gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit20e09d8920e09d89Merge t18 (tracker#18 delta sync) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs, both sides kept; pageShowOf summary = summaryOfmre20e09d89/deploy.sh

8.5 KB

  1. #!/usr/bin/env bash
  2. # deploy.sh — tracker.worldapi.org: Loreana (this folder) → Byrodin. Run ON LOREANA.
  3. #
  4. # ./deploy.sh gates → backup → rsync → restart the container → public URL 200
  5. # ./deploy.sh --dry-run gates → rsync -n (shows what WOULD be sent), no backup, no restart, no URL check
  6. # ./deploy.sh --skip-tests skips the gates (LOUD warning) — only when you know why
  7. # ./deploy.sh --target DIR|HOST:DIR another destination (default below); a local DIR is
  8. # how the script is tested without touching Byrodin
  9. # ./deploy.sh --url URL the URL that must answer 200 after the restart
  10. # (env: DEPLOY_TARGET, DEPLOY_URL, DEPLOY_SSH override the same defaults)
  11. # (backup: tars storage/.sessions/.env that exist on the target to Loreana's
  12. # /media/SLOW1TB2/deploy-backups/<app>/, keeps newest 5; --target DIR backs up DIR instead)
  13. #
  14. # THE FIRST DEPLOY is done by the architect on Byrodin (folder, .env with this app's ident
  15. # API key + secret — registered once in ident's /apps for origin https://tracker.worldapi.org
  16. # — nginx vhost, cert, DNS). This script only updates the CODE: storage/, .sessions/, .env,
  17. # .scratch/, server.*, tests/ fixtures and logs are never sent, so live data on Byrodin is
  18. # never touched. No --delete: a file removed here stays on Byrodin (harmless).
  19. set -euo pipefail
  20. # ---- the app ------------------------------------------------------------------------------
  21. APP=tracker.worldapi.org
  22. CONTAINER=tracker.worldapi.org
  23. [email protected]:/CONTAINERS/projects/tracker.worldapi.org
  24. DEFAULT_URL=https://tracker.worldapi.org/
  25. GATES=(
  26. "node tests/browser.mjs"
  27. )
  28. # NEVER SENT (rsync patterns; a leading / anchors at the app folder)
  29. EXCLUDES=(
  30. /.git/ /.gitignore
  31. /storage/ /.sessions/ /.env /.env.* /.scratch/ /server.* '*.log' '*.pid' node_modules/
  32. )
  33. # ---------------------------------------------------------------------------------------------
  34. DRY=0
  35. SKIP=0
  36. TARGET=${DEPLOY_TARGET:-$DEFAULT_TARGET}
  37. URL=${DEPLOY_URL:-$DEFAULT_URL}
  38. # Loreana's ssh config may not apply to Byrodin: -F /dev/null (ident STATUS)
  39. SSH=${DEPLOY_SSH:-ssh -F /dev/null -o BatchMode=yes -o ConnectTimeout=15}
  40. usage() { sed -n '2,15p' "$0" | sed 's/^# \{0,1\}//'; }
  41. while [ $# -gt 0 ]; do
  42. case "$1" in
  43. --dry-run) DRY=1 ;;
  44. --skip-tests) SKIP=1 ;;
  45. --target) TARGET=${2:?--target needs a value}; shift ;;
  46. --target=*) TARGET=${1#--target=} ;;
  47. --url) URL=${2:?--url needs a value}; shift ;;
  48. --url=*) URL=${1#--url=} ;;
  49. -h|--help) usage; exit 0 ;;
  50. *) echo "deploy: unknown argument: $1" >&2; usage >&2; exit 2 ;;
  51. esac
  52. shift
  53. done
  54. HERE=$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)
  55. cd "$HERE"
  56. step() { printf '\n==> %s\n' "$*"; }
  57. run() { printf ' $ %s\n' "$*" >&2; "$@"; }
  58. die() { printf '\ndeploy: REFUSED — %s\n' "$*" >&2; exit 1; }
  59. # a target `host:dir` is remote, a plain path is local
  60. if [[ "$TARGET" == *:* ]]; then
  61. REMOTE_HOST=${TARGET%%:*}
  62. REMOTE_DIR=${TARGET#*:}
  63. else
  64. REMOTE_HOST=
  65. REMOTE_DIR=$TARGET
  66. fi
