Compare commits

..

9 Commits

Author SHA1 Message Date
jmiller f27c73195f Merge pull request 'release: MokoGIT hard-fork disconnect to prod (rebrand + Option-B GPL + /data/mokogit)' (#852) from dev into main
Cascade Main -> Dev / Cascade main -> dev (push) Has been cancelled
Deploy (Prod) / Deploy to Prod (push) Has been cancelled
Universal: Push Notifications / push-notify (push) Has been cancelled
Generic: Standards Compliance / Secret Scanning (push) Has been cancelled
Generic: Standards Compliance / License Header Validation (push) Has been cancelled
Generic: Standards Compliance / Repository Structure Validation (push) Has been cancelled
Generic: Standards Compliance / Coding Standards Check (push) Has been cancelled
Generic: Standards Compliance / Version Consistency Check (push) Has been cancelled
Generic: Standards Compliance / Workflow Configuration Check (push) Has been cancelled
Generic: Standards Compliance / Documentation Quality Check (push) Has been cancelled
Generic: Standards Compliance / README Completeness Check (push) Has been cancelled
Generic: Standards Compliance / Git Repository Hygiene (push) Has been cancelled
Generic: Standards Compliance / Script Integrity Validation (push) Has been cancelled
Generic: Standards Compliance / Line Length Check (push) Has been cancelled
Generic: Standards Compliance / File Naming Standards (push) Has been cancelled
Generic: Standards Compliance / Insecure Code Pattern Detection (push) Has been cancelled
Generic: Standards Compliance / Code Complexity Analysis (push) Has been cancelled
Generic: Standards Compliance / Code Duplication Detection (push) Has been cancelled
Generic: Standards Compliance / Dead Code Detection (push) Has been cancelled
Generic: Standards Compliance / File Size Limits (push) Has been cancelled
Generic: Standards Compliance / Binary File Detection (push) Has been cancelled
Generic: Standards Compliance / TODO/FIXME Tracking (push) Has been cancelled
Generic: Standards Compliance / Dependency Vulnerability Scanning (push) Has been cancelled
Generic: Standards Compliance / Unused Dependencies Check (push) Has been cancelled
Generic: Standards Compliance / Broken Link Detection (push) Has been cancelled
Generic: Standards Compliance / API Documentation Coverage (push) Has been cancelled
Generic: Standards Compliance / Accessibility Check (push) Has been cancelled
Generic: Standards Compliance / Performance Metrics (push) Has been cancelled
Generic: Standards Compliance / Enterprise Readiness Check (push) Has been cancelled
Generic: Standards Compliance / Repository Health Check (push) Has been cancelled
Generic: Standards Compliance / Terraform Configuration Validation (push) Has been cancelled
Generic: Standards Compliance / Compliance Summary (push) Has been cancelled
2026-07-20 14:13:16 +00:00
jmiller c2b64de621 Merge pull request 'docs(changelog): Joomla update-server artifact-selection fix' (#851) from chore/changelog-updateserver into dev
Universal: Build & Release / Promote to RC (pull_request) Has been skipped
Universal: Build & Release / Build & Release Pipeline (pull_request) Failing after 47s
Universal: Pre-Release / Build Pre-Release (${{ inputs.stability || github.ref_name }}) (push) Successful in 47s
Deploy (Dev) / Deploy to Dev (push) Has been cancelled
Generic: Project CI / Tests (pull_request) Successful in 44s
Generic: Project CI / Lint & Validate (pull_request) Successful in 47s
Universal: PR Check / Branch Policy (pull_request) Successful in 2s
Universal: PR Check / Wiki Update Reminder (pull_request) Successful in 1s
Generic: Repo Health / Access control (pull_request) Has been cancelled
Generic: Repo Health / Site Health (pull_request) Has been cancelled
Generic: Standards Compliance / Secret Scanning (pull_request) Has been cancelled
Generic: Standards Compliance / License Header Validation (pull_request) Has been cancelled
Generic: Standards Compliance / Repository Structure Validation (pull_request) Has been cancelled
Generic: Standards Compliance / Coding Standards Check (pull_request) Has been cancelled
Generic: Standards Compliance / Version Consistency Check (pull_request) Has been cancelled
Generic: Standards Compliance / Workflow Configuration Check (pull_request) Has been cancelled
Generic: Standards Compliance / Documentation Quality Check (pull_request) Has been cancelled
Generic: Standards Compliance / README Completeness Check (pull_request) Has been cancelled
Generic: Standards Compliance / Git Repository Hygiene (pull_request) Has been cancelled
Generic: Standards Compliance / Script Integrity Validation (pull_request) Has been cancelled
