CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 | #!/usr/bin/env bash
#
# Fast auto-deploy for the standalone box. Installed as a ~60s systemd timer by
# scripts/standalone-deploy.sh. Polls the deploy branch; when new commits land,
# it pulls, rebuilds, and runs migrations. Push -> live in ~1-2 min, hands-off.
#
# Exits immediately (cheap) when there is nothing new, so a tight interval is fine.
set -euo pipefail
REPO_DIR="/opt/gluecron"
BRANCH="main"
COMPOSE="docker compose -f docker-compose.standalone.yml"
cd "$REPO_DIR"
git fetch origin "$BRANCH" --quiet
local_sha=$(git rev-parse HEAD)
remote_sha=$(git rev-parse "origin/$BRANCH")
[ "$local_sha" = "$remote_sha" ] && exit 0
echo "$(date -Is) deploying $local_sha -> $remote_sha"
git reset --hard "origin/$BRANCH" # untracked .env / backups are preserved
# NOTE: `|| true` is deliberate. On this Coolify co-tenant box the compose
# also defines a `caddy` service that tries to bind host :80/:443, which
# Coolify's proxy already owns — so `up` reports a non-zero exit for caddy
# even though the app (gluecron) started fine. Under `set -e` that would abort
# the deploy BEFORE the coolify reattach + health gate below. We tolerate the
# partial failure here and instead gate on the app's OWN health further down.
$COMPOSE up -d --build || echo "$(date -Is) compose up returned non-zero (likely the co-tenant caddy port conflict) — continuing to app health gate"
sleep 5
# Co-tenant ingress reattach (Coolify boxes only).
# `docker compose up --build` recreates the gluecron container, which DROPS
# any network attachment not declared in docker-compose.standalone.yml. On
# this box the public ingress is Coolify's Traefik ("coolify-proxy"), which
# reaches the app over the external "coolify" network via the file route
# /traefik/dynamic/gluecron.yaml in the coolify-proxy container. Without this
# reattach, every deploy 502s the site until someone reconnects by hand.
# Idempotent: a no-op if already attached; skipped entirely on a dedicated VPS
# that has no "coolify" network.
if docker network inspect coolify >/dev/null 2>&1; then
docker network connect coolify gluecron-gluecron-1 2>/dev/null \
&& echo "$(date -Is) reattached gluecron to coolify network" \
|| echo "$(date -Is) coolify network already attached (ok)"
fi
$COMPOSE exec -T gluecron bun run db:migrate || true
docker image prune -f >/dev/null 2>&1 || true
# App health gate — the real success signal (not caddy). Poll the container's
# own /healthz; if the app itself never comes up, exit non-zero so the systemd
# unit records a failed deploy instead of a silent green.
healthy=0
for _ in $(seq 1 20); do
if docker exec gluecron-gluecron-1 wget -qO- --timeout=4 http://localhost:3000/healthz >/dev/null 2>&1; then
healthy=1; break
fi
sleep 3
done
if [ "$healthy" != "1" ]; then
echo "$(date -Is) DEPLOY FAILED: app /healthz never came up for $remote_sha" >&2
exit 1
fi
echo "$(date -Is) deploy complete: $remote_sha (app healthy)"
|