Skip to content

CI/CD: GitHub Actions CI + pull-based CD on seed-SER9 - #5

Merged
Arismemo merged 1 commit into
mainfrom
ci-cd
Sep 25, 2026
Merged

Arismemo merged 1 commit into
mainfrom
ci-cd

Conversation

@Arismemo

Copy link
Copy Markdown
Owner

What

  • CI (.github/workflows/ci.yml): every PR and push to main runs check (lint, UI tests, build, server tests) and docker (build image, start it, smoke /healthz, /, /docs = 200 and /api/skills = 401).
  • CD (deploy/cd/): a systemd user timer on seed-SER9 polls main every 2 minutes and deploys only commits whose check and docker runs succeeded — backup → build ash:<sha> → swap compose image tag → smoke → automatic rollback on failure. Status is reported to GitHub Deployments (production).
  • docs/deploy.md: CI/CD becomes the standard path; the manual five steps stay as the fallback.

Why pull-based

The repo is public, so a self-hosted runner on the production host would let fork PRs run code there. The host only pulls and only deploys CI-green main.

Verified

Rehearsed on a staging container (ash-staging, port 19555) with a copy of production data:

  • deploy 9a33fd5 → 6a620d1: backup, build, switch, smoke (53 skills before/after) in 18 s
  • deploying a pre-auth build: smoke caught /api/skills ≠ 401 and rolled back automatically
  • ash-cd rollback and ash-cd poll (waits while CI is pending)

Production was not touched.

🤖 Generated with Claude Code

CI (.github/workflows/ci.yml), on every PR and push to main:
- check: npm ci, lint, UI tests, build, server tests
- docker: build the image, start it, smoke /healthz, /, /docs (200)
  and /api/skills (401 without login)

CD (deploy/cd/ash-cd.sh + systemd user timer, every 2 min):
- deploys main only when its "check" and "docker" runs succeeded
- backup DB + skills_files, git archive from its own mirror, build
  ash:<sha>, derive compose by swapping only the image tag, switch
- smoke: /healthz, /, /docs 200, /api/skills 401, skill count unchanged,
  no migration/uncaught errors in logs; public /healthz only warns
- automatic rollback on smoke failure; failed commits are never retried
- reports to GitHub Deployments (production); keeps the last 10 images
- manual: ash-cd status | deploy <sha> [--force] | rollback [<tag>]
- pull-based on purpose: the repo is public, so no self-hosted runner

Rehearsed end to end on a staging container with a copy of production
data: deploy, smoke-failure rollback, manual rollback, poll-waits-for-CI.

docs/deploy.md: CI/CD is now the standard path; the manual five steps
remain as the fallback.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Arismemo
Arismemo merged commit 14d8a6c into main Sep 25, 2026
2 checks passed
@Arismemo
Arismemo deleted the ci-cd branch September 25, 2026 07:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant