gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit3251488a3251488atracker#7: /my/shows (followed shows, newest follow first, poster, title, last watched SxxEyy); gate can take screenshots (TRACKER_GATE_SHOTS)mre3251488a/deploy.sh

6.7 KB

  1. #!/usr/bin/env bash
  2. # deploy.sh — tracker.worldapi.org: Loreana (this folder) → Byrodin. Run ON LOREANA.
  3. #
  4. # ./deploy.sh gates → rsync → restart the container → public URL 200
  5. # ./deploy.sh --dry-run gates → rsync -n (shows what WOULD be sent), no restart, no URL check
  6. # ./deploy.sh --skip-tests skips the gates (LOUD warning) — only when you know why
  7. # ./deploy.sh --target DIR|HOST:DIR another destination (default below); a local DIR is
  8. # how the script is tested without touching Byrodin
  9. # ./deploy.sh --url URL the URL that must answer 200 after the restart
  10. # (env: DEPLOY_TARGET, DEPLOY_URL, DEPLOY_SSH override the same defaults)
  11. #
  12. # THE FIRST DEPLOY is done by the architect on Byrodin (folder, .env with this app's ident
  13. # API key + secret — registered once in ident's /apps for origin https://tracker.worldapi.org
  14. # — nginx vhost, cert, DNS). This script only updates the CODE: storage/, .sessions/, .env,
  15. # .scratch/, server.*, tests/ fixtures and logs are never sent, so live data on Byrodin is
  16. # never touched. No --delete: a file removed here stays on Byrodin (harmless).
  17. set -euo pipefail
  18. # ---- the app ------------------------------------------------------------------------------
  19. APP=tracker.worldapi.org
  20. CONTAINER=tracker.worldapi.org
  21. [email protected]:/CONTAINERS/projects/tracker.worldapi.org
  22. DEFAULT_URL=https://tracker.worldapi.org/
  23. GATES=(
  24. "node tests/browser.mjs"
  25. )
  26. # NEVER SENT (rsync patterns; a leading / anchors at the app folder)
  27. EXCLUDES=(
  28. /.git/ /.gitignore
  29. /storage/ /.sessions/ /.env /.env.* /.scratch/ /server.* '*.log' '*.pid' node_modules/
  30. )
  31. # ---------------------------------------------------------------------------------------------
  32. DRY=0
  33. SKIP=0
  34. TARGET=${DEPLOY_TARGET:-$DEFAULT_TARGET}
  35. URL=${DEPLOY_URL:-$DEFAULT_URL}
  36. # Loreana's ssh config may not apply to Byrodin: -F /dev/null (ident STATUS)
  37. SSH=${DEPLOY_SSH:-ssh -F /dev/null -o BatchMode=yes -o ConnectTimeout=15}
  38. usage() { sed -n '2,13p' "$0" | sed 's/^# \{0,1\}//'; }
  39. while [ $# -gt 0 ]; do
  40. case "$1" in
  41. --dry-run) DRY=1 ;;
  42. --skip-tests) SKIP=1 ;;
  43. --target) TARGET=${2:?--target needs a value}; shift ;;
  44. --target=*) TARGET=${1#--target=} ;;
  45. --url) URL=${2:?--url needs a value}; shift ;;
  46. --url=*) URL=${1#--url=} ;;
  47. -h|--help) usage; exit 0 ;;
  48. *) echo "deploy: unknown argument: $1" >&2; usage >&2; exit 2 ;;
  49. esac
  50. shift
  51. done
  52. HERE=$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)
  53. cd "$HERE"
  54. step() { printf '\n==> %s\n' "$*"; }
  55. run() { printf ' $ %s\n' "$*" >&2; "$@"; }
  56. die() { printf '\ndeploy: REFUSED — %s\n' "$*" >&2; exit 1; }
  57. # a target `host:dir` is remote, a plain path is local
  58. if [[ "$TARGET" == *:* ]]; then
  59. REMOTE_HOST=${TARGET%%:*}
  60. REMOTE_DIR=${TARGET#*:}
  61. else
  62. REMOTE_HOST=
  63. REMOTE_DIR=$TARGET
  64. fi
  65. step "[0/4] $APP → $TARGET (dry run: $DRY, skip tests: $SKIP)"
  66. echo " from $HERE"
  67. echo " url $URL"
  68. [ -x bin/hybriel ] || die "bin/hybriel is missing here"
  69. [ -f docker-compose.yml ] || die "docker-compose.yml is missing here"
  70. [ -f project.hl ] || die "project.hl is missing here"
  71. command -v rsync >/dev/null || die "rsync is not installed"
  72. # ---- 1. the gates ---------------------------------------------------------------------------
  73. if [ "$SKIP" = 1 ]; then
  74. step "[1/4] GATES SKIPPED"
  75. printf ' !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n'
  76. printf ' !! --skip-tests: NOTHING WAS TESTED. You deploy untested code. !!\n'
  77. printf ' !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!\n'
  78. else
  79. step "[1/4] gates (${#GATES[@]})"
  80. # headless Chromes that exist BEFORE the gates are not ours (other sessions' test runs)
  81. chromes() { ps -eo pid=,ppid=,args= | awk '/[h]l-browser-tier/ && /remote-debugging-port/ && !/--type=/ {print $1, $2}'; }
  82. before=" $(chromes | awk '{print $1}' | tr '\n' ' ') "
