name: Deploy SCHA # Runs after Unit Tests completes on master. Direct pushes only (not PRs). on: workflow_run: workflows: [Unit Tests] types: [completed] branches: [master] jobs: docker: if: gitea.event.workflow_run.conclusion == 'success' && gitea.event.workflow_run.event == 'push' runs-on: self-hosted steps: - name: Checkout uses: actions/checkout@v4 with: ref: ${{ gitea.event.workflow_run.head_sha }} - name: Build Docker image run: docker compose build # Ephemeral local Postgres only — never inherit host DATABASE_URL (prod). - name: Run containerized tests run: | set -euo pipefail # Drop host/prod DB secrets so compose cannot interpolate them. unset DATABASE_URL DB_HOST DB_NAME DB_USER DB_PASSWORD DB_PORT \ COMPOSE_DATABASE_URL DJANGO_ENV DJANGO_SECRET_KEY DJANGO_DEBUG \ DJANGO_ALLOWED_HOSTS || true PROJECT="scha-ci-${{ gitea.event.workflow_run.head_sha }}" cleanup() { docker compose -p "$PROJECT" down -v --remove-orphans || true; } trap cleanup EXIT docker compose -p "$PROJECT" up -d --wait db docker compose -p "$PROJECT" run --rm --no-deps --entrypoint "" \ -e DJANGO_ENV=dev \ -e DJANGO_SECRET_KEY=test-secret-key \ -e DJANGO_DEBUG=true \ -e DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,testserver \ -e DATABASE_URL=postgres://scha:scha@db:5432/scha \ web uv run python manage.py test deploy: if: gitea.event.workflow_run.conclusion == 'success' && gitea.event.workflow_run.event == 'push' runs-on: self-hosted needs: docker env: SERVER_INFRA_ROOT: /home/westfarn/Documents/repos/server-infra steps: - name: Deploy scha prod run: | "$SERVER_INFRA_ROOT/scripts/deploy.sh" \ --app scha \ --env prod \ --ref "${{ gitea.event.workflow_run.head_sha }}"