Compare commits
9 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
f27c73195f
|
|||
|
c2b64de621
|
|||
| d7d6662804 | |||
|
2878699082
|
|||
| b551493110 | |||
|
24e6e2b4a1
|
|||
| 7f540b4510 | |||
|
f6b43492e9
|
|||
| 457a53f987 |
@@ -144,3 +144,4 @@ Makefile.local
|
||||
# ============================================================
|
||||
wiki/
|
||||
docs/
|
||||
.claude/
|
||||
|
||||
@@ -1,22 +1,16 @@
|
||||
# Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
|
||||
# SPDX-License-Identifier: GPL-3.0-or-later
|
||||
# BRIEF: Deploy to the Dev environment on push to the dev branch via the
|
||||
# restricted per-repo deploy pattern. This is a THIN trigger: it only
|
||||
# validates the tier+tag and hands "<tier> <tag>" to the forced-command
|
||||
# deploy-mokogit user over SSH (mokocli cli/deploy.php). The server-side
|
||||
# forced command sudo's to a root-owned deployer that builds, pushes,
|
||||
# recreates and health-checks — the runner never builds, holds a registry
|
||||
# token, or runs the health check. See `.vault system/deploy` and runbook
|
||||
# 16-restricted-deploy-pattern.
|
||||
# OWNER: Template-Go (canonical source; syncs to the root workflows dir). See Template-Go#3.
|
||||
# NOTE: deploy-*.yml are repo-managed (per-repo deploy user + secrets/vars)
|
||||
# and excluded from template sync — see mokocli workflow_sync PLATFORM_EXCLUDES['go'].
|
||||
# BRIEF: Deploy to the Dev environment on push to the dev branch. THIN TRIGGER —
|
||||
# the deploy LOGIC lives in mokocli (cli/deploy.php) and server-side in the
|
||||
# restricted per-repo deploy pattern (.vault system/deploy, runbook 16).
|
||||
# This workflow validates + invokes only; it carries NO registry token and
|
||||
# NO build script. A leaked DEPLOY_SSH_KEY can only redeploy this one repo.
|
||||
# OWNER: Template-Go (canonical; syncs to each repo's .mokogit/workflows).
|
||||
#
|
||||
# Required repo VARIABLES:
|
||||
# DEV_SSH_HOST, DEV_SSH_PORT, DEV_SSH_USERNAME - SSH deploy target for the dev tier
|
||||
# (DEV_SSH_USERNAME = deploy-mokogit, the forced-command deploy user)
|
||||
# Required SECRETS (already configured; reused, not re-set):
|
||||
# DEPLOY_SSH_KEY - deploy-mokogit private key (repo secret)
|
||||
# Required repo VARIABLES (tier-scoped): DEV_SSH_HOST, DEV_SSH_PORT, DEV_SSH_USERNAME.
|
||||
# Required SECRET: DEPLOY_SSH_KEY (the deploy-<repo> private key).
|
||||
# ONBOARDING: a repo joins the restricted deploy pattern when DEV_SSH_USERNAME is
|
||||
# set to deploy-<repo>. Un-onboarded go repos skip the job (guards below).
|
||||
|
||||
name: Deploy (Dev)
|
||||
|
||||
@@ -24,13 +18,9 @@ on:
|
||||
push:
|
||||
branches:
|
||||
- dev
|
||||
# Manual trigger for isolated end-to-end tests.
|
||||
# Runs on the ref it is dispatched from.
|
||||
workflow_dispatch:
