ci: align deployment on Kuby (Docker + rsync + SSH key + healthcheck + rollback)
All checks were successful
ci / ci (push) Successful in 44s
ci / ci (pull_request) Successful in 43s

- Add HTTP /health endpoint (aiohttp) for Docker healthcheck + post-deploy check
- Dockerfile HEALTHCHECK hits /health; docker-compose exposes 1890, container vision-bot
- scripts/deploy_runner.sh runs on .117 (docker compose build/restart)
- .forgejo/workflows/deploy.yml: single job on omhk-deploy runner (clone, syntax test,
  rsync, deploy, health check, auto-rollback) like Kuby
- .forgejo/workflows/ci.yml: single job (ruff + pytest) on dev/PR
This commit is contained in:
Mathis 2026-09-19 16:04:59 +02:00
parent e32ca9c8fb
commit e22a98a4a3
8 changed files with 308 additions and 48 deletions

View file

@ -1,70 +1,46 @@
name: CI/CD
name: ci
on:
push:
branches: [main, dev]
branches: [dev]
pull_request:
branches: [main]
jobs:
lint:
ci:
runs-on: ubuntu-latest
steps:
- name: Checkout
- name: Recuperation du depot
run: |
git clone https://omegakubeserv.tail951d2f.ts.net/Omega_Kube/VisionApp.git .
set -euo pipefail
rm -rf repo
git clone https://omegakubeserv.tail951d2f.ts.net/Omega_Kube/VisionApp.git repo
cd repo
git checkout "${{ github.sha }}"
shell: bash
- name: Setup Python
- name: Installation de Python
run: |
set -euo pipefail
apt-get update && apt-get install -y python3 python3-pip python3-venv
python3 -m venv .venv
. .venv/bin/activate
pip install -r requirements.txt -r requirements-dev.txt
pip install -r repo/requirements.txt -r repo/requirements-dev.txt
shell: bash
- name: Ruff lint
- name: Lint (ruff)
run: |
set -euo pipefail
. .venv/bin/activate
cd repo
ruff check .
- name: Ruff format check
run: |
. .venv/bin/activate
ruff format --check .
shell: bash
test:
runs-on: ubuntu-latest
steps:
- name: Checkout
run: |
git clone https://omegakubeserv.tail951d2f.ts.net/Omega_Kube/VisionApp.git .
git checkout "${{ github.sha }}"
- name: Setup Python
run: |
apt-get update && apt-get install -y python3 python3-pip python3-venv
python3 -m venv .venv
. .venv/bin/activate
pip install -r requirements.txt -r requirements-dev.txt
- name: Syntax check
run: |
. .venv/bin/activate
python3 -m py_compile bot.py
python3 -m py_compile vision.py
python3 -m py_compile config.py
- name: Run tests
- name: Tests (pytest)
run: |
set -euo pipefail
. .venv/bin/activate
cd repo
pytest tests/ -v || true
deploy:
needs: [lint, test]
if: github.ref == 'refs/heads/main' && github.event_name == 'push'
runs-on: ubuntu-latest
steps:
- name: Deploy to production
run: |
apt-get update && apt-get install -y sshpass openssh-client
sshpass -p "${{ secrets.PROD_PASSWORD }}" ssh -o StrictHostKeyChecking=no ${{ secrets.PROD_USER }}@${{ secrets.PROD_HOST }} "cd /home/discord/Bots/VisionApp && git pull origin main --rebase && source venv/bin/activate && pip install -r requirements.txt && echo '${{ secrets.PROD_PASSWORD }}' | sudo -S systemctl restart vision-studio && echo 'Deploy OK'"
shell: bash