  83. for g in "${GATES[@]}"; do
  84. printf ' $ %s\n' "$g"
  85. out=$(mktemp)
  86. if ! $g > "$out" 2>&1; then
  87. grep -E '^FAIL|passed,' "$out" | sed 's/^/ /' || true
  88. echo " (full output: $out)"
  89. die "gate failed: $g"
  90. fi
  91. grep -E 'passed,' "$out" | tail -1 | sed 's/^/ /'
  92. rm -f "$out"
  93. done
  94. # a Chrome our gates LEFT: new since the gates began AND no longer owned by a running node test
  95. leaked=""
  96. while read -r pid ppid; do
  97. [ -z "$pid" ] && continue
  98. case "$before" in *" $pid "*) continue ;; esac
  99. ps -o args= -p "$ppid" 2>/dev/null | grep -q '^node\|/node ' && continue
  100. leaked="$leaked $pid"
  101. done < <(chromes)
  102. if [ -n "$leaked" ]; then
  103. die "a gate left a headless Chrome (pids:$leaked; ps -eo pid,args | grep hl-browser-tier)"
  104. fi
  105. fi
  106. # ---- 2. rsync the code ----------------------------------------------------------------------
  107. RSYNC=(rsync -az --no-owner --no-group --itemize-changes)
  108. for e in "${EXCLUDES[@]}"; do RSYNC+=("--exclude=$e"); done
  109. if [ -n "$REMOTE_HOST" ]; then
  110. RSYNC+=(-e "$SSH")
  111. else
  112. mkdir -p "$REMOTE_DIR"
  113. fi
  114. # the preview is ALWAYS made first (rsync -n): nothing that must stay on Byrodin may be in it
  115. step "[2/4] rsync preview (what would be sent)"
  116. preview=$(mktemp)
  117. run "${RSYNC[@]}" -n ./ "$TARGET/" > "$preview"
  118. sed 's/^/ /' "$preview"
  119. echo " ($(grep -c . "$preview" || true) lines)"
  120. if awk '{print $2}' "$preview" | grep -E '^(storage/|\.sessions/|\.env|\.scratch/|server\.)|\.log$|\.pid$' ; then
  121. die "the preview holds a path that must never be sent (see above)"
  122. fi
  123. rm -f "$preview"
  124. if [ "$DRY" = 1 ]; then
  125. step "[2/4] DRY RUN: nothing sent"
  126. else
  127. step "[2/4] rsync"
  128. run "${RSYNC[@]}" ./ "$TARGET/" | sed 's/^/ /'
  129. fi
  130. # ---- 3. restart the container ---------------------------------------------------------------
  131. RESTART="cd '$REMOTE_DIR' && docker compose up -d --build && docker compose restart && docker compose ps"
  132. if [ "$DRY" = 1 ]; then
  133. step "[3/4] DRY RUN: would restart $CONTAINER"
  134. if [ -n "$REMOTE_HOST" ]; then echo " would run: $SSH $REMOTE_HOST \"$RESTART\""; else echo " would run: bash -c \"$RESTART\""; fi
  135. else
  136. step "[3/4] restart $CONTAINER"
  137. if [ -n "$REMOTE_HOST" ]; then
  138. run $SSH "$REMOTE_HOST" "$RESTART"
  139. else
  140. run bash -c "$RESTART"
  141. fi
  142. fi
  143. # ---- 4. the URL answers 200 -----------------------------------------------------------------
  144. if [ "$DRY" = 1 ]; then
  145. step "[4/4] DRY RUN: would check $URL answers 200"
  146. step "dry run done — nothing was sent, nothing restarted"
  147. exit 0
  148. fi
  149. step "[4/4] $URL must answer 200"
  150. code=000
  151. for i in $(seq 1 20); do
  152. code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 10 "$URL" || true)
  153. echo " try $i: $code"
  154. [ "$code" = 200 ] && break
  155. sleep 1
  156. done
  157. if [ "$code" != 200 ]; then
  158. if [ -n "$REMOTE_HOST" ]; then die "$URL answered $code, not 200 — look: $SSH $REMOTE_HOST docker logs --tail 50 $CONTAINER"; fi
  159. die "$URL answered $code, not 200 — look: docker logs --tail 50 $CONTAINER"
  160. fi
  161. step "deployed $APP → $TARGET, $URL answers 200"

Branches

Latest commits

  • 3251488atracker#7: /my/shows (followed shows, newest follow first, poster, title, last watched SxxEyy); gate can take screenshots (TRACKER_GATE_SHOTS)mre
  • 44b7d9f9tracker#6: /schedule — upcoming episodes of followed shows, soonest firstmre
  • 91c9fc8ctracker#5: /unwatched — unwatched released episodes of followed shows, newest firstmre
  • a97c0295tracker#4: show page /shows/:slug (header, seasons, episodes, watch checks) + tools/relink-episode-seasons.hlmre
  • 05f407c5tracker: no border on any button except inverted ones (Log out, ident status and identities too); header brand weight 100mre
  • 17375427tracker#2: tools/migrate.hl + tools/verify.hl — old MongoDB data into mpackdb with new idsmre
  • 31aac936tracker#3: no border on the header and on filled buttons; inverted buttons keep theirsmre
  • 2ad9d29ctracker#1: login exactly like calendar (identity selector in the header, empty homepage)mre
  • 3691e176tracker#1: empty tracker with the ident login (state of 2026-09-27)mre