ci(deploy): switch to libretech/runner-image:v1 and consolidate
The deploy workflow is now a single job that builds, pushes, and deploys in one runner. Tag computation moved to docker/metadata-action, the per-deploy .env perl rewrite is gone (host pins LIBRENOTES_IMAGE once; main pushes update :main rolling, releases pin to :vX.Y.Z by manual edit), and both jobs run in our bespoke runner image whose runner user already has socket access via group membership. ci.yml moves to the same image so go/make/node are all available without per-step apt installs. Drops compose.prod.yaml (unused, redundant with compose.netcup.yaml).
This commit is contained in:
+17
-15
@@ -51,14 +51,16 @@ docker compose -f compose.yaml -f compose.netcup.yaml up -d
|
||||
|
||||
### Rollback
|
||||
|
||||
Image tags are immutable per commit / version. To roll back, set
|
||||
`LIBRENOTES_IMAGE` to the previous tag in `.env` and run the same
|
||||
`up -d` command. The deployment workflow does not auto-rollback
|
||||
on health-check failure — failed health alerts the operator via
|
||||
the workflow itself, who can then redeploy the prior tag manually.
|
||||
Tag pushes publish immutable tags (`:vX.Y.Z`). To pin or roll back,
|
||||
edit `LIBRENOTES_IMAGE` in `/srv/librenotes/.env` and re-run pull +
|
||||
up. The deployment workflow itself never rewrites the file — failed
|
||||
health checks abort the workflow and the operator redeploys
|
||||
manually.
|
||||
|
||||
```sh
|
||||
# Example: roll back to v0.1.0
|
||||
ssh netcup
|
||||
cd /srv/librenotes
|
||||
perl -i -pe 's|^LIBRENOTES_IMAGE=.*|LIBRENOTES_IMAGE=git.librete.ch/public/librenotes:v0.1.0|' .env
|
||||
docker compose -f compose.yaml -f compose.netcup.yaml pull
|
||||
docker compose -f compose.yaml -f compose.netcup.yaml up -d
|
||||
@@ -67,17 +69,17 @@ docker compose -f compose.yaml -f compose.netcup.yaml up -d
|
||||
### Gitea Actions runner
|
||||
|
||||
Workflows run on the netcup `act_runner` (see `runner/` stack in
|
||||
the netcup umbrella). Both jobs declare `container: catthehacker/ubuntu:runner-latest`
|
||||
because:
|
||||
the netcup umbrella). Both `ci.yml` and `deploy.yml` declare
|
||||
`container: image: git.librete.ch/libretech/runner-image:v1` —
|
||||
a bespoke Ubuntu 24.04 image (built and signed by us, hosted on
|
||||
the same Gitea instance) that bundles `git`, `make`, `node`,
|
||||
`perl`, `ssh`, and a docker CLI. The image's `runner` user is
|
||||
pre-joined to `docker` group gid 998 so the auto-mounted
|
||||
`/var/run/docker.sock` is writable without `--user root`.
|
||||
|
||||
- The default runner label image (`node:20-bookworm`) lacks `make`
|
||||
and `docker`, both required by the workflows.
|
||||
- The `runner-latest` image bundles `make`, `git`, `curl`, `ssh`,
|
||||
`node`, plus a docker CLI.
|
||||
|
||||
The runner config (`runner/config.yaml`) declares
|
||||
`/var/run/docker.sock` as a `valid_volume` so the build job can
|
||||
mount the host socket and push images via `docker/build-push-action`.
|
||||
The runner config (`runner/config.yaml`) whitelists
|
||||
`/var/run/docker.sock` under `valid_volumes` to allow the
|
||||
auto-mount.
|
||||
|
||||
## Backups
|
||||
|
||||
|
||||
Reference in New Issue
Block a user