docs(ops): document registry secrets, rollback, Gitea runner image
operations.md lists the full secret/variable matrix the deploy workflow expects, the new compose.yaml + compose.netcup.yaml invocation, and a note on why both workflow jobs pin catthehacker/ubuntu:runner-latest. self-hosting.md updates the example LIBRENOTES_IMAGE value to the Gitea Packages path and switches the quick-start to compose.netcup.yaml.
This commit is contained in:
+37
-15
@@ -21,26 +21,32 @@ The workflow expects these secrets and variables on the repo:
|
||||
|
||||
| Name | Type | Purpose |
|
||||
| ---- | ---- | ------- |
|
||||
| `REGISTRY` | secret | hostname of the OCI registry |
|
||||
| `REGISTRY_USER` | secret | robot account |
|
||||
| `REGISTRY_PASS` | secret | robot token |
|
||||
| `DEPLOY_HOST` | secret | `user@host` SSH target |
|
||||
| `DEPLOY_KEY` | secret | passphrase-less private key |
|
||||
| `DEPLOY_PATH` | secret | absolute path on host with `docker-compose.*.yml` |
|
||||
| `HEALTH_URL` | secret | e.g. `https://librenot.es/healthz` |
|
||||
| `REGISTRY` | secret | registry hostname, e.g. `git.librete.ch` |
|
||||
| `REGISTRY_USER` | secret | robot account or PAT username with `package:write` |
|
||||
| `REGISTRY_PASS` | secret | robot/PAT token |
|
||||
| `DEPLOY_HOST` | secret | `user@host` SSH target, e.g. `root@netcup` |
|
||||
| `DEPLOY_KEY` | secret | passphrase-less private key (PEM) |
|
||||
| `DEPLOY_PATH` | secret | absolute path on host with the compose stack, e.g. `/srv/librenotes` |
|
||||
| `HEALTH_URL` | secret | e.g. `https://ln.cloud.librete.ch/healthz` |
|
||||
| `DEPLOY_ENABLED` | variable | `true` to enable the workflow |
|
||||
|
||||
The image is pushed to `${REGISTRY}/public/librenotes`; main pushes
|
||||
publish `:main` and `:<sha7>`, tag pushes publish `:vX.Y.Z` and
|
||||
`:latest`.
|
||||
|
||||
### Production compose stack
|
||||
|
||||
On the deployment host, place `docker-compose.yml` and
|
||||
`docker-compose.prod.yml` from this repo at `$DEPLOY_PATH`,
|
||||
together with an `.env` file containing the runtime configuration
|
||||
(JWT secret, SMTP credentials, public base URL, image tag).
|
||||
On the deployment host, place `compose.yaml` and
|
||||
`compose.netcup.yaml` from this repo at `$DEPLOY_PATH`, together
|
||||
with an `.env` file containing `LIBRENOTES_IMAGE` plus the runtime
|
||||
configuration (JWT secret, SMTP credentials, public base URL).
|
||||
See `.env.netcup.example` for the full key list.
|
||||
|
||||
Bring it up with:
|
||||
|
||||
```sh
|
||||
docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d
|
||||
docker compose -f compose.yaml -f compose.netcup.yaml pull
|
||||
docker compose -f compose.yaml -f compose.netcup.yaml up -d
|
||||
```
|
||||
|
||||
### Rollback
|
||||
@@ -52,11 +58,27 @@ on health-check failure — failed health alerts the operator via
|
||||
the workflow itself, who can then redeploy the prior tag manually.
|
||||
|
||||
```sh
|
||||
# Example: roll back to v0.1.2
|
||||
sed -i 's/^LIBRENOTES_IMAGE=.*/LIBRENOTES_IMAGE=registry.librete.ch\/librenotes:v0.1.2/' .env
|
||||
docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d
|
||||
# Example: roll back to v0.1.0
|
||||
perl -i -pe 's|^LIBRENOTES_IMAGE=.*|LIBRENOTES_IMAGE=git.librete.ch/public/librenotes:v0.1.0|' .env
|
||||
docker compose -f compose.yaml -f compose.netcup.yaml pull
|
||||
docker compose -f compose.yaml -f compose.netcup.yaml up -d
|
||||
```
|
||||
|
||||
### Gitea Actions runner
|
||||
|
||||
Workflows run on the netcup `act_runner` (see `runner/` stack in
|
||||
the netcup umbrella). Both jobs declare `container: catthehacker/ubuntu:runner-latest`
|
||||
because:
|
||||
|
||||
- The default runner label image (`node:20-bookworm`) lacks `make`
|
||||
and `docker`, both required by the workflows.
|
||||
- The `runner-latest` image bundles `make`, `git`, `curl`, `ssh`,
|
||||
`node`, plus a docker CLI.
|
||||
|
||||
The runner config (`runner/config.yaml`) declares
|
||||
`/var/run/docker.sock` as a `valid_volume` so the build job can
|
||||
mount the host socket and push images via `docker/build-push-action`.
|
||||
|
||||
## Backups
|
||||
|
||||
`scripts/backup.sh` is a self-contained backup driver suitable for
|
||||
|
||||
Reference in New Issue
Block a user