name: Deploy on: push: branches: [master] jobs: deploy: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v4 - name: Build (frontend + API via make) run: make web server - name: Deploy to box run: | mkdir -p ~/apps/hub/dist ~/apps/hub/scripts ~/apps/hub/docs cp bin/hub-api ~/apps/hub/hub-api.new mv -f ~/apps/hub/hub-api.new ~/apps/hub/hub-api chmod +x ~/apps/hub/hub-api cp config.yaml ~/apps/hub/config.yaml cp -r scripts/. ~/apps/hub/scripts/ cp -r dist/. ~/apps/hub/dist/ chmod +x ~/apps/hub/hub-api ~/apps/hub/scripts/* systemctl --user restart hub-api - name: Notify ok if: success() env: WH_URL: ${{ secrets.WH_URL }} WH_SECRET: ${{ secrets.WH_SECRET }} REF: ${{ github.ref_name }} run: | BODY="$(jq -nc --arg t "✅ ${{ github.repository }}: деплой прошёл ($REF)" '{text:$t}')" SIG="$(printf %s "$BODY" | openssl dgst -sha256 -hmac "$WH_SECRET" | awk '{print $2}')" curl -fsS -X POST "$WH_URL" -H "Content-Type: application/json" \ -H "X-Hub-Signature-256: sha256=$SIG" -d "$BODY" - name: Notify fail if: failure() env: WH_URL: ${{ secrets.WH_URL }} WH_SECRET: ${{ secrets.WH_SECRET }} REF: ${{ github.ref_name }} run: | BODY="$(jq -nc --arg t "❌ ${{ github.repository }}: деплой наебнулся ($REF)" '{text:$t}')" SIG="$(printf %s "$BODY" | openssl dgst -sha256 -hmac "$WH_SECRET" | awk '{print $2}')" curl -fsS -X POST "$WH_URL" -H "Content-Type: application/json" \ -H "X-Hub-Signature-256: sha256=$SIG" -d "$BODY"