From 8d47df711df0fbea9f06f00f073b5d3f10fa0e38 Mon Sep 17 00:00:00 2001 From: Lotus CI Date: Mon, 28 Sep 2026 18:47:49 -0400 Subject: [PATCH] fix(lxc106): deploy script merges config.json and updates itself (#13) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit LXC 106's matrix-deploy hook has not fired since May: Gitea posts to 10.10.10.6:9000, which webhook.service binds to 127.0.0.1. The same hooks (same secret) are served by webhook-lotus on :9001; the Gitea hook is being re-pointed there. Before it starts firing again: - cinny/config.json is merged into the live file instead of copied over it. The live file carries gifApiKey (injected by lotus_deploy.sh), empty in git, which a copy would blank. Repo keys win except where the repo value is empty and the live one isn't. Backup goes to /root/config-backups; the live file is left untouched on error. - The script installs its own updates (deploy/lxc106-cinny.sh → /usr/local/bin/matrix-deploy.sh, after bash -n). Until now repo edits to it never reached the server. - A hooks.json change restarts webhook-lotus 15 s after the script exits, since that listener is the one running this script. - README: port 9001, the file list, and the history. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA --- README.md | 4 +-- deploy/lxc106-cinny.sh | 58 ++++++++++++++++++++++++++++++++++++++---- 2 files changed, 55 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index 65984b1..7c70da0 100644 --- a/README.md +++ b/README.md @@ -111,7 +111,7 @@ matrix/ - Build log: `/var/log/cinny-build.log` - Nginx site config: `/etc/nginx/sites-available/cinny` (copy in this repo: `cinny/nginx.conf`, synced with live on 2026-09-23) - Nginx security headers: `/etc/nginx/snippets/cinny-security-headers.conf` (`cinny/nginx-security-headers.conf`). Included at server level **and** in every `location` that sets its own `add_header`; nginx drops inherited `add_header`s in such blocks, which left static assets without `nosniff` and `/sw.js` without its CSP (cinny #210). Edit the CSP here, not in the site config. **Exception:** `/public/element-call/` (the bundled Element Call, which the app itself frames) uses `cinny-security-headers-framed.conf` (`cinny/nginx-security-headers-framed.conf`), the same headers **without** the CSP. The app CSP's `frame-ancestors 'none'` would block every web call. -- ⚠️ The `matrix-deploy` hook on 106 has been unreachable since May (webhook bound to `127.0.0.1:9000`), so edits to these files in the repo are **not** auto-deployed there. Apply them by hand (`nginx -t` then `nginx -s reload`) and keep the repo copy in sync. +- The `matrix-deploy` hook on 106 is served by `webhook-lotus` on `10.10.10.6:9001` (Gitea hook → `http://10.10.10.6:9001/hooks/matrix-deploy`). It was pointed at `:9000` until 2026-09-28, which is bound to `127.0.0.1`, so nothing deployed from May to then (matrix #13). `cinny/config.json` is **merged** into the live file (server-injected values such as `gifApiKey` are kept), and the script installs its own updates (`deploy/lxc106-cinny.sh` → `/usr/local/bin/matrix-deploy.sh`). --- @@ -132,7 +132,7 @@ Pushes to `main` on `LotusGuild/matrix` automatically deploy to the relevant LXC | LXC | Service | IP | Port | Deploys When Changed | |-----|---------|----|----|----------------------| | 151 | matrix/hookshot | 10.10.10.29 | **9500** | `hookshot/*.js`, `systemd/livekit-server.service`, `livekit/voice-limit-guard.py`, `systemd/voice-limit-guard.service`, `matrixbot/*` | -| 106 | cinny | 10.10.10.6 | 9000 | `cinny/config.json`, `cinny/upstream-check.sh`, `cinny/lotus-build.sh`, `deploy/hooks-lxc106.json`, `systemd/cinny-upstream-check.cron` | +| 106 | cinny | 10.10.10.6 | 9001 | `cinny/config.json` (merged), `cinny/nginx.conf`, `cinny/upstream-check.sh`, `cinny/lotus-build.sh`, `cinny/lotus_deploy.sh`, `deploy/hooks-lxc106.json`, `deploy/lxc106-cinny.sh` (self), `systemd/cinny-upstream-check.cron` | | 139 | landing/NPM | 10.10.10.27 | 9000 | `landing/index.html` | | 110 | draupnir | 10.10.10.24 | 9000 | `draupnir/production.yaml` | diff --git a/deploy/lxc106-cinny.sh b/deploy/lxc106-cinny.sh index 68fe51f..1205313 100644 --- a/deploy/lxc106-cinny.sh +++ b/deploy/lxc106-cinny.sh @@ -3,7 +3,8 @@ # Handles: cinny/config.json, cinny/nginx.conf, cinny/upstream-check.sh, # cinny/lotus-build.sh, cinny/lotus_deploy.sh, # deploy/hooks-lxc106.json, systemd/cinny-upstream-check.cron -# Triggered by: Gitea webhook on push to main +# Triggered by: Gitea webhook on push to main → http://10.10.10.6:9001/hooks/matrix-deploy +# (webhook-lotus; the :9000 listener is bound to 127.0.0.1 and unreachable). set -euo pipefail REPO_DIR="/opt/matrix-config" @@ -27,9 +28,39 @@ else fi if echo "$CHANGED" | grep -q '^cinny/config.json'; then - echo "Deploying cinny config.json..." - cp "$REPO_DIR/cinny/config.json" /var/www/html/config.json - echo "✓ config.json deployed" + echo "Deploying cinny config.json (merged: keeps server-only values)..." + # The live file carries values injected on the server that are empty in git + # (gifApiKey, set by lotus_deploy.sh from GIPHY_API_KEY). A plain copy would + # blank them, so repo keys win except where the repo value is empty and the + # live one isn't. Backup outside the web root; on any error the live file + # is left untouched. + mkdir -p /root/config-backups + cp -p /var/www/html/config.json "/root/config-backups/config.json.$(date +%Y%m%d%H%M%S)" 2>/dev/null || true + if python3 - "$REPO_DIR/cinny/config.json" /var/www/html/config.json <<'PY' +import json, os, sys, tempfile +repo_path, live_path = sys.argv[1], sys.argv[2] +repo = json.load(open(repo_path)) +live = json.load(open(live_path)) if os.path.exists(live_path) else {} +merged = dict(repo) +kept = [] +for key, value in live.items(): + if key in repo and repo[key] in ("", None) and value not in ("", None): + merged[key] = value + kept.append(key) +fd, tmp = tempfile.mkstemp(dir=os.path.dirname(live_path)) +with os.fdopen(fd, "w") as f: + json.dump(merged, f, indent=2) + f.write("\n") +json.load(open(tmp)) +os.chmod(tmp, 0o644) +os.replace(tmp, live_path) +print("kept server values for: " + (", ".join(kept) or "none")) +PY + then + echo "✓ config.json deployed" + else + echo "✗ config.json merge FAILED — live file left unchanged" + fi fi if echo "$CHANGED" | grep -q '^cinny/nginx.conf'; then @@ -80,7 +111,11 @@ if echo "$CHANGED" | grep -q '^deploy/hooks-lxc106.json'; then echo "Deploying hooks-lxc106.json..." cp "$REPO_DIR/deploy/hooks-lxc106.json" /etc/webhook/hooks.json systemctl restart webhook - echo "✓ hooks.json deployed, webhook restarted" + # webhook-lotus (:9001) serves the same hooks and is the one running THIS + # script (Gitea posts matrix-deploy there), so restarting it now would kill + # this deploy mid-run: restart it shortly after we exit instead. + systemd-run --on-active=15s --unit="webhook-lotus-reload-$(date +%s)" systemctl restart webhook-lotus + echo "✓ hooks.json deployed, webhook restarted (webhook-lotus in 15s)" fi if echo "$CHANGED" | grep -q '^systemd/cinny-upstream-check.cron'; then @@ -90,4 +125,17 @@ if echo "$CHANGED" | grep -q '^systemd/cinny-upstream-check.cron'; then echo "✓ cron deployed" fi +# Keep the installed copy of this script in step with the repo (the webhook +# runs /usr/local/bin/matrix-deploy.sh, not the repo file). Checked with bash -n +# first; takes effect from the next deploy. +if echo "$CHANGED" | grep -q '^deploy/lxc106-cinny.sh'; then + if bash -n "$REPO_DIR/deploy/lxc106-cinny.sh"; then + cp "$REPO_DIR/deploy/lxc106-cinny.sh" /usr/local/bin/matrix-deploy.sh + chmod +x /usr/local/bin/matrix-deploy.sh + echo "✓ matrix-deploy.sh updated" + else + echo "✗ bash -n FAILED on lxc106-cinny.sh — keeping the installed copy" + fi +fi + echo "=== $(date) === LXC106 deploy complete ===" -- 2.47.3