  67. step "[0/5] $APP → $TARGET (dry run: $DRY, skip tests: $SKIP)"
  68. echo " from $HERE"
  69. echo " url $URL"
  70. [ -x bin/hybriel ] || die "bin/hybriel is missing here"
  71. [ -f docker-compose.yml ] || die "docker-compose.yml is missing here"
  72. [ -f project.hl ] || die "project.hl is missing here"
  73. command -v rsync >/dev/null || die "rsync is not installed"
  74. # ---- 1. the gates ---------------------------------------------------------------------------
  75. if [ "$SKIP" = 1 ]; then
  76. step "[1/5] GATES SKIPPED"
  77. printf ' !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n'
  78. printf ' !! --skip-tests: NOTHING WAS TESTED. You deploy untested code. !!\n'
  79. printf ' !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n'
  80. else
  81. step "[1/5] gates (${#GATES[@]})"
  82. # headless Chromes that exist BEFORE the gates are not ours (other sessions' test runs)
  83. chromes() { ps -eo pid=,ppid=,args= | awk '/[h]l-browser-tier/ && /remote-debugging-port/ && !/--type=/ {print $1, $2}'; }
  84. before=" $(chromes | awk '{print $1}' | tr '\n' ' ') "
  85. for g in "${GATES[@]}"; do
  86. printf ' $ %s\n' "$g"
  87. out=$(mktemp)
  88. if ! $g > "$out" 2>&1; then
  89. grep -E '^FAIL|passed,' "$out" | sed 's/^/ /' || true
  90. echo " (full output: $out)"
  91. die "gate failed: $g"
  92. fi
  93. grep -E 'passed,' "$out" | tail -1 | sed 's/^/ /'
  94. rm -f "$out"
  95. done
  96. # a Chrome our gates LEFT: new since the gates began AND no longer owned by a running node test
  97. leaked=""
  98. while read -r pid ppid; do
  99. [ -z "$pid" ] && continue
  100. case "$before" in *" $pid "*) continue ;; esac
  101. ps -o args= -p "$ppid" 2>/dev/null | grep -q '^node\|/node ' && continue
  102. leaked="$leaked $pid"
  103. done < <(chromes)
  104. if [ -n "$leaked" ]; then
  105. die "a gate left a headless Chrome (pids:$leaked; ps -eo pid,args | grep hl-browser-tier)"
  106. fi
  107. fi
  108. # ---- 2. pre-deploy backup of the LIVE data (before anything is sent) ------------------------
  109. BACKUP_ROOT=${DEPLOY_BACKUP_ROOT:-/media/SLOW1TB2/deploy-backups}
  110. BACKUP_DIR="$BACKUP_ROOT/$APP"
  111. BACKUP_FILE="$BACKUP_DIR/$APP-$(date +%Y%m%d-%H%M).tgz"
  112. if [ "$DRY" = 1 ]; then
  113. step "[2/5] DRY RUN: backup skipped"
  114. else
  115. step "[2/5] backup live data ($APP) → $BACKUP_FILE"
  116. mkdir -p "$BACKUP_DIR"
  117. if [ -n "$REMOTE_HOST" ]; then
  118. present=$($SSH "$REMOTE_HOST" "cd '$REMOTE_DIR' 2>/dev/null && for p in storage .sessions .env; do [ -e \"\$p\" ] && echo \"\$p\"; done; true")
  119. else
  120. present=$(cd "$REMOTE_DIR" 2>/dev/null && for p in storage .sessions .env; do [ -e "$p" ] && echo "$p"; done; true)
  121. fi
  122. present=$(printf '%s' "$present" | tr '\n' ' ' | sed 's/ *$//')
  123. if [ -z "$present" ]; then
  124. echo " nothing to back up yet (no storage/.sessions/.env on the target)"
  125. else
  126. echo " taring: $present"
  127. if [ -n "$REMOTE_HOST" ]; then
  128. run $SSH "$REMOTE_HOST" "tar czf - -C '$REMOTE_DIR' $present" > "$BACKUP_FILE" \
  129. || { rm -f "$BACKUP_FILE"; die "backup failed (tar/ssh error) — refusing to deploy"; }
  130. else
  131. run tar czf "$BACKUP_FILE" -C "$REMOTE_DIR" $present \
  132. || { rm -f "$BACKUP_FILE"; die "backup failed (tar error) — refusing to deploy"; }
  133. fi
  134. [ -s "$BACKUP_FILE" ] || { rm -f "$BACKUP_FILE"; die "backup is empty — refusing to deploy"; }
  135. echo " $(du -h "$BACKUP_FILE" | cut -f1) $BACKUP_FILE"