Generic: Standards Compliance / Line Length Check (pull_request) Has been cancelled
Generic: Standards Compliance / File Naming Standards (pull_request) Has been cancelled
Generic: Standards Compliance / Insecure Code Pattern Detection (pull_request) Has been cancelled
Generic: Standards Compliance / Code Complexity Analysis (pull_request) Has been cancelled
Generic: Standards Compliance / Code Duplication Detection (pull_request) Has been cancelled
Generic: Standards Compliance / Dead Code Detection (pull_request) Has been cancelled
Generic: Standards Compliance / File Size Limits (pull_request) Has been cancelled
Generic: Standards Compliance / Binary File Detection (pull_request) Has been cancelled
Generic: Standards Compliance / TODO/FIXME Tracking (pull_request) Has been cancelled
Generic: Standards Compliance / Dependency Vulnerability Scanning (pull_request) Has been cancelled
Generic: Standards Compliance / Unused Dependencies Check (pull_request) Has been cancelled
Generic: Standards Compliance / Broken Link Detection (pull_request) Has been cancelled
Generic: Standards Compliance / API Documentation Coverage (pull_request) Has been cancelled
Generic: Standards Compliance / Accessibility Check (pull_request) Has been cancelled
Generic: Standards Compliance / Performance Metrics (pull_request) Has been cancelled
Generic: Standards Compliance / Enterprise Readiness Check (pull_request) Has been cancelled
Generic: Standards Compliance / Repository Health Check (pull_request) Has been cancelled
Generic: Standards Compliance / Terraform Configuration Validation (pull_request) Has been cancelled
Branch Cleanup / Delete merged branch (pull_request) Has been cancelled
Universal: Workflow Sync Trigger / Sync workflows to live repos (pull_request) Has been cancelled
RC Revert / Rename rc/ back to dev/ (pull_request) Has been cancelled
Deploy (RC) / Deploy to RC (push) Has been cancelled
Universal: PR Check / Build RC Package (pull_request) Has been cancelled
Universal: PR Check / Report Issues (pull_request) Has been cancelled
Generic: Repo Health / Scripts governance (pull_request) Has been cancelled
Generic: Repo Health / Repository health (pull_request) Has been cancelled
Generic: Repo Health / Report: Scripts Governance (pull_request) Has been cancelled
Generic: Repo Health / Report: Repository Health (pull_request) Has been cancelled
Generic: Standards Compliance / Compliance Summary (pull_request) Has been cancelled
Universal: PR Check / Validate PR (pull_request) Successful in 23s
Universal: PR Check / Secret Scan (pull_request) Successful in 1m4s
Universal: PR Check / Require Docs Update (pull_request) Successful in 1m7s
Universal: Auto Version Bump / Version Bump (push) Has been skipped
2026-07-20 14:09:12 +00:00
Moko Consulting d7d6662804 docs(changelog): record Joomla update-server artifact-selection fix
Universal: Pre-Release / Build Pre-Release (${{ inputs.stability || github.ref_name }}) (push) Failing after 28s
Generic: Project CI / Lint & Validate (pull_request) Has been cancelled
Generic: Project CI / Tests (pull_request) Has been cancelled
Universal: PR Check / Branch Policy (pull_request) Has been cancelled
Universal: PR Check / Require Docs Update (pull_request) Has been cancelled
Universal: PR Check / Wiki Update Reminder (pull_request) Has been cancelled
Universal: PR Check / Secret Scan (pull_request) Has been cancelled
Universal: PR Check / Validate PR (pull_request) Has been cancelled
Branch Cleanup / Delete merged branch (pull_request) Has been cancelled
RC Revert / Rename rc/ back to dev/ (pull_request) Has been cancelled
Universal: PR Check / Build RC Package (pull_request) Has been cancelled
Universal: PR Check / Report Issues (pull_request) Has been cancelled
Authored-by: Moko Consulting
2026-07-20 09:08:21 -05:00
jmiller 2878699082 Merge pull request 'chore(sync): cascade main -> dev' (#845) from main into dev
Universal: Auto Version Bump / Version Bump (push) Has been skipped
Universal: Pre-Release / Build Pre-Release (${{ inputs.stability || github.ref_name }}) (push) Successful in 50s
Deploy (Dev) / Deploy to Dev (push) Has been cancelled
2026-07-20 13:57:29 +00:00
jmiller b551493110 chore: sync deploy-{dev,rc,prod}.yml from Template-Go [skip ci]
Branch Cleanup / Delete merged branch (pull_request) Has been skipped
RC Revert / Rename rc/ back to dev/ (pull_request) Has been skipped
Thin-trigger deploy: logic in mokocli (cli/deploy.php) + restricted per-repo deploy
pattern. No registry token / build script in CI. Onboarding-guarded.
