LXC 106 deploy: merge config.json, self-update (#13) #15

Merged
jared merged 1 commits from lxc106-deploy-fix into main 2026-09-28 18:52:30 -04:00
Owner

Fixes the deploy side of #13 (LXC 106 auto-deploy dead since May).

Cause: Gitea hook 73 posts to http://10.10.10.6:9000/hooks/matrix-deploy, but webhook.service on LXC 106 binds 127.0.0.1:9000, so every delivery is refused. The same hooks, with the same secret, are served by webhook-lotus on :9001, which is reachable and already handles the cinny repo's lotus-deploy hook. The Gitea hook gets re-pointed there after this merges and the script is installed.

Why the script must change first: the first delivery would install everything changed since May, including cinny/config.json. A plain cp would blank the live gifApiKey, which is injected on the server and empty in git.

Changes:

  • config.json is merged, not copied. Repo values win, except empty repo values where the live one is set. There's a backup in /root/config-backups, and the live file is untouched on error. Tested with the repo config against a live-style file: the key is kept and everything else matches the repo. Invalid JSON exits 1 and leaves the live file untouched.
  • The script updates its own installed copy (/usr/local/bin/matrix-deploy.sh, after bash -n).
  • A hooks.json change restarts webhook-lotus 15 s after the script exits, because that listener is the one running the script.
  • README: the port, the deployed files, and the history.

This PR is also the first merge under the fixed branch protection from #14 (required checks Lint / *).

🤖 Generated with Claude Code

https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA

Fixes the deploy side of **#13** (LXC 106 auto-deploy dead since May). **Cause:** Gitea hook 73 posts to `http://10.10.10.6:9000/hooks/matrix-deploy`, but `webhook.service` on LXC 106 binds `127.0.0.1:9000`, so every delivery is refused. The same hooks, with the same secret, are served by `webhook-lotus` on `:9001`, which is reachable and already handles the cinny repo's `lotus-deploy` hook. The Gitea hook gets re-pointed there **after** this merges and the script is installed. **Why the script must change first:** the first delivery would install everything changed since May, including `cinny/config.json`. A plain `cp` would blank the live `gifApiKey`, which is injected on the server and empty in git. **Changes:** - **`config.json` is merged, not copied.** Repo values win, except empty repo values where the live one is set. There's a backup in `/root/config-backups`, and the live file is untouched on error. Tested with the repo config against a live-style file: the key is kept and everything else matches the repo. Invalid JSON exits 1 and leaves the live file untouched. - **The script updates its own installed copy** (`/usr/local/bin/matrix-deploy.sh`, after `bash -n`). - **A `hooks.json` change restarts `webhook-lotus` 15 s after the script exits,** because that listener is the one running the script. - **README:** the port, the deployed files, and the history. This PR is also the first merge under the fixed branch protection from **#14** (required checks `Lint / *`). 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
jared added 1 commit 2026-09-28 18:48:14 -04:00
fix(lxc106): deploy script merges config.json and updates itself (#13)
Lint / Shell (shellcheck) (push) Successful in 31s
Lint / JS (eslint) (push) Successful in 5s
Lint / No secrets in webhook configs (push) Successful in 4s
Lint / Landing page is rendered (matrix (push) Successful in 6s
Lint / Python (ruff) (push) Successful in 8s
Lint / Python deps (pip-audit) (push) Successful in 1m2s
Lint / Secret scan (gitleaks) (push) Successful in 10s
Lint / Shell (shellcheck) (pull_request) Successful in 12s
Lint / JS (eslint) (pull_request) Successful in 12s
Lint / No secrets in webhook configs (pull_request) Successful in 8s
Lint / Landing page is rendered (matrix (pull_request) Successful in 8s
Lint / Python (ruff) (pull_request) Successful in 8s
Lint / Python deps (pip-audit) (pull_request) Successful in 1m15s
Lint / Secret scan (gitleaks) (pull_request) Successful in 12s
8d47df711d
LXC 106's matrix-deploy hook has not fired since May: Gitea posts to
10.10.10.6:9000, which webhook.service binds to 127.0.0.1. The same hooks
(same secret) are served by webhook-lotus on :9001; the Gitea hook is being
re-pointed there. Before it starts firing again:

- cinny/config.json is merged into the live file instead of copied over it.
  The live file carries gifApiKey (injected by lotus_deploy.sh), empty in
  git, which a copy would blank. Repo keys win except where the repo value is
  empty and the live one isn't. Backup goes to /root/config-backups; the live
  file is left untouched on error.
- The script installs its own updates (deploy/lxc106-cinny.sh →
  /usr/local/bin/matrix-deploy.sh, after bash -n). Until now repo edits to
  it never reached the server.
- A hooks.json change restarts webhook-lotus 15 s after the script exits,
  since that listener is the one running this script.
- README: port 9001, the file list, and the history.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
jared merged commit d76d276da4 into main 2026-09-28 18:52:30 -04:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: LotusGuild/matrix#15