|
||||
|
||||
# No `concurrency:` block: it triggers a MokoGIT Actions run-creation bug that
|
||||
# silently drops deploys on rapid pushes to the branch. Do not re-add until the
|
||||
# upstream bug is confirmed fixed.
|
||||
# No `concurrency:` block: triggers a MokoGIT run-creation bug that drops deploys.
|
||||
|
||||
env:
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
|
||||
@@ -39,6 +29,7 @@ jobs:
|
||||
deploy-dev:
|
||||
name: "Deploy to Dev"
|
||||
runs-on: ubuntu-latest
|
||||
if: ${{ vars.DEV_SSH_USERNAME != '' }}
|
||||
steps:
|
||||
- name: Checkout source
|
||||
uses: actions/checkout@v4
|
||||
@@ -60,29 +51,20 @@ jobs:
|
||||
echo "$DEPLOY_KEY" > ~/.ssh/deploy_key
|
||||
chmod 600 ~/.ssh/deploy_key
|
||||
|
||||
- name: Setup MokoCLI tools
|
||||
- name: Set up mokocli (deploy logic)
|
||||
env:
|
||||
MOKO_CLONE_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
|
||||
MOKO_CLONE_HOST: git.mokoconsulting.tech/MokoConsulting
|
||||
MOKOGIT_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
|
||||
run: |
|
||||
# Use pre-installed /opt/mokocli if available (updated by cron every 6h)
|
||||
if [ -f /opt/mokocli/cli/deploy.php ] && [ -f /opt/mokocli/vendor/autoload.php ]; then
|
||||
echo Using pre-installed /opt/mokocli
|
||||
echo MOKO_CLI=/opt/mokocli/cli >> $GITHUB_ENV
|
||||
else
|
||||
echo Falling back to fresh clone
|
||||
if ! command -v composer > /dev/null 2>&1; then
|
||||
sudo apt-get update -qq && sudo apt-get install -y -qq php-cli php-mbstring php-xml php-zip php-curl composer > /dev/null 2>&1
|
||||
fi
|
||||
rm -rf /tmp/mokocli
|
||||
CLONE_URL=https://x-access-token:${MOKO_CLONE_TOKEN}@${MOKO_CLONE_HOST}/mokocli.git
|
||||
git clone --depth 1 --branch main --quiet $CLONE_URL /tmp/mokocli
|
||||
cd /tmp/mokocli && composer install --no-dev --no-interaction --quiet
|
||||
echo MOKO_CLI=/tmp/mokocli/cli >> $GITHUB_ENV
|
||||
fi
|
||||
command -v php >/dev/null || { sudo apt-get update -qq && sudo apt-get install -y -qq php-cli; }
|
||||
git clone --depth 1 "https://x-access-token:${MOKOGIT_TOKEN}@git.mokoconsulting.tech/MokoConsulting/MokoCLI.git" "$RUNNER_TEMP/mokocli"
|
||||
echo "MOKO_CLI=$RUNNER_TEMP/mokocli/cli" >> $GITHUB_ENV
|
||||
|
||||
- name: Deploy (dev)
|
||||
- name: Deploy (mokocli triggers the restricted deploy pattern)
|
||||
run: |
|
||||
php ${MOKO_CLI}/deploy.php --tier dev --tag "${{ steps.config.outputs.tag }}" \
|
||||
--ssh-host ${{ vars.DEV_SSH_HOST }} --ssh-port ${{ vars.DEV_SSH_PORT }} \
|
||||
--ssh-user ${{ vars.DEV_SSH_USERNAME }} --ssh-key ~/.ssh/deploy_key
|
||||
if [ -z "${{ vars.DEV_SSH_USERNAME }}" ]; then
|
||||
echo "DEV_SSH_USERNAME unset — repo not onboarded to the restricted deploy pattern; skipping."