Authored-by: Moko Consulting
2026-07-20 08:57:14 -05:00
jmiller 24e6e2b4a1 Merge pull request 'chore: ignore .claude + untrack .gemini (AI client dot-folders)' (#850) from chore/ignore-ai-folders into dev
Universal: Auto Version Bump / Version Bump (push) Has been skipped
Universal: Pre-Release / Build Pre-Release (${{ inputs.stability || github.ref_name }}) (push) Successful in 1m25s
Deploy (Dev) / Build & Deploy to Dev (push) Failing after 57s
2026-07-20 13:47:02 +00:00
Moko Consulting 7f540b4510 chore: ignore .claude + untrack .gemini (AI client dot-folders)
Universal: Pre-Release / Build Pre-Release (${{ inputs.stability || github.ref_name }}) (push) Successful in 49s
Universal: PR Check / Branch Policy (pull_request) Successful in 1s
Universal: PR Check / Require Docs Update (pull_request) Has been skipped
Universal: PR Check / Wiki Update Reminder (pull_request) Has been skipped
Generic: Project CI / Lint & Validate (pull_request) Successful in 33s
Universal: PR Check / Validate PR (pull_request) Successful in 10s
Generic: Project CI / Tests (pull_request) Successful in 29s
Universal: PR Check / Secret Scan (pull_request) Successful in 40s
Branch Cleanup / Delete merged branch (pull_request) Successful in 2s
RC Revert / Rename rc/ back to dev/ (pull_request) Has been skipped
Universal: PR Check / Build RC Package (pull_request) Has been cancelled
Universal: PR Check / Report Issues (pull_request) Has been cancelled
AI-client working dirs must not be committed. Add .claude/ to .gitignore
(.gemini/ and .mokoai/ already present) and untrack .gemini/GEMINI.md.

Authored-by: Moko Consulting
2026-07-20 08:46:22 -05:00
jmiller f6b43492e9 Merge pull request 'fix(updateserver): pick installable package zip, not source archive (prod hotfix)' (#844) from hotfix/joomla-artifact-selection into main
Universal: Push Notifications / push-notify (push) Successful in 2s
Generic: Standards Compliance / Secret Scanning (push) Failing after 8s
Generic: Standards Compliance / License Header Validation (push) Successful in 12s
Generic: Standards Compliance / Repository Structure Validation (push) Successful in 16s
Generic: Standards Compliance / Coding Standards Check (push) Successful in 14s
Cascade Main -> Dev / Cascade main -> dev (push) Successful in 1m5s
Generic: Standards Compliance / Workflow Configuration Check (push) Failing after 8s
Generic: Standards Compliance / Documentation Quality Check (push) Successful in 19s
Generic: Standards Compliance / README Completeness Check (push) Failing after 16s
Generic: Standards Compliance / Version Consistency Check (push) Successful in 2m2s
Generic: Standards Compliance / Script Integrity Validation (push) Successful in 17s
Generic: Standards Compliance / Line Length Check (push) Successful in 23s
Generic: Standards Compliance / File Naming Standards (push) Successful in 11s
Generic: Standards Compliance / Insecure Code Pattern Detection (push) Successful in 10s
Generic: Standards Compliance / Git Repository Hygiene (push) Successful in 2m54s
Generic: Standards Compliance / Code Complexity Analysis (push) Successful in 1m9s
Generic: Standards Compliance / Dead Code Detection (push) Successful in 8s
Generic: Standards Compliance / Code Duplication Detection (push) Successful in 54s
Generic: Standards Compliance / File Size Limits (push) Successful in 6s
Deploy (Prod) / Build & Deploy to Prod (push) Successful in 5m46s
Generic: Standards Compliance / TODO/FIXME Tracking (push) Successful in 6s
Generic: Standards Compliance / Unused Dependencies Check (push) Successful in 41s
Generic: Standards Compliance / Dependency Vulnerability Scanning (push) Successful in 46s
Generic: Standards Compliance / API Documentation Coverage (push) Successful in 6s
Generic: Standards Compliance / Broken Link Detection (push) Successful in 9s
Generic: Standards Compliance / Accessibility Check (push) Successful in 6s
Generic: Standards Compliance / Performance Metrics (push) Successful in 6s
Generic: Standards Compliance / Binary File Detection (push) Successful in 1m20s
Generic: Standards Compliance / Terraform Configuration Validation (push) Successful in 10s
Generic: Standards Compliance / Repository Health Check (push) Successful in 42s
Generic: Standards Compliance / Enterprise Readiness Check (push) Successful in 42s
Generic: Project CI / Lint & Validate (pull_request) Successful in 29s
Generic: Project CI / Tests (pull_request) Successful in 28s
Universal: PR Check / Require Docs Update (pull_request) Has been skipped
Universal: PR Check / Wiki Update Reminder (pull_request) Has been skipped
Universal: PR Check / Branch Policy (pull_request) Successful in 2s
Universal: PR Check / Validate PR (pull_request) Successful in 7s
Universal: PR Check / Secret Scan (pull_request) Successful in 35s
Generic: Standards Compliance / Compliance Summary (push) Has been cancelled
Universal: PR Check / Build RC Package (pull_request) Has been cancelled