  136. ls -1t "$BACKUP_DIR/$APP"-*.tgz 2>/dev/null | tail -n +6 | xargs -r rm -f --
  137. echo " keeping $(ls -1 "$BACKUP_DIR/$APP"-*.tgz 2>/dev/null | wc -l) archive(s) of $APP"
  138. fi
  139. fi
  140. # ---- 3. rsync the code ----------------------------------------------------------------------
  141. RSYNC=(rsync -az --no-owner --no-group --itemize-changes)
  142. for e in "${EXCLUDES[@]}"; do RSYNC+=("--exclude=$e"); done
  143. if [ -n "$REMOTE_HOST" ]; then
  144. RSYNC+=(-e "$SSH")
  145. else
  146. mkdir -p "$REMOTE_DIR"
  147. fi
  148. # the preview is ALWAYS made first (rsync -n): nothing that must stay on Byrodin may be in it
  149. step "[3/5] rsync preview (what would be sent)"
  150. preview=$(mktemp)
  151. run "${RSYNC[@]}" -n ./ "$TARGET/" > "$preview"
  152. sed 's/^/ /' "$preview"
  153. echo " ($(grep -c . "$preview" || true) lines)"
  154. if awk '{print $2}' "$preview" | grep -E '^(storage/|\.sessions/|\.env|\.scratch/|server\.)|\.log$|\.pid$' ; then
  155. die "the preview holds a path that must never be sent (see above)"
  156. fi
  157. rm -f "$preview"
  158. if [ "$DRY" = 1 ]; then
  159. step "[3/5] DRY RUN: nothing sent"
  160. else
  161. step "[3/5] rsync"
  162. run "${RSYNC[@]}" ./ "$TARGET/" | sed 's/^/ /'
  163. fi
  164. # ---- 4. restart the container ---------------------------------------------------------------
  165. RESTART="cd '$REMOTE_DIR' && docker compose up -d --build && docker compose restart && docker compose ps"
  166. if [ "$DRY" = 1 ]; then
  167. step "[4/5] DRY RUN: would restart $CONTAINER"
  168. if [ -n "$REMOTE_HOST" ]; then echo " would run: $SSH $REMOTE_HOST \"$RESTART\""; else echo " would run: bash -c \"$RESTART\""; fi
  169. else
  170. step "[4/5] restart $CONTAINER"
  171. if [ -n "$REMOTE_HOST" ]; then
  172. run $SSH "$REMOTE_HOST" "$RESTART"
  173. else
  174. run bash -c "$RESTART"
  175. fi
  176. fi
  177. # ---- 5. the URL answers 200 -----------------------------------------------------------------
  178. if [ "$DRY" = 1 ]; then
  179. step "[5/5] DRY RUN: would check $URL answers 200"
  180. step "dry run done — nothing was sent, nothing restarted"
  181. exit 0
  182. fi
  183. step "[5/5] $URL must answer 200"
  184. code=000
  185. for i in $(seq 1 20); do
  186. code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "$URL" || true)
  187. echo " try $i: $code"
  188. [ "$code" = 200 ] && break
  189. sleep 1
  190. done
  191. if [ "$code" != 200 ]; then
  192. if [ -n "$REMOTE_HOST" ]; then die "$URL answered $code, not 200 — look: $SSH $REMOTE_HOST docker logs --tail 50 $CONTAINER"; fi
  193. die "$URL answered $code, not 200 — look: docker logs --tail 50 $CONTAINER"
  194. fi
  195. step "deployed $APP → $TARGET, $URL answers 200"

Branches

Latest commits

  • 20e09d89Merge t18 (tracker#18 delta sync) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs, both sides kept; pageShowOf summary = summaryOfmre
  • f83571c3tracker#18 (mission 067): daily sync by change lists — TMDB /tv|movie/changes (since the stored day, paged) + TVmaze /updates/shows → only our changed titles (followed: full step, unfollowed: light step — changed seasons, no TVmaze), full walk on first run / gap > 14 days / failed list; show record refreshed (title, tmdbSummary, tagline, status, genres …; renamed titles re-indexed); summary = the creator's own text (page: summary > tmdbSummary > tvmazeSummary), one-time clear of copied summaries (9,647 on the live copy); gate 261, tests/realdata-018*.mjs, README + STATUSmre