|
||||
exit 0
|
||||
fi
|
||||
php "$MOKO_CLI/deploy.php" --tier dev --tag "${{ steps.config.outputs.tag }}" \
|
||||
--ssh-host "${{ vars.DEV_SSH_HOST }}" --ssh-port "${{ vars.DEV_SSH_PORT }}" \
|
||||
--ssh-user "${{ vars.DEV_SSH_USERNAME }}" --ssh-key ~/.ssh/deploy_key
|
||||
|
||||
@@ -1,23 +1,16 @@
|
||||
# Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
|
||||
# SPDX-License-Identifier: GPL-3.0-or-later
|
||||
# BRIEF: Deploy to the Prod environment on push to the main branch via the
|
||||
# restricted per-repo deploy pattern. This is a THIN trigger: it only
|
||||
# validates the tier+tag and hands "<tier> <tag>" to the forced-command
|
||||
# deploy-mokogit user over SSH (mokocli cli/deploy.php). The server-side
|
||||
# forced command sudo's to a root-owned deployer that builds, pushes,
|
||||
# recreates and health-checks — the runner never builds, holds a registry
|
||||
# token, or runs the health check. See `.vault system/deploy` and runbook
|
||||
# 16-restricted-deploy-pattern.
|
||||
# Prod deploys on merge to main (dev -> rc -> main pipeline).
|
||||
# OWNER: Template-Go (canonical source; syncs to the root workflows dir). See Template-Go#3.
|
||||
# NOTE: deploy-*.yml are repo-managed (per-repo deploy user + secrets/vars)
|
||||
# and excluded from template sync — see mokocli workflow_sync PLATFORM_EXCLUDES['go'].
|
||||
# BRIEF: Deploy to the Prod environment on push to the main branch. THIN TRIGGER —
|
||||
# the deploy LOGIC lives in mokocli (cli/deploy.php) and server-side in the
|
||||
# restricted per-repo deploy pattern (.vault system/deploy, runbook 16).
|
||||
# This workflow validates + invokes only; it carries NO registry token and
|
||||
# NO build script. A leaked DEPLOY_SSH_KEY can only redeploy this one repo.
|
||||
# OWNER: Template-Go (canonical; syncs to each repo's .mokogit/workflows).
|
||||
#
|
||||
# Required repo VARIABLES:
|
||||
# PROD_SSH_HOST, PROD_SSH_PORT, PROD_SSH_USERNAME - SSH deploy target for the prod tier
|
||||
# (PROD_SSH_USERNAME = deploy-mokogit, the forced-command deploy user)
|
||||
# Required SECRETS (already configured; reused, not re-set):
|
||||
# DEPLOY_SSH_KEY - deploy-mokogit private key (repo secret)
|
||||
# Required repo VARIABLES (tier-scoped): PROD_SSH_HOST, PROD_SSH_PORT, PROD_SSH_USERNAME.
|
||||
# Required SECRET: DEPLOY_SSH_KEY (the deploy-<repo> private key).
|
||||
# ONBOARDING: a repo joins the restricted deploy pattern when PROD_SSH_USERNAME is
|
||||
# set to deploy-<repo>. Un-onboarded go repos skip the job (guards below).
|
||||
|
||||
name: Deploy (Prod)
|
||||
|
||||
@@ -25,13 +18,9 @@ on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
# Manual trigger for a prod re-deploy.
|
||||
# Runs on the ref it is dispatched from (use main).
|
||||
workflow_dispatch:
