LXC 106 deploy: merge config.json, self-update (#13) #15
@@ -111,7 +111,7 @@ matrix/
|
||||
- Build log: `/var/log/cinny-build.log`
|
||||
- Nginx site config: `/etc/nginx/sites-available/cinny` (copy in this repo: `cinny/nginx.conf`, synced with live on 2026-09-23)
|
||||
- Nginx security headers: `/etc/nginx/snippets/cinny-security-headers.conf` (`cinny/nginx-security-headers.conf`). Included at server level **and** in every `location` that sets its own `add_header`; nginx drops inherited `add_header`s in such blocks, which left static assets without `nosniff` and `/sw.js` without its CSP (cinny #210). Edit the CSP here, not in the site config. **Exception:** `/public/element-call/` (the bundled Element Call, which the app itself frames) uses `cinny-security-headers-framed.conf` (`cinny/nginx-security-headers-framed.conf`), the same headers **without** the CSP. The app CSP's `frame-ancestors 'none'` would block every web call.
|
||||
- ⚠️ The `matrix-deploy` hook on 106 has been unreachable since May (webhook bound to `127.0.0.1:9000`), so edits to these files in the repo are **not** auto-deployed there. Apply them by hand (`nginx -t` then `nginx -s reload`) and keep the repo copy in sync.
|
||||
- The `matrix-deploy` hook on 106 is served by `webhook-lotus` on `10.10.10.6:9001` (Gitea hook → `http://10.10.10.6:9001/hooks/matrix-deploy`). It was pointed at `:9000` until 2026-09-28, which is bound to `127.0.0.1`, so nothing deployed from May to then (matrix #13). `cinny/config.json` is **merged** into the live file (server-injected values such as `gifApiKey` are kept), and the script installs its own updates (`deploy/lxc106-cinny.sh` → `/usr/local/bin/matrix-deploy.sh`).
|
||||
|
||||
---
|
||||
|
||||
@@ -132,7 +132,7 @@ Pushes to `main` on `LotusGuild/matrix` automatically deploy to the relevant LXC
|
||||
| LXC | Service | IP | Port | Deploys When Changed |
|
||||
|-----|---------|----|----|----------------------|
|
||||
| 151 | matrix/hookshot | 10.10.10.29 | **9500** | `hookshot/*.js`, `systemd/livekit-server.service`, `livekit/voice-limit-guard.py`, `systemd/voice-limit-guard.service`, `matrixbot/*` |
|
||||
| 106 | cinny | 10.10.10.6 | 9000 | `cinny/config.json`, `cinny/upstream-check.sh`, `cinny/lotus-build.sh`, `deploy/hooks-lxc106.json`, `systemd/cinny-upstream-check.cron` |
|
||||
| 106 | cinny | 10.10.10.6 | 9001 | `cinny/config.json` (merged), `cinny/nginx.conf`, `cinny/upstream-check.sh`, `cinny/lotus-build.sh`, `cinny/lotus_deploy.sh`, `deploy/hooks-lxc106.json`, `deploy/lxc106-cinny.sh` (self), `systemd/cinny-upstream-check.cron` |
|
||||
| 139 | landing/NPM | 10.10.10.27 | 9000 | `landing/index.html` |
|
||||
| 110 | draupnir | 10.10.10.24 | 9000 | `draupnir/production.yaml` |
|
||||
|
||||
|
||||
+53
-5
@@ -3,7 +3,8 @@
|
||||
# Handles: cinny/config.json, cinny/nginx.conf, cinny/upstream-check.sh,
|
||||
# cinny/lotus-build.sh, cinny/lotus_deploy.sh,
|
||||
# deploy/hooks-lxc106.json, systemd/cinny-upstream-check.cron
|
||||
# Triggered by: Gitea webhook on push to main
|
||||
# Triggered by: Gitea webhook on push to main → http://10.10.10.6:9001/hooks/matrix-deploy
|
||||
# (webhook-lotus; the :9000 listener is bound to 127.0.0.1 and unreachable).
|
||||
set -euo pipefail
|
||||
|
||||
REPO_DIR="/opt/matrix-config"
|
||||
@@ -27,9 +28,39 @@ else
|
||||
fi
|
||||
|
||||
if echo "$CHANGED" | grep -q '^cinny/config.json'; then
|
||||
echo "Deploying cinny config.json..."
