Files
dedinit.ru/openspec/changes/auto-deploy-dedinit-actions/design.md
T

104 lines
3.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Design: Автодеплой dedinit.ru через Gitea Actions
## Архитектура
```
[пользователь/агент]
│ git push (main) в gitverse.ru (источник истины)
▼
[gitverse.ru] kpa39l/dedinit.ru
│ крон-скрипт: git fetch gitverse && git push gitea (каждые ~10 мин)
▼
[gitea.nixg.ru] estorozhenko/dedinit.ru ← НЕ mirror, Actions включены
│ push в main → Gitea Actions
▼
[bigbox-runner] (gitea-act-runner v3.3.1, label docker27-bash)
│ job-контейнер docker27-bash: checkout → make build → tools/deploy_sftp.py
▼
[kpa39l.myjino.ru:2222:/dedinit.ru/] (SFTP-only, пароль из secrets.SSHPASS)
```
## Шаги
### 1. Снять mirror-статус у Gitea-репозитория
Раньше репо было pull-mirror (интервал 8ч) с gitverse.ru. На mirror-репо Gitea
отключает Actions. Снимаем:
```bash
curl -X PATCH "https://gitea.nixg.ru/api/v1/repos/estorozhenko/dedinit.ru" \
-H "Authorization: token $GITEA_NIXG_TOKEN" \
-H "Content-Type: application/json" \
-d '{"mirror": false}'
```
Проверка: `GET /repos/estorozhenko/dedinit.ru` → `"mirror":false`, `"has_actions":true`.
### 2. Синхронизация gitverse → gitea крон-скриптом
Создать `/opt/gitea.nixg.ru/sync-dedinit.sh`:
```bash
#!/usr/bin/env bash
set -euo pipefail
cd /opt/dedinit.ru
git fetch gitverse main || git fetch origin main # gitverse = источник истины
# аккуратно: приносим refs/heads/main gitverse → gitea
git push gitea main:main
```
(детали remote gitea — см. ниже) + cron на bigbox каждые 10 минут.
### 3. Workflow `.gitea/workflows/deploy.yml`
```yaml
name: deploy
on:
push:
branches: [main]
jobs:
deploy:
runs-on: [ubuntu-24.04] # label раннера bigbox-runner
steps:
- uses: actions/checkout@v4
- name: install hugo
run: |
curl -sL https://api.github.com/repos/gohugoio/hugo/releases/latest \
| grep -oE 'browser_download_url.*_extended.*linux-amd64.tar.gz' | head -1
# распаковать hugo в /usr/local/bin
- name: build
run: make build
- name: deploy
env:
SSHPASS: ${{ secrets.SSHPASS }}
run: make deploy
```
### 4. Секрет в Gitea
```bash
curl -X PUT "https://gitea.nixg.ru/api/v1/repos/estorozhenko/dedinit.ru/actions/secrets/SSHPASS" \
-H "Authorization: token $GITEA_NIXG_TOKEN" \
-d '{"value": "-Zp4ep747t25"}'
```
## Файлы
- `.gitea/workflows/deploy.yml` — новый
- `tools/deploy_sftp.py`, `Makefile` — переиспользуются без изменений
- `/opt/gitea.nixg.ru/sync-dedinit.sh` (+ cron) — новый
- Для SSH-доступа к gitea: remote `gitea` = `git@gitverse` нет; проверю, есть ли SSH/HTTPS-доступ к gitea.nixg.ru, или поднимем родной remote через https+token.
## Команды верификации
- `curl -s https://gitea.nixg.ru/api/v1/repos/estorozhenko/dedinit.ru | grep '"has_actions"'` → true
- `openspec validate auto-deploy-dedinit-actions` → valid
- После пуша: `curl -s https://gitea.nixg.ru/api/v1/repos/estorozhenko/dedinit.ru/actions/runs | ...` → run существует
- `curl -s -o /dev/null -w '%{http_code}' https://dedinit.ru/` → 200
## Rollback
1. Вернуть mirror: `PATCH /repos/estorozhenko/dedinit.ru` → `{"mirror": true}`
2. Убрать workflow: `git rm .gitea/workflows/deploy.yml` + push
3. Удалить секрет: `DELETE /repos/estorozhenko/dedinit.ru/actions/secrets/SSHPASS`
4. Остановить крон-скрипт синхронизации