|
||||
|
||||
# No `concurrency:` block: it triggers a MokoGIT Actions run-creation bug that
|
||||
# silently drops deploys on rapid pushes to the branch. Do not re-add until the
|
||||
# upstream bug is confirmed fixed.
|
||||
# No `concurrency:` block: triggers a MokoGIT run-creation bug that drops deploys.
|
||||
|
||||
env:
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
|
||||
@@ -40,6 +29,7 @@ jobs:
|
||||
deploy-prod:
|
||||
name: "Deploy to Prod"
|
||||
runs-on: ubuntu-latest
|
||||
if: ${{ vars.PROD_SSH_USERNAME != '' }}
|
||||
steps:
|
||||
- name: Checkout source
|
||||
uses: actions/checkout@v4
|
||||
@@ -61,29 +51,20 @@ jobs:
|
||||
echo "$DEPLOY_KEY" > ~/.ssh/deploy_key
|
||||
chmod 600 ~/.ssh/deploy_key
|
||||
|
||||
- name: Setup MokoCLI tools
|
||||
- name: Set up mokocli (deploy logic)
|
||||
env:
|
||||
MOKO_CLONE_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
|
||||
MOKO_CLONE_HOST: git.mokoconsulting.tech/MokoConsulting
|
||||
MOKOGIT_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
|
||||
run: |
|
||||
# Use pre-installed /opt/mokocli if available (updated by cron every 6h)
|
||||
if [ -f /opt/mokocli/cli/deploy.php ] && [ -f /opt/mokocli/vendor/autoload.php ]; then
|
||||
echo Using pre-installed /opt/mokocli
|
||||
echo MOKO_CLI=/opt/mokocli/cli >> $GITHUB_ENV
|
||||
else
|
||||
echo Falling back to fresh clone
|
||||
if ! command -v composer > /dev/null 2>&1; then
|
||||
sudo apt-get update -qq && sudo apt-get install -y -qq php-cli php-mbstring php-xml php-zip php-curl composer > /dev/null 2>&1
|
||||
fi
|
||||
rm -rf /tmp/mokocli
|
||||
CLONE_URL=https://x-access-token:${MOKO_CLONE_TOKEN}@${MOKO_CLONE_HOST}/mokocli.git
|
||||
git clone --depth 1 --branch main --quiet $CLONE_URL /tmp/mokocli
|
||||
cd /tmp/mokocli && composer install --no-dev --no-interaction --quiet
|
||||
echo MOKO_CLI=/tmp/mokocli/cli >> $GITHUB_ENV
|
||||
fi
|
||||
command -v php >/dev/null || { sudo apt-get update -qq && sudo apt-get install -y -qq php-cli; }
|
||||
git clone --depth 1 "https://x-access-token:${MOKOGIT_TOKEN}@git.mokoconsulting.tech/MokoConsulting/MokoCLI.git" "$RUNNER_TEMP/mokocli"
|
||||
echo "MOKO_CLI=$RUNNER_TEMP/mokocli/cli" >> $GITHUB_ENV
|
||||
|
||||
- name: Deploy (prod)
|
||||
- name: Deploy (mokocli triggers the restricted deploy pattern)
|
||||
run: |
|
||||
php ${MOKO_CLI}/deploy.php --tier prod --tag "${{ steps.config.outputs.tag }}" \
|
||||
--ssh-host ${{ vars.PROD_SSH_HOST }} --ssh-port ${{ vars.PROD_SSH_PORT }} \
|
||||
--ssh-user ${{ vars.PROD_SSH_USERNAME }} --ssh-key ~/.ssh/deploy_key
|
||||
if [ -z "${{ vars.PROD_SSH_USERNAME }}" ]; then
|
||||
echo "PROD_SSH_USERNAME unset — repo not onboarded to the restricted deploy pattern; skipping."
