LXC 106 deploy: merge config.json, self-update (#13) #15

Merged
jared merged 1 commits from lxc106-deploy-fix into main 2026-09-28 18:52:30 -04:00
2 changed files with 55 additions and 7 deletions
+2 -2
View File
@@ -111,7 +111,7 @@ matrix/
- Build log: `/var/log/cinny-build.log`
- Nginx site config: `/etc/nginx/sites-available/cinny` (copy in this repo: `cinny/nginx.conf`, synced with live on 2026-09-23)
- Nginx security headers: `/etc/nginx/snippets/cinny-security-headers.conf` (`cinny/nginx-security-headers.conf`). Included at server level **and** in every `location` that sets its own `add_header`; nginx drops inherited `add_header`s in such blocks, which left static assets without `nosniff` and `/sw.js` without its CSP (cinny #210). Edit the CSP here, not in the site config. **Exception:** `/public/element-call/` (the bundled Element Call, which the app itself frames) uses `cinny-security-headers-framed.conf` (`cinny/nginx-security-headers-framed.conf`), the same headers **without** the CSP. The app CSP's `frame-ancestors 'none'` would block every web call.
- ⚠️ The `matrix-deploy` hook on 106 has been unreachable since May (webhook bound to `127.0.0.1:9000`), so edits to these files in the repo are **not** auto-deployed there. Apply them by hand (`nginx -t` then `nginx -s reload`) and keep the repo copy in sync.
- The `matrix-deploy` hook on 106 is served by `webhook-lotus` on `10.10.10.6:9001` (Gitea hook → `http://10.10.10.6:9001/hooks/matrix-deploy`). It was pointed at `:9000` until 2026-09-28, which is bound to `127.0.0.1`, so nothing deployed from May to then (matrix #13). `cinny/config.json` is **merged** into the live file (server-injected values such as `gifApiKey` are kept), and the script installs its own updates (`deploy/lxc106-cinny.sh` → `/usr/local/bin/matrix-deploy.sh`).
---
@@ -132,7 +132,7 @@ Pushes to `main` on `LotusGuild/matrix` automatically deploy to the relevant LXC
| LXC | Service | IP | Port | Deploys When Changed |
|-----|---------|----|----|----------------------|
| 151 | matrix/hookshot | 10.10.10.29 | **9500** | `hookshot/*.js`, `systemd/livekit-server.service`, `livekit/voice-limit-guard.py`, `systemd/voice-limit-guard.service`, `matrixbot/*` |
| 106 | cinny | 10.10.10.6 | 9000 | `cinny/config.json`, `cinny/upstream-check.sh`, `cinny/lotus-build.sh`, `deploy/hooks-lxc106.json`, `systemd/cinny-upstream-check.cron` |
| 106 | cinny | 10.10.10.6 | 9001 | `cinny/config.json` (merged), `cinny/nginx.conf`, `cinny/upstream-check.sh`, `cinny/lotus-build.sh`, `cinny/lotus_deploy.sh`, `deploy/hooks-lxc106.json`, `deploy/lxc106-cinny.sh` (self), `systemd/cinny-upstream-check.cron` |
| 139 | landing/NPM | 10.10.10.27 | 9000 | `landing/index.html` |
| 110 | draupnir | 10.10.10.24 | 9000 | `draupnir/production.yaml` |
+53 -5
View File
@@ -3,7 +3,8 @@
# Handles: cinny/config.json, cinny/nginx.conf, cinny/upstream-check.sh,
# cinny/lotus-build.sh, cinny/lotus_deploy.sh,
# deploy/hooks-lxc106.json, systemd/cinny-upstream-check.cron
# Triggered by: Gitea webhook on push to main
# Triggered by: Gitea webhook on push to main → http://10.10.10.6:9001/hooks/matrix-deploy
# (webhook-lotus; the :9000 listener is bound to 127.0.0.1 and unreachable).
set -euo pipefail
REPO_DIR="/opt/matrix-config"
@@ -27,9 +28,39 @@ else
fi
if echo "$CHANGED" | grep -q '^cinny/config.json'; then
echo "Deploying cinny config.json..."
cp "$REPO_DIR/cinny/config.json" /var/www/html/config.json
echo "✓ config.json deployed"
echo "Deploying cinny config.json (merged: keeps server-only values)..."
# The live file carries values injected on the server that are empty in git
# (gifApiKey, set by lotus_deploy.sh from GIPHY_API_KEY). A plain copy would
# blank them, so repo keys win except where the repo value is empty and the
# live one isn't. Backup outside the web root; on any error the live file
# is left untouched.
mkdir -p /root/config-backups
cp -p /var/www/html/config.json "/root/config-backups/config.json.$(date +%Y%m%d%H%M%S)" 2>/dev/null || true
if python3 - "$REPO_DIR/cinny/config.json" /var/www/html/config.json <<'PY'
import json, os, sys, tempfile
repo_path, live_path = sys.argv[1], sys.argv[2]
repo = json.load(open(repo_path))
live = json.load(open(live_path)) if os.path.exists(live_path) else {}
merged = dict(repo)
kept = []
for key, value in live.items():
if key in repo and repo[key] in ("", None) and value not in ("", None):
merged[key] = value
kept.append(key)
fd, tmp = tempfile.mkstemp(dir=os.path.dirname(live_path))
with os.fdopen(fd, "w") as f:
json.dump(merged, f, indent=2)
f.write("\n")
json.load(open(tmp))
os.chmod(tmp, 0o644)
os.replace(tmp, live_path)
print("kept server values for: " + (", ".join(kept) or "none"))
PY
then
echo "✓ config.json deployed"
else
echo "✗ config.json merge FAILED — live file left unchanged"
fi
fi
if echo "$CHANGED" | grep -q '^cinny/nginx.conf'; then
@@ -80,7 +111,11 @@ if echo "$CHANGED" | grep -q '^deploy/hooks-lxc106.json'; then
echo "Deploying hooks-lxc106.json..."
cp "$REPO_DIR/deploy/hooks-lxc106.json" /etc/webhook/hooks.json
systemctl restart webhook
echo "✓ hooks.json deployed, webhook restarted"
# webhook-lotus (:9001) serves the same hooks and is the one running THIS
# script (Gitea posts matrix-deploy there), so restarting it now would kill
# this deploy mid-run: restart it shortly after we exit instead.
systemd-run --on-active=15s --unit="webhook-lotus-reload-$(date +%s)" systemctl restart webhook-lotus
echo "✓ hooks.json deployed, webhook restarted (webhook-lotus in 15s)"
fi
if echo "$CHANGED" | grep -q '^systemd/cinny-upstream-check.cron'; then
@@ -90,4 +125,17 @@ if echo "$CHANGED" | grep -q '^systemd/cinny-upstream-check.cron'; then
echo "✓ cron deployed"
fi
# Keep the installed copy of this script in step with the repo (the webhook
# runs /usr/local/bin/matrix-deploy.sh, not the repo file). Checked with bash -n
# first; takes effect from the next deploy.
if echo "$CHANGED" | grep -q '^deploy/lxc106-cinny.sh'; then
if bash -n "$REPO_DIR/deploy/lxc106-cinny.sh"; then
cp "$REPO_DIR/deploy/lxc106-cinny.sh" /usr/local/bin/matrix-deploy.sh
chmod +x /usr/local/bin/matrix-deploy.sh
echo "✓ matrix-deploy.sh updated"
else
echo "✗ bash -n FAILED on lxc106-cinny.sh — keeping the installed copy"
fi
fi
echo "=== $(date) === LXC106 deploy complete ==="