Files
shot-crafter-calculator/.gitea/workflows/ci.yml
T
darroyo a2fb5cc521
CI / Build Native (push) Failing after 12m4s
ci: deploy native binary directly to LXC via SSH (drop Docker/registry)
Switch the runtime from a Docker image to a systemd service running the
native binary on the LXC host. The CI still uses Docker for the build
environment (maven:3.9.6-eclipse-temurin-21), but stops at producing the
static native binary.

Pipeline changes:
- Drop docker.io, docker-buildx, docker buildx, docker push, registry.
- Drop Dockerfile, compose.yaml, .dockerignore (no longer needed).
- Build native binary in CI container, SCP to LXC, run deploy script.
- Deploy script stops the service, swaps the binary, starts it, hits
  /q/health/live to verify.

LXC one-time setup (manual, run on the host):
- useradd runner (UID 1001)
- mkdir /opt/shot-crafter-calculator/{data,keys,deploy}
- copy RSA JWT keys into keys/
- install /etc/systemd/system/shot-crafter-calculator.service
- install /usr/local/bin/deploy-shot-crafter-calculator.sh
- useradd deployer + ssh keypair for the CI
- store DEPLOY_SSH_KEY secret in Gitea

Bootstrap the first deploy manually with scp + ssh before relying on CI.
2026-08-13 20:05:17 -04:00

82 lines
2.5 KiB
YAML

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
build-native:
name: Build Native
runs-on: ubuntu-latest
container:
image: maven:3.9.6-eclipse-temurin-21
options: --memory=8g
steps:
- name: Install git, node, gcc, and basic tools
run: |
apt-get update
apt-get install -y git curl ca-certificates build-essential zlib1g-dev openssh-client
curl -fsSL https://deb.nodesource.com/setup_22.x | bash -
apt-get install -y nodejs
rm -rf /var/lib/apt/lists/*
git --version
node --version
gcc --version
- name: Checkout
uses: actions/checkout@v4
- name: Cache Maven repository
uses: actions/cache@v4
with:
path: ~/.m2/repository
key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}
restore-keys: ${{ runner.os }}-maven-
- name: Set up GraalVM
uses: graalvm/setup-graalvm@v1
with:
distribution: 'graalvm'
java-version: '21'
components: 'native-image'
- name: Cache Node + npm
uses: actions/cache@v4
with:
path: |
target/node
src/frontend/node_modules
key: ${{ runner.os }}-node-${{ hashFiles('src/frontend/package-lock.json') }}
restore-keys: ${{ runner.os }}-node-
- name: Build (Native)
run: mvn package -Pnative -B -DskipTests -Dquarkus.native.native-image-xmx=4g -Dquarkus.native.binary-type=STATIC
- name: Verify native binary
run: ls -la target/shot-crafter-calculator-1.0.0-runner
- name: Deploy to LXC
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
run: |
set -e
mkdir -p ~/.ssh
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
chmod 0600 ~/.ssh/deploy_key
ssh-keyscan -H localhost >> ~/.ssh/known_hosts
ssh -i ~/.ssh/deploy_key deployer@localhost \
"mkdir -p /opt/shot-crafter-calculator/deploy"
scp -i ~/.ssh/deploy_key \
target/shot-crafter-calculator-1.0.0-runner \
deployer@localhost:/opt/shot-crafter-calculator/deploy/application
ssh -i ~/.ssh/deploy_key deployer@localhost \
"sudo /usr/local/bin/deploy-shot-crafter-calculator.sh"