The deploy workflow is now a single job that builds, pushes, and deploys in one runner. Tag computation moved to docker/metadata-action, the per-deploy .env perl rewrite is gone (host pins LIBRENOTES_IMAGE once; main pushes update :main rolling, releases pin to :vX.Y.Z by manual edit), and both jobs run in our bespoke runner image whose runner user already has socket access via group membership. ci.yml moves to the same image so go/make/node are all available without per-step apt installs. Drops compose.prod.yaml (unused, redundant with compose.netcup.yaml).
23 lines
945 B
Bash
23 lines
945 B
Bash
# Server-side .env for netcup deploy. Copy to /srv/librenotes/.env on the host.
|
|
# Used by: docker compose -f compose.yaml -f compose.netcup.yaml up -d
|
|
|
|
# Image to pull. The default `:main` rolls forward — main pushes
|
|
# rebuild and push the same tag, so `compose pull` picks up the new
|
|
# digest without rewriting this file. To pin a release (or roll back),
|
|
# edit this line to an immutable tag such as :v0.1.0 and re-run
|
|
# `docker compose -f compose.yaml -f compose.netcup.yaml pull && up -d`.
|
|
LIBRENOTES_IMAGE=git.librete.ch/public/librenotes:main
|
|
|
|
# Public origin (caddy reverse-proxies to librenotes:8080)
|
|
LIBRENOTES_BASE_URL=https://ln.cloud.librete.ch
|
|
|
|
# JWT secret — at least 32 bytes. Generate: openssl rand -base64 48
|
|
LIBRENOTES_JWT_SECRET=CHANGE_ME
|
|
|
|
# SMTP relay (magic-link delivery)
|
|
LIBRENOTES_SMTP_HOST=smtp.example.com
|
|
LIBRENOTES_SMTP_PORT=587
|
|
LIBRENOTES_SMTP_USER=
|
|
LIBRENOTES_SMTP_PASS=
|
|
LIBRENOTES_SMTP_FROM=no-reply@librete.ch
|