:main-<sha>
deploy (build/host, after publish)
→ runs directly on the host (no SSH needed)
→ copies docker-compose.yml to /opt/netork-website/
→ docker compose pull + up -d --remove-orphans
docker-compose.yml: replaced local build: . with
registry.netork.io/netork/website:latest so the deploy job
pulls the just-published image instead of building again.
Required Gitea secrets: REGISTRY_USER, REGISTRY_PASSWORD
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
16 lines
356 B
YAML
16 lines
356 B
YAML
services:
|
|
netork-website:
|
|
image: registry.netork.io/netork/website:latest
|
|
container_name: netork-website
|
|
restart: unless-stopped
|
|
expose:
|
|
- "80"
|
|
networks:
|
|
- proxy-net
|
|
|
|
# Zoraxy proxies to netork-website:80 via proxy-net.
|
|
# No host port binding needed — SSL terminated by Zoraxy.
|
|
networks:
|
|
proxy-net:
|
|
external: true
|