Universal: PR Check / Report Issues (pull_request) Has been cancelled
2026-07-20 11:53:14 +00:00
Moko Consulting 457a53f987 fix(updateserver): pick installable package zip, not the source archive
Universal: Pre-Release / Build Pre-Release (${{ inputs.stability || github.ref_name }}) (push) Successful in 1m5s
Universal: Build & Release / Promote to RC (pull_request) Has been skipped
Universal: Build & Release / Build & Release Pipeline (pull_request) Failing after 1m8s
Universal: PR Check / Branch Policy (pull_request) Successful in 1s
Generic: Project CI / Lint & Validate (pull_request) Successful in 34s
Universal: PR Check / Wiki Update Reminder (pull_request) Successful in 1s
Generic: Project CI / Tests (pull_request) Successful in 22s
Universal: PR Check / Validate PR (pull_request) Successful in 7s
Generic: Repo Health / Access control (pull_request) Successful in 2s
Generic: Repo Health / Site Health (pull_request) Has been skipped
Generic: Standards Compliance / Secret Scanning (pull_request) Failing after 8s
Universal: PR Check / Require Docs Update (pull_request) Failing after 35s
Generic: Standards Compliance / License Header Validation (pull_request) Successful in 7s
Generic: Standards Compliance / Repository Structure Validation (pull_request) Successful in 13s
Generic: Standards Compliance / Coding Standards Check (pull_request) Successful in 18s
Generic: Standards Compliance / Workflow Configuration Check (pull_request) Failing after 7s
Universal: PR Check / Secret Scan (pull_request) Successful in 54s
Generic: Standards Compliance / Documentation Quality Check (pull_request) Successful in 6s
Generic: Standards Compliance / README Completeness Check (pull_request) Failing after 7s
Generic: Standards Compliance / Script Integrity Validation (pull_request) Successful in 8s
Generic: Standards Compliance / Line Length Check (pull_request) Successful in 14s
Generic: Standards Compliance / Version Consistency Check (pull_request) Successful in 49s
Generic: Standards Compliance / File Naming Standards (pull_request) Successful in 9s
Generic: Standards Compliance / Git Repository Hygiene (pull_request) Successful in 45s
Generic: Standards Compliance / Insecure Code Pattern Detection (pull_request) Successful in 15s
Generic: Standards Compliance / Code Duplication Detection (pull_request) Successful in 47s
Generic: Standards Compliance / Code Complexity Analysis (pull_request) Successful in 1m15s
Generic: Standards Compliance / Dead Code Detection (pull_request) Successful in 25s
Generic: Standards Compliance / File Size Limits (pull_request) Successful in 20s
Generic: Standards Compliance / TODO/FIXME Tracking (pull_request) Successful in 21s
Generic: Standards Compliance / Dependency Vulnerability Scanning (pull_request) Successful in 1m6s
Generic: Standards Compliance / Unused Dependencies Check (pull_request) Successful in 49s
Generic: Standards Compliance / Broken Link Detection (pull_request) Successful in 8s
Generic: Standards Compliance / API Documentation Coverage (pull_request) Successful in 6s
Generic: Standards Compliance / Accessibility Check (pull_request) Successful in 6s
Generic: Standards Compliance / Performance Metrics (pull_request) Successful in 6s
Generic: Standards Compliance / Binary File Detection (pull_request) Successful in 2m3s
Generic: Standards Compliance / Terraform Configuration Validation (pull_request) Successful in 13s
Branch Cleanup / Delete merged branch (pull_request) Successful in 1s
Universal: Workflow Sync Trigger / Sync workflows to live repos (pull_request) Has been skipped
RC Revert / Rename rc/ back to dev/ (pull_request) Has been skipped
Generic: Standards Compliance / Enterprise Readiness Check (pull_request) Successful in 53s
Generic: Standards Compliance / Repository Health Check (pull_request) Successful in 51s
Universal: PR Check / Build RC Package (pull_request) Has been cancelled
Universal: PR Check / Report Issues (pull_request) Has been cancelled
Generic: Repo Health / Scripts governance (pull_request) Has been cancelled
Generic: Repo Health / Repository health (pull_request) Has been cancelled
Generic: Repo Health / Report: Scripts Governance (pull_request) Has been cancelled
Generic: Repo Health / Report: Repository Health (pull_request) Has been cancelled
Generic: Standards Compliance / Compliance Summary (pull_request) Has been cancelled
The Joomla update feed took the FIRST .zip attachment on a release as the
download URL. Releases that carry extra zips (e.g. <repo>-<channel>-source.zip
alongside pkg_*.zip) then advertised the raw SOURCE archive, so Joomla
downloaded a non-installable zip and failed with "Install path does not exist"
(affected prerelease/dev channels; stable had a single pkg_ zip so was fine).

Add selectJoomlaArtifact(): prefer an extension-prefixed zip
(pkg_/com_/mod_/plg_/tpl_/lib_) that is not a "-source" archive, then any
non-source zip, then any zip.

