diff --git a/.gitea/workflows/deploy-dev.yml b/.gitea/workflows/deploy-dev.yml index 743c595..1940ca0 100644 --- a/.gitea/workflows/deploy-dev.yml +++ b/.gitea/workflows/deploy-dev.yml @@ -1,24 +1,71 @@ -name: Deploy Dev +name: Deploy Dev — Frontend on: push: branches: - dev + workflow_dispatch: jobs: deploy: + name: Deploy para VM Dev runs-on: self-hosted + env: + DEPLOY_PATH: /opt/omnichannel + steps: - - name: Atualizar código na VM Dev - run: | - cd /opt/omnichannel/frontend - git pull origin dev + - name: Checkout + uses: actions/checkout@v4 - - name: Copiar env + - name: Preflight + shell: bash run: | - cp /home/desenvolvimento/.envs/omnichannel/frontend.env.development /opt/omnichannel/frontend/.env.development + set -euo pipefail + echo "Runner: $(hostname)" + docker --version + docker compose version - - name: Rebuild container + - name: Verificar secrets obrigatórios + shell: bash + env: + ENV_DEV: ${{ secrets.ENV_DEV }} run: | - cd /opt/omnichannel - docker compose up -d --build frontend + set -euo pipefail + if [ -z "${ENV_DEV:-}" ]; then + echo "Secret ENV_DEV não configurado. Adicione o conteúdo completo do .env.development em Settings > Actions > Secrets." + exit 1 + fi + + - name: Escrever .env.development + shell: bash + env: + ENV_DEV: ${{ secrets.ENV_DEV }} + run: | + set -euo pipefail + printf '%s\n' "$ENV_DEV" > "$DEPLOY_PATH/frontend/.env.development" + chmod 600 "$DEPLOY_PATH/frontend/.env.development" + + - name: Sync código + shell: bash + run: | + set -euo pipefail + LOCK="/tmp/omnichannel-frontend-dev.lock" + ( + flock -n 9 || { echo "Deploy já em andamento. Tente novamente em instantes."; exit 1; } + + rsync -az --delete \ + --exclude='.git/' \ + --exclude='.gitea/' \ + --exclude='.env*' \ + --exclude='node_modules/' \ + --exclude='dist/' \ + ./ "$DEPLOY_PATH/frontend/" + ) 9>"$LOCK" + + - name: Build e reiniciar container + shell: bash + run: | + set -euo pipefail + cd "$DEPLOY_PATH" + docker compose build frontend + docker compose up -d frontend diff --git a/.gitea/workflows/deploy-prod.yml b/.gitea/workflows/deploy-prod.yml new file mode 100644 index 0000000..b81c18f --- /dev/null +++ b/.gitea/workflows/deploy-prod.yml @@ -0,0 +1,71 @@ +name: Deploy Prod — Frontend + +on: + push: + branches: + - master + workflow_dispatch: + +jobs: + deploy: + name: Deploy para VM Prod + runs-on: self-hosted-prod + env: + DEPLOY_PATH: /opt/omnichannel + + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Preflight + shell: bash + run: | + set -euo pipefail + echo "Runner: $(hostname)" + docker --version + docker compose version + + - name: Verificar secrets obrigatórios + shell: bash + env: + ENV_PROD: ${{ secrets.ENV_PROD }} + run: | + set -euo pipefail + if [ -z "${ENV_PROD:-}" ]; then + echo "Secret ENV_PROD não configurado." + exit 1 + fi + + - name: Escrever .env.production + shell: bash + env: + ENV_PROD: ${{ secrets.ENV_PROD }} + run: | + set -euo pipefail + printf '%s\n' "$ENV_PROD" > "$DEPLOY_PATH/frontend/.env.production" + chmod 600 "$DEPLOY_PATH/frontend/.env.production" + + - name: Sync código + shell: bash + run: | + set -euo pipefail + LOCK="/tmp/omnichannel-frontend-prod.lock" + ( + flock -n 9 || { echo "Deploy já em andamento. Tente novamente em instantes."; exit 1; } + + rsync -az --delete \ + --exclude='.git/' \ + --exclude='.gitea/' \ + --exclude='.env*' \ + --exclude='node_modules/' \ + --exclude='dist/' \ + ./ "$DEPLOY_PATH/frontend/" + ) 9>"$LOCK" + + - name: Build e reiniciar container + shell: bash + run: | + set -euo pipefail + cd "$DEPLOY_PATH" + docker compose build frontend + docker compose up -d frontend