name: Deploy # Its own workflow, and workflow_dispatch only — there is no push trigger, so # there is nothing to skip. Deploying used to be a job inside the build # workflow behind `if: github.event.inputs.deploy == 'true'`. On a push there # is no github.event.inputs at all; this Forgejo dispatched the job regardless, # the runner could not resolve it, and it reported "Early termination". Every # run of that workflow showed a failure for a job that was never meant to run. # # A separate file also matches what deploying is: a deliberate act, taken after # someone has looked at the change, not a consequence of pushing. on: workflow_dispatch: inputs: revision: description: Full commit SHA to deploy. Leave blank for the branch tip. required: false default: '' jobs: deploy: name: Deploy to the host runs-on: forgejo-local env: DEPLOY_DIR: ${{ vars.DEPLOY_DIR || '/home/danvics/docker/ped-ai' }} steps: # The deploy directory is also a working tree. This refuses rather than # resetting over someone's uncommitted work. - name: Refuse to deploy over uncommitted work run: | if [ -n "$(git -C "$DEPLOY_DIR" status --porcelain)" ]; then echo "$DEPLOY_DIR has uncommitted changes; commit or stash them first." >&2 git -C "$DEPLOY_DIR" status --short >&2 exit 1 fi # Detaches HEAD at the deployed revision, which is what a deployed tree # should be. If DEPLOY_DIR is also where you write code, point this at a # checkout of its own instead — vars.DEPLOY_DIR. - name: Move the deploy checkout to this revision run: | REVISION="${{ github.event.inputs.revision }}" [ -n "$REVISION" ] || REVISION="${{ github.sha }}" echo "REVISION=$REVISION" >> "$GITHUB_ENV" git -C "$DEPLOY_DIR" fetch --quiet --all git -C "$DEPLOY_DIR" checkout --quiet --detach "$REVISION" # deploy.sh pins the image, waits for health, asks /api/build what is # actually running, and rolls back if it disagrees. Schema migrations are # applied by the container's own entrypoint before the app starts. - name: Deploy and verify run: | IMAGE="git.danvics.com/danvics/pediatric-ai-scribe-v3" "$DEPLOY_DIR/scripts/deploy.sh" "$IMAGE:$REVISION" "$REVISION"