|
||||
cp "$REPO_DIR/cinny/config.json" /var/www/html/config.json
|
||||
echo "✓ config.json deployed"
|
||||
echo "Deploying cinny config.json (merged: keeps server-only values)..."
|
||||
# The live file carries values injected on the server that are empty in git
|
||||
# (gifApiKey, set by lotus_deploy.sh from GIPHY_API_KEY). A plain copy would
|
||||
# blank them, so repo keys win except where the repo value is empty and the
|
||||
# live one isn't. Backup outside the web root; on any error the live file
|
||||
# is left untouched.
|
||||
mkdir -p /root/config-backups
|
||||
cp -p /var/www/html/config.json "/root/config-backups/config.json.$(date +%Y%m%d%H%M%S)" 2>/dev/null || true
|
||||
if python3 - "$REPO_DIR/cinny/config.json" /var/www/html/config.json <<'PY'
|
||||
import json, os, sys, tempfile
|
||||
repo_path, live_path = sys.argv[1], sys.argv[2]
|
||||
repo = json.load(open(repo_path))
|
||||
live = json.load(open(live_path)) if os.path.exists(live_path) else {}
|
||||
merged = dict(repo)
|
||||
kept = []
|
||||
for key, value in live.items():
|
||||
if key in repo and repo[key] in ("", None) and value not in ("", None):
|
||||
merged[key] = value
|
||||
kept.append(key)
|
||||
fd, tmp = tempfile.mkstemp(dir=os.path.dirname(live_path))
|
||||
with os.fdopen(fd, "w") as f:
|
||||
json.dump(merged, f, indent=2)
|
||||
f.write("\n")
|
||||
json.load(open(tmp))
|
||||
os.chmod(tmp, 0o644)
|
||||
os.replace(tmp, live_path)
|
||||
print("kept server values for: " + (", ".join(kept) or "none"))
|
||||
PY
|
||||
then
|
||||
echo "✓ config.json deployed"
|
||||
else
|
||||
echo "✗ config.json merge FAILED — live file left unchanged"
|
||||
fi
|
||||
fi
|
||||
|
||||
if echo "$CHANGED" | grep -q '^cinny/nginx.conf'; then
|
||||
@@ -80,7 +111,11 @@ if echo "$CHANGED" | grep -q '^deploy/hooks-lxc106.json'; then
|
||||
echo "Deploying hooks-lxc106.json..."
|
||||
cp "$REPO_DIR/deploy/hooks-lxc106.json" /etc/webhook/hooks.json
|
||||
systemctl restart webhook
|
||||
echo "✓ hooks.json deployed, webhook restarted"
|
||||
# webhook-lotus (:9001) serves the same hooks and is the one running THIS
|
||||
# script (Gitea posts matrix-deploy there), so restarting it now would kill
|
||||
# this deploy mid-run: restart it shortly after we exit instead.
|
||||
systemd-run --on-active=15s --unit="webhook-lotus-reload-$(date +%s)" systemctl restart webhook-lotus
|
||||
echo "✓ hooks.json deployed, webhook restarted (webhook-lotus in 15s)"
|
||||
fi
|
||||
|
||||
if echo "$CHANGED" | grep -q '^systemd/cinny-upstream-check.cron'; then
|
||||
@@ -90,4 +125,17 @@ if echo "$CHANGED" | grep -q '^systemd/cinny-upstream-check.cron'; then
|
||||
echo "✓ cron deployed"
|
||||
fi
|
||||
|
||||
# Keep the installed copy of this script in step with the repo (the webhook
|
||||
# runs /usr/local/bin/matrix-deploy.sh, not the repo file). Checked with bash -n
|
||||
# first; takes effect from the next deploy.
|
||||
if echo "$CHANGED" | grep -q '^deploy/lxc106-cinny.sh'; then
|
||||
if bash -n "$REPO_DIR/deploy/lxc106-cinny.sh"; then
|
||||
cp "$REPO_DIR/deploy/lxc106-cinny.sh" /usr/local/bin/matrix-deploy.sh
|
||||
chmod +x /usr/local/bin/matrix-deploy.sh
|
||||
echo "✓ matrix-deploy.sh updated"
|
||||
else
|
||||
echo "✗ bash -n FAILED on lxc106-cinny.sh — keeping the installed copy"
|
||||
fi
|
||||
fi
|
||||
|
||||
echo "=== $(date) === LXC106 deploy complete ==="
|
||||
|
||||
Reference in New Issue
Block a user