  • f2b00674Merge t26 (tracker#26 + #28) into main (mission 062): short ids for every new person (castPersonId, guest route), guest stars stored on the title and created as people only when opened (/person/tmdb/<id>?show=<id> → 302), lean watch/follow clicks (showRow a small object, cast/crew from the slug, watches cached per user, face rows only after a season toggle); gate 311, tests/realdata-062.mjs, README + STATUSmre
  • fa1f9dfatracker#29 (mission 063): unwatched check muted grey outline + check (accent only on hover), watched stays solid — no code regression, the accent outline read as ticked; gate checks real checks visibly (computed style + screenshot pixel) on /my/unwatched, show, movie, /my/movies; gate 266, tests/realdata-063.mjs, README + STATUSmre
  • 10bb3f93tracker#28 (mission 061): full cast (all seasons, main cast by episodes, guest stars) + crew (created by, directed by, written by, screenplay, story, music) — stored by the details completion, the daily sync, the search import (one details request) and a background credits job (resumes, RSS limit); show page collapsed after 20 with client-side Show all; showBySlug via a slug map; gate 249, tests/realdata-028.mjs, README + STATUSmre
  • d8b12d67tracker#27 (mission 060): short ids for movies, series and persons — old 702 kept (data/old-short-ids.json), new random [a-z0-9]{5} unique across both, claimed at creation, background backfill (resumes), shown under poster/photo, /<shortId> → 301; gate 259, tests/realdata-060*, README + STATUSmre
  • 25a50bc4tracker#26 (mission 059): titles from a filmography are completed — on open (skeleton, step-wise face showComplete, no reload) and by the in-app details repair (resumes, TMDB-paced, series in parts); cast from TMDB credits; gate 231, tests/realdata-026.mjs, README + STATUSmre
  • f14db671tracker#22-#25 (mission 058): episode air dates, season check = all episodes watched, movie watched check (+ /my/movies count), /genres/<genre> pages (movies + series, newest first, paginated); gate 238, tests/realdata-058.mjs, README + STATUSmre
  • 1704ec45tracker#17 (mission 057): season caret down/up, skeleton rows while a season loads, sessionless showSeasonEpisodes face (no page re-mount), client-only close; gate 214, tests/realdata-057.mjs, README + STATUSmre
  • f2fe3e36mission 056: README + STATUS (merge, fixes, Hybriel 8590df63, real-data check), tests/realdata-056.mjs, tools/check-public-slugs.hlmre
  • f40c250emission 056: re-vendor hybriel master 8590df63 (#121, #122); an adult title's page is Not found for non-followers; gate: leave the page before stopping the servermre
  • 2b7fdd6cmission 056: signed-out header one row on phones ("Log in", nowrap), backfill skips adult titles' posters, gate checksmre
  • 2c53d5efMerge branch 't16-person' (tracker#16 person pages) into main; filmography shows only public titles (054 adult flag), gate race fix (backfill start line)mre
  • c171227emission 054: hide adult/unknown titles from the public lists and the search; in-app adult-flag backfill (TMDB details + poster per title, resumes), gate + real-data proofmre
  • 139fafd8tracker#16: short bio (4 lines, click = all), real-data check script, README + STATUSmre
  • 93be9476tracker#16: person pages /person/<slug> with the filmography fetched from TMDB on the first visit (step by step), gatemre
  • 47a3cae6STATUS: mission 053 merge commit idsmre
  • dcc5eecaMerge branch 't14-search'mre
  • 03edc783Merge branch 't15-tvmaze'mre
  • 71b46345tracker#15: numbering check by date or title, placeholder titles in other languages, docs + real-data proofmre