name: Build & Deploy on: push: branches: - main jobs: deploy: runs-on: ubuntu-latest # ← FIX: Offizieller Runner, Docker ist vorinstalliert steps: # --- Checkout --- - name: Checkout repo uses: actions/checkout@v4 # ← Update auf v4 # --- Login to registry --- - name: Login to registry env: REGISTRY_USER: ${{ secrets.REGISTRY_USER }} REGISTRY_PASS: ${{ secrets.REGISTRY_PASS }} run: | echo "$REGISTRY_PASS" | docker login registry.infra.mintel.me \ -u "$REGISTRY_USER" \ --password-stdin # --- Build image --- - name: Build image run: | docker build \ --pull \ --build-arg NEXT_PUBLIC_UMAMI_WEBSITE_ID=${{ secrets.NEXT_PUBLIC_UMAMI_WEBSITE_ID }} \ --build-arg NEXT_PUBLIC_UMAMI_SCRIPT_URL=${{ secrets.NEXT_PUBLIC_UMAMI_SCRIPT_URL }} \ --build-arg NEXT_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }} \ -t registry.infra.mintel.me/mintel/klz-cables.com:latest . # --- Push image --- - name: Push image run: docker push registry.infra.mintel.me/mintel/klz-cables.com:latest # --- SSH setup --- - name: Setup SSH run: | mkdir -p ~/.ssh echo "${{ secrets.ALPHA_SSH_KEY }}" > ~/.ssh/id_ed25519 chmod 600 ~/.ssh/id_ed25519 ssh-keyscan -H alpha.mintel.me >> ~/.ssh/known_hosts # --- Sync files --- - name: Sync files to server run: | tar czf - docker-compose.yml | \ ssh -i ~/.ssh/id_ed25519 -o StrictHostKeyChecking=no deploy@alpha.mintel.me \ "mkdir -p /home/deploy/sites/klz-cables.com/ && tar xzf - -C /home/deploy/sites/klz-cables.com/" # --- Deploy --- - name: Deploy on server env: REGISTRY_USER: ${{ secrets.REGISTRY_USER }} REGISTRY_PASS: ${{ secrets.REGISTRY_PASS }} run: | ssh -i ~/.ssh/id_ed25519 -o StrictHostKeyChecking=no deploy@alpha.mintel.me " set -e echo '$REGISTRY_PASS' | docker login registry.infra.mintel.me -u '$REGISTRY_USER' --password-stdin cd /home/deploy/sites/klz-cables.com echo 'SENTRY_DSN=${{ secrets.SENTRY_DSN }}' > .env docker compose pull app docker compose up -d --force-recreate --no-deps app docker image prune -f --filter 'until=24h' docker compose ps app docker compose logs --tail=20 app "