Authored-by: Moko Consulting
2026-07-20 06:51:55 -05:00
6 changed files with 80 additions and 133 deletions
View File
+1
View File
@@ -144,3 +144,4 @@ Makefile.local
# ============================================================
wiki/
docs/
.claude/
+25 -43
View File
@@ -1,22 +1,16 @@
# Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
# SPDX-License-Identifier: GPL-3.0-or-later
# BRIEF: Deploy to the Dev environment on push to the dev branch via the
# restricted per-repo deploy pattern. This is a THIN trigger: it only
# validates the tier+tag and hands "<tier> <tag>" to the forced-command
# deploy-mokogit user over SSH (mokocli cli/deploy.php). The server-side
# forced command sudo's to a root-owned deployer that builds, pushes,
# recreates and health-checks — the runner never builds, holds a registry
# token, or runs the health check. See `.vault system/deploy` and runbook
# 16-restricted-deploy-pattern.
# OWNER: Template-Go (canonical source; syncs to the root workflows dir). See Template-Go#3.
# NOTE: deploy-*.yml are repo-managed (per-repo deploy user + secrets/vars)
# and excluded from template sync — see mokocli workflow_sync PLATFORM_EXCLUDES['go'].
# BRIEF: Deploy to the Dev environment on push to the dev branch. THIN TRIGGER —
# the deploy LOGIC lives in mokocli (cli/deploy.php) and server-side in the
# restricted per-repo deploy pattern (.vault system/deploy, runbook 16).
# This workflow validates + invokes only; it carries NO registry token and
# NO build script. A leaked DEPLOY_SSH_KEY can only redeploy this one repo.
# OWNER: Template-Go (canonical; syncs to each repo's .mokogit/workflows).
#
# Required repo VARIABLES:
# DEV_SSH_HOST, DEV_SSH_PORT, DEV_SSH_USERNAME - SSH deploy target for the dev tier
# (DEV_SSH_USERNAME = deploy-mokogit, the forced-command deploy user)
# Required SECRETS (already configured; reused, not re-set):
# DEPLOY_SSH_KEY - deploy-mokogit private key (repo secret)
# Required repo VARIABLES (tier-scoped): DEV_SSH_HOST, DEV_SSH_PORT, DEV_SSH_USERNAME.
# Required SECRET: DEPLOY_SSH_KEY (the deploy-<repo> private key).
# ONBOARDING: a repo joins the restricted deploy pattern when DEV_SSH_USERNAME is
# set to deploy-<repo>. Un-onboarded go repos skip the job (guards below).
name: Deploy (Dev)
@@ -24,13 +18,9 @@ on:
push:
branches:
- dev
# Manual trigger for isolated end-to-end tests.
# Runs on the ref it is dispatched from.
workflow_dispatch:
# No `concurrency:` block: it triggers a MokoGIT Actions run-creation bug that
# silently drops deploys on rapid pushes to the branch. Do not re-add until the
# upstream bug is confirmed fixed.
# No `concurrency:` block: triggers a MokoGIT run-creation bug that drops deploys.
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
@@ -39,6 +29,7 @@ jobs:
deploy-dev:
name: "Deploy to Dev"
runs-on: ubuntu-latest
if: ${{ vars.DEV_SSH_USERNAME != '' }}
steps:
- name: Checkout source
uses: actions/checkout@v4
@@ -60,29 +51,20 @@ jobs:
echo "$DEPLOY_KEY" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
- name: Setup MokoCLI tools
- name: Set up mokocli (deploy logic)
env:
MOKO_CLONE_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
MOKO_CLONE_HOST: git.mokoconsulting.tech/MokoConsulting
MOKOGIT_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
run: |
# Use pre-installed /opt/mokocli if available (updated by cron every 6h)
if [ -f /opt/mokocli/cli/deploy.php ] && [ -f /opt/mokocli/vendor/autoload.php ]; then
echo Using pre-installed /opt/mokocli
echo MOKO_CLI=/opt/mokocli/cli >> $GITHUB_ENV
else
echo Falling back to fresh clone
if ! command -v composer > /dev/null 2>&1; then
sudo apt-get update -qq && sudo apt-get install -y -qq php-cli php-mbstring php-xml php-zip php-curl composer > /dev/null 2>&1
fi
rm -rf /tmp/mokocli
CLONE_URL=https://x-access-token:${MOKO_CLONE_TOKEN}@${MOKO_CLONE_HOST}/mokocli.git
git clone --depth 1 --branch main --quiet $CLONE_URL /tmp/mokocli
cd /tmp/mokocli && composer install --no-dev --no-interaction --quiet
echo MOKO_CLI=/tmp/mokocli/cli >> $GITHUB_ENV
fi
command -v php >/dev/null || { sudo apt-get update -qq && sudo apt-get install -y -qq php-cli; }
git clone --depth 1 "https://x-access-token:${MOKOGIT_TOKEN}@git.mokoconsulting.tech/MokoConsulting/MokoCLI.git" "$RUNNER_TEMP/mokocli"
echo "MOKO_CLI=$RUNNER_TEMP/mokocli/cli" >> $GITHUB_ENV
- name: Deploy (dev)
- name: Deploy (mokocli triggers the restricted deploy pattern)
run: |
php ${MOKO_CLI}/deploy.php --tier dev --tag "${{ steps.config.outputs.tag }}" \
--ssh-host ${{ vars.DEV_SSH_HOST }} --ssh-port ${{ vars.DEV_SSH_PORT }} \
--ssh-user ${{ vars.DEV_SSH_USERNAME }} --ssh-key ~/.ssh/deploy_key
if [ -z "${{ vars.DEV_SSH_USERNAME }}" ]; then
echo "DEV_SSH_USERNAME unset — repo not onboarded to the restricted deploy pattern; skipping."