|
||||
exit 0
|
||||
fi
|
||||
php "$MOKO_CLI/deploy.php" --tier prod --tag "${{ steps.config.outputs.tag }}" \
|
||||
--ssh-host "${{ vars.PROD_SSH_HOST }}" --ssh-port "${{ vars.PROD_SSH_PORT }}" \
|
||||
--ssh-user "${{ vars.PROD_SSH_USERNAME }}" --ssh-key ~/.ssh/deploy_key
|
||||
|
||||
@@ -1,23 +1,17 @@
|
||||
# Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
|
||||
# SPDX-License-Identifier: GPL-3.0-or-later
|
||||
# BRIEF: Deploy to the RC environment on push to the rc branch via the
|
||||
# restricted per-repo deploy pattern. This is a THIN trigger: it only
|
||||
# validates the tier+tag and hands "<tier> <tag>" to the forced-command
|
||||
# deploy-mokogit user over SSH (mokocli cli/deploy.php). The server-side
|
||||
# forced command sudo's to a root-owned deployer that builds, pushes,
|
||||
# recreates and health-checks — the runner never builds, holds a registry
|
||||
# token, or runs the health check. See `.vault system/deploy` and runbook
|
||||
# 16-restricted-deploy-pattern.
|
||||
# The rc branch is created by promote-rc when a PR to main opens.
|
||||
# OWNER: Template-Go (canonical source; syncs to the root workflows dir). See Template-Go#3.
|
||||
# NOTE: deploy-*.yml are repo-managed (per-repo deploy user + secrets/vars)
|
||||
# and excluded from template sync — see mokocli workflow_sync PLATFORM_EXCLUDES['go'].
|
||||
# BRIEF: Deploy to the RC environment on push to the rc branch. THIN TRIGGER —
|
||||
# the deploy LOGIC lives in mokocli (cli/deploy.php) and server-side in the
|
||||
# restricted per-repo deploy pattern (.vault system/deploy, runbook 16).
|
||||
# This workflow validates + invokes only; it carries NO registry token and
|
||||
# NO build script. A leaked DEPLOY_SSH_KEY can only redeploy this one repo.
|
||||
# OWNER: Template-Go (canonical; syncs to each repo's .mokogit/workflows).
|
||||
#
|
||||
# Required repo VARIABLES:
|
||||
# RC_SSH_HOST, RC_SSH_PORT, RC_SSH_USERNAME - SSH deploy target for the rc tier
|
||||
# (RC_SSH_USERNAME = deploy-mokogit, the forced-command deploy user)
|
||||
# Required SECRETS (already configured; reused, not re-set):
|
||||
# DEPLOY_SSH_KEY - deploy-mokogit private key (repo secret)
|
||||
# Required repo VARIABLES (tier-scoped): RC_SSH_HOST, RC_SSH_PORT, RC_SSH_USERNAME.
|
||||
# Required SECRET: DEPLOY_SSH_KEY (the deploy-<repo> private key).
|
||||
# ONBOARDING: a repo joins the restricted deploy pattern when RC_SSH_USERNAME is
|
||||
# set to deploy-<repo>. Un-onboarded go repos skip the job (guards below), so this
|
||||
# template is safe to cascade to every go repo.
|
||||
|
||||
name: Deploy (RC)
|
||||
|
||||
@@ -25,15 +19,9 @@ on:
|
||||
push:
|
||||
branches:
|
||||
- rc
|
||||
# Manual trigger for isolated end-to-end tests without a full RC promotion.
|
||||
# Runs on the ref it is dispatched from; that ref must carry current source
|
||||
# (>= the RC database migration version) or the rebuilt image will refuse the
|
||||
# newer DB. Dispatch from `rc` once `rc` is current.
|
||||
workflow_dispatch:
|
||||
|
||||
# No `concurrency:` block: it triggers a MokoGIT Actions run-creation bug that
|
||||
# silently drops deploys on rapid pushes to the branch. Do not re-add until the
|
||||
# upstream bug is confirmed fixed.
|
||||
# No `concurrency:` block: triggers a MokoGIT run-creation bug that drops deploys.
|
||||
|
||||
env:
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
|
||||
@@ -42,6 +30,8 @@ jobs:
|
||||
deploy-rc:
|
||||
name: "Deploy to RC"
|
||||
runs-on: ubuntu-latest
|
||||
# Guard 1 (job-level): skip entirely unless onboarded.
|
||||
if: ${{ vars.RC_SSH_USERNAME != '' }}
|
||||
steps:
|
||||
- name: Checkout source
|
||||
uses: actions/checkout@v4
|
||||
@@ -63,29 +53,21 @@ jobs:
|
||||
echo "$DEPLOY_KEY" > ~/.ssh/deploy_key
|
||||
