## Summary - Public short domain is **`piha.lc`** (prod) and **`beta.piha.li`** (beta) - `/` is a marketing page in [aimloperations.com](https://aimloperations.com) / `company_site` styling (Inter, dark, cyan) - CTA: want access → [contact](https://aimloperations.com/contact) - Nav/logo/footer match the company site; debug mint form uses the same chrome Closes #3. ## Secrets (control node) Update hostnames only — no new token/pepper unless you are rotating: **`url_shortening_service_prod.env`** ```text DJANGO_ALLOWED_HOSTS=piha.lc,shortener.aimloperations.com,url-shortener,web SHORT_DOMAIN=piha.lc PUBLIC_SHORT_URL=https://piha.lc SHORT_PUBLIC_HOSTS=piha.lc CONTACT_URL=https://aimloperations.com/contact ``` **`url_shortening_service_beta.env`** ```text DJANGO_ALLOWED_HOSTS=beta.piha.li,shortener-beta.aimloperations.com,url-shortener,web SHORT_DOMAIN=beta.piha.li PUBLIC_SHORT_URL=https://beta.piha.li SHORT_PUBLIC_HOSTS=beta.piha.li CONTACT_URL=https://aimloperations.com/contact ``` NPM: `piha.lc` / `beta.piha.li` → this container. Still do not proxy `/api/` on the short host. ## Test plan - [ ] `cd site && uv run python manage.py test` - [ ] `GET /` looks like aimloperations.com; Request access / Contact go to aimloperations.com/contact - [ ] `GET /<code>` still 302 - [ ] `/api/` on Host `piha.lc` is 404 Reviewed-on: #4
84 lines
2.6 KiB
YAML
84 lines
2.6 KiB
YAML
name: Deploy Prod
|
|
|
|
on:
|
|
workflow_dispatch: {}
|
|
|
|
jobs:
|
|
unit-tests:
|
|
runs-on: self-hosted
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install uv
|
|
run: |
|
|
curl -LsSf https://astral.sh/uv/install.sh | sh
|
|
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
|
|
|
- name: Install dependencies
|
|
run: uv sync --frozen
|
|
|
|
- name: Run unit tests
|
|
env:
|
|
DJANGO_ENV: dev
|
|
DJANGO_SECRET_KEY: test-secret-key
|
|
DATABASE_URL: ""
|
|
DB_HOST: ""
|
|
SHORTENER_API_TOKENS: monica:dev-only-token
|
|
PUBLIC_SHORT_URL: https://piha.lc
|
|
SHORT_PUBLIC_HOSTS: piha.lc
|
|
SHORT_API_HOSTS: testserver,localhost,127.0.0.1
|
|
SHORT_ALLOWED_HOSTS: mkdrealtor.com
|
|
CLICK_IP_PEPPER: test-pepper
|
|
run: |
|
|
cd site
|
|
uv run python manage.py test
|
|
|
|
docker:
|
|
needs: unit-tests
|
|
runs-on: self-hosted
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Build Docker image
|
|
run: docker compose build
|
|
|
|
- name: Run containerized tests
|
|
run: |
|
|
set -euo pipefail
|
|
unset DATABASE_URL DB_HOST DB_NAME DB_USER DB_PASSWORD DB_PORT \
|
|
COMPOSE_DATABASE_URL DJANGO_ENV DJANGO_SECRET_KEY DJANGO_DEBUG \
|
|
DJANGO_ALLOWED_HOSTS || true
|
|
|
|
PROJECT="shortener-ci-${{ gitea.sha }}"
|
|
cleanup() { docker compose -p "$PROJECT" down -v --remove-orphans || true; }
|
|
trap cleanup EXIT
|
|
|
|
docker compose -p "$PROJECT" up -d --wait db
|
|
docker compose -p "$PROJECT" run --rm --no-deps --entrypoint "" \
|
|
-e DJANGO_ENV=dev \
|
|
-e DJANGO_SECRET_KEY=test-secret-key \
|
|
-e DJANGO_DEBUG=true \
|
|
-e DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,testserver \
|
|
-e DATABASE_URL=postgres://url_shortener:url_shortener@db:5432/url_shortener \
|
|
-e SHORTENER_API_TOKENS=monica:dev-only-token \
|
|
-e PUBLIC_SHORT_URL=https://piha.lc \
|
|
-e SHORT_PUBLIC_HOSTS=piha.lc \
|
|
-e SHORT_API_HOSTS=testserver,localhost,127.0.0.1 \
|
|
-e SHORT_ALLOWED_HOSTS=mkdrealtor.com \
|
|
-e CLICK_IP_PEPPER=test-pepper \
|
|
web uv run python manage.py test
|
|
|
|
deploy-prod:
|
|
needs: docker
|
|
runs-on: self-hosted
|
|
env:
|
|
SERVER_INFRA_ROOT: /home/westfarn/Documents/repos/server-infra
|
|
ANSIBLE_PRIVATE_KEY_FILE: /home/westfarn/.ssh/ansible_deploy
|
|
steps:
|
|
- name: Deploy url_shortening_service prod to all webservers
|
|
run: |
|
|
"$SERVER_INFRA_ROOT/scripts/deploy.sh" \
|
|
--app url_shortening_service \
|
|
--env prod \
|
|
--ref "${{ gitea.sha }}"
|