exit 0
fi
php "$MOKO_CLI/deploy.php" --tier dev --tag "${{ steps.config.outputs.tag }}" \
--ssh-host "${{ vars.DEV_SSH_HOST }}" --ssh-port "${{ vars.DEV_SSH_PORT }}" \
--ssh-user "${{ vars.DEV_SSH_USERNAME }}" --ssh-key ~/.ssh/deploy_key
+25 -44
View File
@@ -1,23 +1,16 @@
# Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
# SPDX-License-Identifier: GPL-3.0-or-later
# BRIEF: Deploy to the Prod environment on push to the main branch via the
# restricted per-repo deploy pattern. This is a THIN trigger: it only
# validates the tier+tag and hands "<tier> <tag>" to the forced-command
# deploy-mokogit user over SSH (mokocli cli/deploy.php). The server-side
# forced command sudo's to a root-owned deployer that builds, pushes,
# recreates and health-checks — the runner never builds, holds a registry
# token, or runs the health check. See `.vault system/deploy` and runbook
# 16-restricted-deploy-pattern.
# Prod deploys on merge to main (dev -> rc -> main pipeline).
# OWNER: Template-Go (canonical source; syncs to the root workflows dir). See Template-Go#3.
# NOTE: deploy-*.yml are repo-managed (per-repo deploy user + secrets/vars)
# and excluded from template sync — see mokocli workflow_sync PLATFORM_EXCLUDES['go'].
# BRIEF: Deploy to the Prod environment on push to the main branch. THIN TRIGGER —
# the deploy LOGIC lives in mokocli (cli/deploy.php) and server-side in the
# restricted per-repo deploy pattern (.vault system/deploy, runbook 16).
# This workflow validates + invokes only; it carries NO registry token and
# NO build script. A leaked DEPLOY_SSH_KEY can only redeploy this one repo.
# OWNER: Template-Go (canonical; syncs to each repo's .mokogit/workflows).
#
# Required repo VARIABLES:
# PROD_SSH_HOST, PROD_SSH_PORT, PROD_SSH_USERNAME - SSH deploy target for the prod tier
# (PROD_SSH_USERNAME = deploy-mokogit, the forced-command deploy user)
# Required SECRETS (already configured; reused, not re-set):
# DEPLOY_SSH_KEY - deploy-mokogit private key (repo secret)
# Required repo VARIABLES (tier-scoped): PROD_SSH_HOST, PROD_SSH_PORT, PROD_SSH_USERNAME.
# Required SECRET: DEPLOY_SSH_KEY (the deploy-<repo> private key).
# ONBOARDING: a repo joins the restricted deploy pattern when PROD_SSH_USERNAME is
# set to deploy-<repo>. Un-onboarded go repos skip the job (guards below).
name: Deploy (Prod)
@@ -25,13 +18,9 @@ on:
push:
branches:
- main
# Manual trigger for a prod re-deploy.
# Runs on the ref it is dispatched from (use main).
workflow_dispatch:
