## Summary - Standalone Django 6 shortener: Bearer `/api/links/` (create/list/detail/disable) and public `GET /<code>` 302 - Host split, target-host allowlist, named rotatable tokens; `short_url` from `PUBLIC_SHORT_URL` - Landing page, DEBUG-only `/debug/` mint form, Django admin - Docker/compose (host **8005**), Gitea CI like monica_site (PR tests, beta on merge, prod button) - Caller contract in `API.md` Closes #1. Infra follow-up: [server-infra#22](ai_ml_operations/server-infra#22). ## Test plan - [ ] `cd site && uv run python manage.py test` - [ ] `docker compose up --build` → http://127.0.0.1:8005/ - [ ] `POST /api/links/` with `Bearer monica:dev-only-token` → 201 - [ ] `GET /<code>` → 302 to allowlisted https URL - [ ] No Bearer → 401; non-allowlisted host → 400 - [ ] `/debug/` only when `DEBUG=true` Reviewed-on: #2
84 lines
2.7 KiB
YAML
84 lines
2.7 KiB
YAML
name: Deploy Prod
|
|
|
|
on:
|
|
workflow_dispatch: {}
|
|
|
|
jobs:
|
|
unit-tests:
|
|
runs-on: self-hosted
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install uv
|
|
run: |
|
|
curl -LsSf https://astral.sh/uv/install.sh | sh
|
|
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
|
|
|
- name: Install dependencies
|
|
run: uv sync --frozen
|
|
|
|
- name: Run unit tests
|
|
env:
|
|
DJANGO_ENV: dev
|
|
DJANGO_SECRET_KEY: test-secret-key
|
|
DATABASE_URL: ""
|
|
DB_HOST: ""
|
|
SHORTENER_API_TOKENS: monica:dev-only-token
|
|
PUBLIC_SHORT_URL: https://go.mkdrealtor.com
|
|
SHORT_PUBLIC_HOSTS: go.mkdrealtor.com
|
|
SHORT_API_HOSTS: testserver,localhost,127.0.0.1
|
|
SHORT_ALLOWED_HOSTS: mkdrealtor.com
|
|
CLICK_IP_PEPPER: test-pepper
|
|
run: |
|
|
cd site
|
|
uv run python manage.py test
|
|
|
|
docker:
|
|
needs: unit-tests
|
|
runs-on: self-hosted
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Build Docker image
|
|
run: docker compose build
|
|
|
|
- name: Run containerized tests
|
|
run: |
|
|
set -euo pipefail
|
|
unset DATABASE_URL DB_HOST DB_NAME DB_USER DB_PASSWORD DB_PORT \
|
|
COMPOSE_DATABASE_URL DJANGO_ENV DJANGO_SECRET_KEY DJANGO_DEBUG \
|
|
DJANGO_ALLOWED_HOSTS || true
|
|
|
|
PROJECT="shortener-ci-${{ gitea.sha }}"
|
|
cleanup() { docker compose -p "$PROJECT" down -v --remove-orphans || true; }
|
|
trap cleanup EXIT
|
|
|
|
docker compose -p "$PROJECT" up -d --wait db
|
|
docker compose -p "$PROJECT" run --rm --no-deps --entrypoint "" \
|
|
-e DJANGO_ENV=dev \
|
|
-e DJANGO_SECRET_KEY=test-secret-key \
|
|
-e DJANGO_DEBUG=true \
|
|
-e DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,testserver \
|
|
-e DATABASE_URL=postgres://url_shortener:url_shortener@db:5432/url_shortener \
|
|
-e SHORTENER_API_TOKENS=monica:dev-only-token \
|
|
-e PUBLIC_SHORT_URL=https://go.mkdrealtor.com \
|
|
-e SHORT_PUBLIC_HOSTS=go.mkdrealtor.com \
|
|
-e SHORT_API_HOSTS=testserver,localhost,127.0.0.1 \
|
|
-e SHORT_ALLOWED_HOSTS=mkdrealtor.com \
|
|
-e CLICK_IP_PEPPER=test-pepper \
|
|
web uv run python manage.py test
|
|
|
|
deploy-prod:
|
|
needs: docker
|
|
runs-on: self-hosted
|
|
env:
|
|
SERVER_INFRA_ROOT: /home/westfarn/Documents/repos/server-infra
|
|
ANSIBLE_PRIVATE_KEY_FILE: /home/westfarn/.ssh/ansible_deploy
|
|
steps:
|
|
- name: Deploy url_shortening_service prod to all webservers
|
|
run: |
|
|
"$SERVER_INFRA_ROOT/scripts/deploy.sh" \
|
|
--app url_shortening_service \
|
|
--env prod \
|
|
--ref "${{ gitea.sha }}"
|