chmod 600 ~/.ssh/deploy_key
|
||||
|
||||
- name: Setup MokoCLI tools
|
||||
- name: Set up mokocli (deploy logic)
|
||||
env:
|
||||
MOKO_CLONE_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
|
||||
MOKO_CLONE_HOST: git.mokoconsulting.tech/MokoConsulting
|
||||
MOKOGIT_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
|
||||
run: |
|
||||
# Use pre-installed /opt/mokocli if available (updated by cron every 6h)
|
||||
if [ -f /opt/mokocli/cli/deploy.php ] && [ -f /opt/mokocli/vendor/autoload.php ]; then
|
||||
echo Using pre-installed /opt/mokocli
|
||||
echo MOKO_CLI=/opt/mokocli/cli >> $GITHUB_ENV
|
||||
else
|
||||
echo Falling back to fresh clone
|
||||
if ! command -v composer > /dev/null 2>&1; then
|
||||
sudo apt-get update -qq && sudo apt-get install -y -qq php-cli php-mbstring php-xml php-zip php-curl composer > /dev/null 2>&1
|
||||
fi
|
||||
rm -rf /tmp/mokocli
|
||||
CLONE_URL=https://x-access-token:${MOKO_CLONE_TOKEN}@${MOKO_CLONE_HOST}/mokocli.git
|
||||
git clone --depth 1 --branch main --quiet $CLONE_URL /tmp/mokocli
|
||||
cd /tmp/mokocli && composer install --no-dev --no-interaction --quiet
|
||||
echo MOKO_CLI=/tmp/mokocli/cli >> $GITHUB_ENV
|
||||
fi
|
||||
command -v php >/dev/null || { sudo apt-get update -qq && sudo apt-get install -y -qq php-cli; }
|
||||
git clone --depth 1 "https://x-access-token:${MOKOGIT_TOKEN}@git.mokoconsulting.tech/MokoConsulting/MokoCLI.git" "$RUNNER_TEMP/mokocli"
|
||||
echo "MOKO_CLI=$RUNNER_TEMP/mokocli/cli" >> $GITHUB_ENV
|
||||
|
||||
- name: Deploy (rc)
|
||||
- name: Deploy (mokocli triggers the restricted deploy pattern)
|
||||
run: |
|
||||
php ${MOKO_CLI}/deploy.php --tier rc --tag "${{ steps.config.outputs.tag }}" \
|
||||
--ssh-host ${{ vars.RC_SSH_HOST }} --ssh-port ${{ vars.RC_SSH_PORT }} \
|
||||
--ssh-user ${{ vars.RC_SSH_USERNAME }} --ssh-key ~/.ssh/deploy_key
|
||||
# Guard 2 (step-level, reliable): no-op if not onboarded.
|
||||
if [ -z "${{ vars.RC_SSH_USERNAME }}" ]; then
|
||||
echo "RC_SSH_USERNAME unset — repo not onboarded to the restricted deploy pattern; skipping."
|
||||
exit 0
|
||||
fi
|
||||
php "$MOKO_CLI/deploy.php" --tier rc --tag "${{ steps.config.outputs.tag }}" \
|
||||
--ssh-host "${{ vars.RC_SSH_HOST }}" --ssh-port "${{ vars.RC_SSH_PORT }}" \
|
||||
--ssh-user "${{ vars.RC_SSH_USERNAME }}" --ssh-key ~/.ssh/deploy_key
|
||||
|
||||
@@ -3,6 +3,7 @@
|
||||
## [Unreleased]
|
||||
|
||||
### Fixed
|
||||
- **Update server (Joomla): serve the installable package, not the source archive** — `GenerateJoomlaXML` selected the first `.zip` attachment on a release, so releases carrying extra zips (e.g. `<repo>-<channel>-source.zip` ahead of `pkg_*.zip`) advertised the raw source archive; Joomla then downloaded a non-installable zip and failed with "Install path does not exist" (prerelease/dev channels). New `selectJoomlaArtifact()` prefers an extension-prefixed package (`pkg_`/`com_`/`mod_`/`plg_`/`tpl_`/`lib_`) and never a `-source` archive (hotfixed to prod)
|
||||
- **Actions: `.mokogit/workflows` custom-path detection restored** — `WorkflowDirs` now scans `.mokogit/workflows`; the legacy `.mokogitea/workflows` is fully retired. Workflow indexing, push-triggered CI/deploys, and `workflow_dispatch` work again (#798)
|
||||
- **Issue custom-status dropdown shows its options again** — the status `<select>` carried the `ui compact dropdown` class, so fomantic turned it into an overlay menu that painted behind the page content (options were present in the DOM but invisible); it is now a plain native `<select>` with its inline styles moved to a stylesheet (`web_src/css/repo/issue-status.css`)
|
||||
- Restored the repo's `.mokogit/workflows/` (deploy + org CI, ~20 workflows) from Template-Go after the workflow sync had dropped them
|
||||
|
||||
Reference in New Issue
Block a user