# No `concurrency:` block: it triggers a MokoGIT Actions run-creation bug that
# silently drops deploys on rapid pushes to the branch. Do not re-add until the
# upstream bug is confirmed fixed.
# No `concurrency:` block: triggers a MokoGIT run-creation bug that drops deploys.
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
@@ -40,6 +29,7 @@ jobs:
deploy-prod:
name: "Deploy to Prod"
runs-on: ubuntu-latest
if: ${{ vars.PROD_SSH_USERNAME != '' }}
steps:
- name: Checkout source
uses: actions/checkout@v4
@@ -61,29 +51,20 @@ jobs:
echo "$DEPLOY_KEY" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
- name: Setup MokoCLI tools
- name: Set up mokocli (deploy logic)
env:
MOKO_CLONE_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
MOKO_CLONE_HOST: git.mokoconsulting.tech/MokoConsulting
MOKOGIT_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
run: |
# Use pre-installed /opt/mokocli if available (updated by cron every 6h)
if [ -f /opt/mokocli/cli/deploy.php ] && [ -f /opt/mokocli/vendor/autoload.php ]; then
echo Using pre-installed /opt/mokocli
echo MOKO_CLI=/opt/mokocli/cli >> $GITHUB_ENV
else
echo Falling back to fresh clone
if ! command -v composer > /dev/null 2>&1; then
sudo apt-get update -qq && sudo apt-get install -y -qq php-cli php-mbstring php-xml php-zip php-curl composer > /dev/null 2>&1
fi
rm -rf /tmp/mokocli
CLONE_URL=https://x-access-token:${MOKO_CLONE_TOKEN}@${MOKO_CLONE_HOST}/mokocli.git
git clone --depth 1 --branch main --quiet $CLONE_URL /tmp/mokocli
cd /tmp/mokocli && composer install --no-dev --no-interaction --quiet
echo MOKO_CLI=/tmp/mokocli/cli >> $GITHUB_ENV
fi
command -v php >/dev/null || { sudo apt-get update -qq && sudo apt-get install -y -qq php-cli; }
git clone --depth 1 "https://x-access-token:${MOKOGIT_TOKEN}@git.mokoconsulting.tech/MokoConsulting/MokoCLI.git" "$RUNNER_TEMP/mokocli"
echo "MOKO_CLI=$RUNNER_TEMP/mokocli/cli" >> $GITHUB_ENV
- name: Deploy (prod)
- name: Deploy (mokocli triggers the restricted deploy pattern)
run: |
php ${MOKO_CLI}/deploy.php --tier prod --tag "${{ steps.config.outputs.tag }}" \
--ssh-host ${{ vars.PROD_SSH_HOST }} --ssh-port ${{ vars.PROD_SSH_PORT }} \
--ssh-user ${{ vars.PROD_SSH_USERNAME }} --ssh-key ~/.ssh/deploy_key
if [ -z "${{ vars.PROD_SSH_USERNAME }}" ]; then
echo "PROD_SSH_USERNAME unset — repo not onboarded to the restricted deploy pattern; skipping."
exit 0
fi
php "$MOKO_CLI/deploy.php" --tier prod --tag "${{ steps.config.outputs.tag }}" \
--ssh-host "${{ vars.PROD_SSH_HOST }}" --ssh-port "${{ vars.PROD_SSH_PORT }}" \
--ssh-user "${{ vars.PROD_SSH_USERNAME }}" --ssh-key ~/.ssh/deploy_key
+28 -46
View File
@@ -1,23 +1,17 @@
# Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
# SPDX-License-Identifier: GPL-3.0-or-later
# BRIEF: Deploy to the RC environment on push to the rc branch via the
# restricted per-repo deploy pattern. This is a THIN trigger: it only
# validates the tier+tag and hands "<tier> <tag>" to the forced-command
# deploy-mokogit user over SSH (mokocli cli/deploy.php). The server-side
# forced command sudo's to a root-owned deployer that builds, pushes,
# recreates and health-checks — the runner never builds, holds a registry
# token, or runs the health check. See `.vault system/deploy` and runbook
# 16-restricted-deploy-pattern.
# The rc branch is created by promote-rc when a PR to main opens.
# OWNER: Template-Go (canonical source; syncs to the root workflows dir). See Template-Go#3.
# NOTE: deploy-*.yml are repo-managed (per-repo deploy user + secrets/vars)
# and excluded from template sync — see mokocli workflow_sync PLATFORM_EXCLUDES['go'].
# BRIEF: Deploy to the RC environment on push to the rc branch. THIN TRIGGER —
# the deploy LOGIC lives in mokocli (cli/deploy.php) and server-side in the
# restricted per-repo deploy pattern (.vault system/deploy, runbook 16).
# This workflow validates + invokes only; it carries NO registry token and
# NO build script. A leaked DEPLOY_SSH_KEY can only redeploy this one repo.
# OWNER: Template-Go (canonical; syncs to each repo's .mokogit/workflows).
#
# Required repo VARIABLES:
# RC_SSH_HOST, RC_SSH_PORT, RC_SSH_USERNAME - SSH deploy target for the rc tier
# (RC_SSH_USERNAME = deploy-mokogit, the forced-command deploy user)
# Required SECRETS (already configured; reused, not re-set):
# DEPLOY_SSH_KEY - deploy-mokogit private key (repo secret)
# Required repo VARIABLES (tier-scoped): RC_SSH_HOST, RC_SSH_PORT, RC_SSH_USERNAME.
# Required SECRET: DEPLOY_SSH_KEY (the deploy-<repo> private key).
# ONBOARDING: a repo joins the restricted deploy pattern when RC_SSH_USERNAME is
# set to deploy-<repo>. Un-onboarded go repos skip the job (guards below), so this
# template is safe to cascade to every go repo.
name: Deploy (RC)
@@ -25,15 +19,9 @@ on:
push:
branches:
- rc
# Manual trigger for isolated end-to-end tests without a full RC promotion.
# Runs on the ref it is dispatched from; that ref must carry current source
# (>= the RC database migration version) or the rebuilt image will refuse the
# newer DB. Dispatch from `rc` once `rc` is current.
workflow_dispatch:
