Files
pezkuwichain 9e3844fd89 ci: deploy each function to the project that actually serves it
The functions in this repo do not all live in the same place, and the deploy
step I added yesterday sent all of them to the self-hosted host on vps3.

telegram-bot and ask are served from the cloud project vbhftvdayqfmcgmzdxfv.
Both Telegram bots reach it by webhook — ?bot=krd is @pezkuwichainBot and
?bot=dks is @DKSKurdistanBot — and news.pex.mom's assistant calls ask there.
Copies of both still sit in the vps3 volume from before that split, holding a
bot token revoked on 2026-07-19, and take no traffic. Deploying to vps3 was
therefore updating a dead copy while the live one kept running old code.

So the self-hosted job now excludes those two, and a second job deploys them to
the cloud project. That closes a real gap: they had been deployed by hand for
months, and git drifted far enough behind that on 2026-07-21 the running
function body had to be extracted from the deployed bundle to recover it.

The host registry records the split too, so the gate cannot be pointed at the
wrong target by accident.
2026-07-30 02:02:28 -07:00

143 lines
4.9 KiB
YAML

name: Deploy
on:
workflow_run:
workflows: ["CI"]
types: [completed]
branches: [main]
workflow_dispatch:
concurrency:
group: deploy
cancel-in-progress: true
env:
VITE_SUPABASE_URL: ${{ secrets.VITE_SUPABASE_URL }}
VITE_SUPABASE_ANON_KEY: ${{ secrets.VITE_SUPABASE_ANON_KEY }}
VITE_DEPOSIT_TON_ADDRESS: ${{ secrets.VITE_DEPOSIT_TON_ADDRESS }}
VITE_DEPOSIT_POLKADOT_ADDRESS: ${{ secrets.VITE_DEPOSIT_POLKADOT_ADDRESS }}
jobs:
deploy:
name: Deploy to VPS
runs-on: ubuntu-latest
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
- run: npm ci
- run: npm run build
# VPS1 (telegram.pezkuwichain.io) is currently running Zagros testnet - deployed manually
# Re-enable this step when testnet period is over
# - name: Deploy to telegram.pezkuwichain.io
# uses: appleboy/scp-action@v1.0.0
# with:
# host: ${{ secrets.VPS1_HOST }}
# username: ${{ secrets.VPS1_USER }}
# key: ${{ secrets.VPS1_SSH_KEY }}
# source: 'dist/*'
# target: '/var/www/telegram.pezkuwichain.io'
# strip_components: 1
- name: Deploy to telegram.pezkiwi.app
uses: appleboy/scp-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
source: 'dist/*'
target: '/var/www/telegram.pezkiwi.app'
strip_components: 1
- name: Cleanup old assets on VPS
uses: appleboy/ssh-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
script: bash /opt/cleanup-miniapp.sh
# Edge functions live in a Supabase volume shared with other projects, so they
# are written through the ownership gate on the host rather than copied in
# directly. The gate refuses any name this project does not own, which is what
# stops a repeat of the 2026-06-28 incident where another project's deploy
# silently replaced telegram-auth and broke sign-in for a month.
deploy-functions:
name: Deploy edge functions (self-hosted)
needs: deploy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# telegram-bot and ask are excluded on purpose: both Telegram bots and the
# news.pex.mom assistant are served from the cloud project, not from here.
# Stale copies of both still sit in this volume from before that split and
# take no traffic. They are deployed by the deploy-cloud-functions job.
- name: Package functions
run: |
tar czf functions.tgz -C supabase \
--exclude='functions/telegram-bot' \
--exclude='functions/ask' \
functions
- name: Copy to staging on VPS
uses: appleboy/scp-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
source: 'functions.tgz'
target: '/opt/miniapp-deploy-staging'
- name: Deploy through ownership gate
uses: appleboy/ssh-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
script: |
set -e
BASE=/opt/miniapp-deploy-staging
trap 'rm -rf "$BASE"' EXIT
rm -rf "$BASE/functions"
tar xzf "$BASE/functions.tgz" -C "$BASE"
supabase-deploy-functions \
--project pezkuwi-telegram-miniapp \
--src "$BASE/functions" \
--restart
# The two Telegram bots and the news.pex.mom assistant run on the cloud
# Supabase project, reached by webhook at
# vbhftvdayqfmcgmzdxfv.supabase.co/functions/v1/telegram-bot?bot=krd|dks.
# These were deployed by hand for months, which let the source in git drift
# behind what was actually running — badly enough that on 2026-07-21 the live
# function body had to be pulled back out of the deployed bundle to recover it.
deploy-cloud-functions:
name: Deploy edge functions (cloud)
needs: deploy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Deploy telegram-bot and ask
env:
SUPABASE_ACCESS_TOKEN: ${{ secrets.SUPABASE_ACCESS_TOKEN }}
run: |
set -e
if [ -z "$SUPABASE_ACCESS_TOKEN" ]; then
echo "::error::SUPABASE_ACCESS_TOKEN is not set — the bots would silently keep running old code"
exit 1
fi
for fn in telegram-bot ask; do
npx --yes supabase@latest functions deploy "$fn" \
--project-ref vbhftvdayqfmcgmzdxfv \
--no-verify-jwt
done