Pinned 2026 toolchains (Go 1.26, Rust 1.98/edition 2024, Python 3.14 + uv, Node 24, Zig 0.16, NixOS 26.05), postgres 18 / mongo 8, lockfiles built from, non-root runtimes, .dockerignore, per-project LICENSE, READMEs with the git.devai.io clone line, checkout@v7 CI. Security fixes in the legacy Rust APIs (any-password login, self-assigned admin, hard-coded JWT secret), JWT alg/exp/sub enforcement across the blog series, safe markdown links in the frontends, and many smaller bugs — every project was built, run and exercised end to end. Adds scripts/publish.sh + a CI publish job that splits every folder into its own repo at git.devai.io/templates/<folder>. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01128fhuZbgivaSJvtMf4s1G
40 lines
1.2 KiB
YAML
40 lines
1.2 KiB
YAML
name: ci
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
test:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- run: docker compose up -d --build
|
|
- run: |
|
|
timeout 60 sh -c 'until curl -fs localhost:8080/; do sleep 2; done' \
|
|
|| { docker compose logs; exit 1; }
|
|
- run: docker compose down
|
|
|
|
publish:
|
|
needs: test
|
|
if: github.ref == 'refs/heads/main'
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
packages: write
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- run: echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u "${{ github.actor }}" --password-stdin
|
|
- run: docker build -t "ghcr.io/${{ github.repository }}:latest" .
|
|
- run: docker push "ghcr.io/${{ github.repository }}:latest"
|
|
|
|
deploy:
|
|
needs: publish
|
|
if: github.ref == 'refs/heads/main' && vars.DEPLOY_HOST != ''
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- run: |
|
|
install -m 600 /dev/null key && echo "${{ secrets.DEPLOY_KEY }}" > key
|
|
ssh -i key -o StrictHostKeyChecking=accept-new \
|
|
"${{ vars.DEPLOY_USER }}@${{ vars.DEPLOY_HOST }}" \
|
|
"cd /srv/random-quote && git pull --ff-only && docker compose up -d --build"
|