# No `concurrency:` block: it triggers a MokoGIT Actions run-creation bug that
# silently drops deploys on rapid pushes to the branch. Do not re-add until the
# upstream bug is confirmed fixed.
# No `concurrency:` block: triggers a MokoGIT run-creation bug that drops deploys.
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
@@ -42,6 +30,8 @@ jobs:
deploy-rc:
name: "Deploy to RC"
runs-on: ubuntu-latest
# Guard 1 (job-level): skip entirely unless onboarded.
if: ${{ vars.RC_SSH_USERNAME != '' }}
steps:
- name: Checkout source
uses: actions/checkout@v4
@@ -63,29 +53,21 @@ jobs:
echo "$DEPLOY_KEY" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
- name: Setup MokoCLI tools
- name: Set up mokocli (deploy logic)
env:
MOKO_CLONE_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
MOKO_CLONE_HOST: git.mokoconsulting.tech/MokoConsulting
MOKOGIT_TOKEN: ${{ secrets.MOKOGIT_TOKEN }}
run: |
# Use pre-installed /opt/mokocli if available (updated by cron every 6h)
if [ -f /opt/mokocli/cli/deploy.php ] && [ -f /opt/mokocli/vendor/autoload.php ]; then
echo Using pre-installed /opt/mokocli
echo MOKO_CLI=/opt/mokocli/cli >> $GITHUB_ENV
else
echo Falling back to fresh clone
if ! command -v composer > /dev/null 2>&1; then
sudo apt-get update -qq && sudo apt-get install -y -qq php-cli php-mbstring php-xml php-zip php-curl composer > /dev/null 2>&1
fi
rm -rf /tmp/mokocli
CLONE_URL=https://x-access-token:${MOKO_CLONE_TOKEN}@${MOKO_CLONE_HOST}/mokocli.git
git clone --depth 1 --branch main --quiet $CLONE_URL /tmp/mokocli
cd /tmp/mokocli && composer install --no-dev --no-interaction --quiet
echo MOKO_CLI=/tmp/mokocli/cli >> $GITHUB_ENV
fi
command -v php >/dev/null || { sudo apt-get update -qq && sudo apt-get install -y -qq php-cli; }
git clone --depth 1 "https://x-access-token:${MOKOGIT_TOKEN}@git.mokoconsulting.tech/MokoConsulting/MokoCLI.git" "$RUNNER_TEMP/mokocli"
echo "MOKO_CLI=$RUNNER_TEMP/mokocli/cli" >> $GITHUB_ENV
- name: Deploy (rc)
- name: Deploy (mokocli triggers the restricted deploy pattern)
run: |
php ${MOKO_CLI}/deploy.php --tier rc --tag "${{ steps.config.outputs.tag }}" \
--ssh-host ${{ vars.RC_SSH_HOST }} --ssh-port ${{ vars.RC_SSH_PORT }} \
--ssh-user ${{ vars.RC_SSH_USERNAME }} --ssh-key ~/.ssh/deploy_key
# Guard 2 (step-level, reliable): no-op if not onboarded.
if [ -z "${{ vars.RC_SSH_USERNAME }}" ]; then
echo "RC_SSH_USERNAME unset — repo not onboarded to the restricted deploy pattern; skipping."
exit 0
fi
php "$MOKO_CLI/deploy.php" --tier rc --tag "${{ steps.config.outputs.tag }}" \
--ssh-host "${{ vars.RC_SSH_HOST }}" --ssh-port "${{ vars.RC_SSH_PORT }}" \
--ssh-user "${{ vars.RC_SSH_USERNAME }}" --ssh-key ~/.ssh/deploy_key
+1
View File
@@ -3,6 +3,7 @@
## [Unreleased]
### Fixed
- **Update server (Joomla): serve the installable package, not the source archive** — `GenerateJoomlaXML` selected the first `.zip` attachment on a release, so releases carrying extra zips (e.g. `<repo>-<channel>-source.zip` ahead of `pkg_*.zip`) advertised the raw source archive; Joomla then downloaded a non-installable zip and failed with "Install path does not exist" (prerelease/dev channels). New `selectJoomlaArtifact()` prefers an extension-prefixed package (`pkg_`/`com_`/`mod_`/`plg_`/`tpl_`/`lib_`) and never a `-source` archive (hotfixed to prod)
- **Actions: `.mokogit/workflows` custom-path detection restored** — `WorkflowDirs` now scans `.mokogit/workflows`; the legacy `.mokogitea/workflows` is fully retired. Workflow indexing, push-triggered CI/deploys, and `workflow_dispatch` work again (#798)
- **Issue custom-status dropdown shows its options again** — the status `<select>` carried the `ui compact dropdown` class, so fomantic turned it into an overlay menu that painted behind the page content (options were present in the DOM but invisible); it is now a plain native `<select>` with its inline styles moved to a stylesheet (`web_src/css/repo/issue-status.css`)
- Restored the repo's `.mokogit/workflows/` (deploy + org CI, ~20 workflows) from Template-Go after the workflow sync had dropped them