Files
pezkuwi-telegram-miniapp/.github/workflows/deploy.yml
T
pezkuwichain 54f565621c fix(auth): namespace edge functions, restore miniapp sign-in
The Supabase edge-function volume on the host is shared with pwap-web, which
deploys into it by rsyncing its whole tree. Both projects defined a function
called telegram-auth, so on 2026-06-28 pwap-web's login-widget handler replaced
this project's initData handler. Sign-in and every wallet screen behind it have
returned 401 ever since; nothing failed loudly because the name still resolved.

Rename this project's two colliding functions to a tgm- namespace so the two
deploys can no longer reach the same directory, and point the client at the new
name. process-withdraw is renamed too: it is currently unreferenced here, but it
moves platform funds, so leaving it shadowed by another project's version is not
something to keep.

Also deploy functions from CI. They were last pushed by hand in April, so seven
of them had drifted behind the repo and one had never shipped at all. The new
step writes through the host's ownership gate, which refuses any name this
project does not own — the drift and the collision both stop here.

Ownership is recorded in /opt/supabase-self-hosted/functions-registry.json.
2026-07-29 20:21:37 -07:00

107 lines
3.4 KiB
YAML

name: Deploy
on:
workflow_run:
workflows: ["CI"]
types: [completed]
branches: [main]
workflow_dispatch:
concurrency:
group: deploy
cancel-in-progress: true
env:
VITE_SUPABASE_URL: ${{ secrets.VITE_SUPABASE_URL }}
VITE_SUPABASE_ANON_KEY: ${{ secrets.VITE_SUPABASE_ANON_KEY }}
VITE_DEPOSIT_TON_ADDRESS: ${{ secrets.VITE_DEPOSIT_TON_ADDRESS }}
VITE_DEPOSIT_POLKADOT_ADDRESS: ${{ secrets.VITE_DEPOSIT_POLKADOT_ADDRESS }}
jobs:
deploy:
name: Deploy to VPS
runs-on: ubuntu-latest
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
- run: npm ci
- run: npm run build
# VPS1 (telegram.pezkuwichain.io) is currently running Zagros testnet - deployed manually
# Re-enable this step when testnet period is over
# - name: Deploy to telegram.pezkuwichain.io
# uses: appleboy/scp-action@v1.0.0
# with:
# host: ${{ secrets.VPS1_HOST }}
# username: ${{ secrets.VPS1_USER }}
# key: ${{ secrets.VPS1_SSH_KEY }}
# source: 'dist/*'
# target: '/var/www/telegram.pezkuwichain.io'
# strip_components: 1
- name: Deploy to telegram.pezkiwi.app
uses: appleboy/scp-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
source: 'dist/*'
target: '/var/www/telegram.pezkiwi.app'
strip_components: 1
- name: Cleanup old assets on VPS
uses: appleboy/ssh-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
script: bash /opt/cleanup-miniapp.sh
# Edge functions live in a Supabase volume shared with other projects, so they
# are written through the ownership gate on the host rather than copied in
# directly. The gate refuses any name this project does not own, which is what
# stops a repeat of the 2026-06-28 incident where another project's deploy
# silently replaced telegram-auth and broke sign-in for a month.
deploy-functions:
name: Deploy edge functions
needs: deploy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Package functions
run: tar czf functions.tgz -C supabase functions
- name: Copy to staging on VPS
uses: appleboy/scp-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
source: 'functions.tgz'
target: '/opt/miniapp-deploy-staging'
- name: Deploy through ownership gate
uses: appleboy/ssh-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
script: |
set -e
BASE=/opt/miniapp-deploy-staging
trap 'rm -rf "$BASE"' EXIT
rm -rf "$BASE/functions"
tar xzf "$BASE/functions.tgz" -C "$BASE"
supabase-deploy-functions \
--project pezkuwi-telegram-miniapp \
--src "$BASE/functions" \
--restart