mirror of
https://github.com/pezkuwichain/pezkuwi-telegram-miniapp.git
synced 2026-07-31 14:35:43 +00:00
9e3844fd89
The functions in this repo do not all live in the same place, and the deploy step I added yesterday sent all of them to the self-hosted host on vps3. telegram-bot and ask are served from the cloud project vbhftvdayqfmcgmzdxfv. Both Telegram bots reach it by webhook — ?bot=krd is @pezkuwichainBot and ?bot=dks is @DKSKurdistanBot — and news.pex.mom's assistant calls ask there. Copies of both still sit in the vps3 volume from before that split, holding a bot token revoked on 2026-07-19, and take no traffic. Deploying to vps3 was therefore updating a dead copy while the live one kept running old code. So the self-hosted job now excludes those two, and a second job deploys them to the cloud project. That closes a real gap: they had been deployed by hand for months, and git drifted far enough behind that on 2026-07-21 the running function body had to be extracted from the deployed bundle to recover it. The host registry records the split too, so the gate cannot be pointed at the wrong target by accident.
143 lines
4.9 KiB
YAML
143 lines
4.9 KiB
YAML
name: Deploy
|
|
|
|
on:
|
|
workflow_run:
|
|
workflows: ["CI"]
|
|
types: [completed]
|
|
branches: [main]
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: deploy
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
VITE_SUPABASE_URL: ${{ secrets.VITE_SUPABASE_URL }}
|
|
VITE_SUPABASE_ANON_KEY: ${{ secrets.VITE_SUPABASE_ANON_KEY }}
|
|
VITE_DEPOSIT_TON_ADDRESS: ${{ secrets.VITE_DEPOSIT_TON_ADDRESS }}
|
|
VITE_DEPOSIT_POLKADOT_ADDRESS: ${{ secrets.VITE_DEPOSIT_POLKADOT_ADDRESS }}
|
|
|
|
jobs:
|
|
deploy:
|
|
name: Deploy to VPS
|
|
runs-on: ubuntu-latest
|
|
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '20'
|
|
cache: 'npm'
|
|
|
|
- run: npm ci
|
|
|
|
- run: npm run build
|
|
|
|
# VPS1 (telegram.pezkuwichain.io) is currently running Zagros testnet - deployed manually
|
|
# Re-enable this step when testnet period is over
|
|
# - name: Deploy to telegram.pezkuwichain.io
|
|
# uses: appleboy/scp-action@v1.0.0
|
|
# with:
|
|
# host: ${{ secrets.VPS1_HOST }}
|
|
# username: ${{ secrets.VPS1_USER }}
|
|
# key: ${{ secrets.VPS1_SSH_KEY }}
|
|
# source: 'dist/*'
|
|
# target: '/var/www/telegram.pezkuwichain.io'
|
|
# strip_components: 1
|
|
|
|
- name: Deploy to telegram.pezkiwi.app
|
|
uses: appleboy/scp-action@v1.0.0
|
|
with:
|
|
host: ${{ secrets.VPS2_HOST }}
|
|
username: ${{ secrets.VPS2_USER }}
|
|
key: ${{ secrets.VPS2_SSH_KEY }}
|
|
source: 'dist/*'
|
|
target: '/var/www/telegram.pezkiwi.app'
|
|
strip_components: 1
|
|
|
|
- name: Cleanup old assets on VPS
|
|
uses: appleboy/ssh-action@v1.0.0
|
|
with:
|
|
host: ${{ secrets.VPS2_HOST }}
|
|
username: ${{ secrets.VPS2_USER }}
|
|
key: ${{ secrets.VPS2_SSH_KEY }}
|
|
script: bash /opt/cleanup-miniapp.sh
|
|
|
|
# Edge functions live in a Supabase volume shared with other projects, so they
|
|
# are written through the ownership gate on the host rather than copied in
|
|
# directly. The gate refuses any name this project does not own, which is what
|
|
# stops a repeat of the 2026-06-28 incident where another project's deploy
|
|
# silently replaced telegram-auth and broke sign-in for a month.
|
|
deploy-functions:
|
|
name: Deploy edge functions (self-hosted)
|
|
needs: deploy
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
# telegram-bot and ask are excluded on purpose: both Telegram bots and the
|
|
# news.pex.mom assistant are served from the cloud project, not from here.
|
|
# Stale copies of both still sit in this volume from before that split and
|
|
# take no traffic. They are deployed by the deploy-cloud-functions job.
|
|
- name: Package functions
|
|
run: |
|
|
tar czf functions.tgz -C supabase \
|
|
--exclude='functions/telegram-bot' \
|
|
--exclude='functions/ask' \
|
|
functions
|
|
|
|
- name: Copy to staging on VPS
|
|
uses: appleboy/scp-action@v1.0.0
|
|
with:
|
|
host: ${{ secrets.VPS2_HOST }}
|
|
username: ${{ secrets.VPS2_USER }}
|
|
key: ${{ secrets.VPS2_SSH_KEY }}
|
|
source: 'functions.tgz'
|
|
target: '/opt/miniapp-deploy-staging'
|
|
|
|
- name: Deploy through ownership gate
|
|
uses: appleboy/ssh-action@v1.0.0
|
|
with:
|
|
host: ${{ secrets.VPS2_HOST }}
|
|
username: ${{ secrets.VPS2_USER }}
|
|
key: ${{ secrets.VPS2_SSH_KEY }}
|
|
script: |
|
|
set -e
|
|
BASE=/opt/miniapp-deploy-staging
|
|
trap 'rm -rf "$BASE"' EXIT
|
|
rm -rf "$BASE/functions"
|
|
tar xzf "$BASE/functions.tgz" -C "$BASE"
|
|
supabase-deploy-functions \
|
|
--project pezkuwi-telegram-miniapp \
|
|
--src "$BASE/functions" \
|
|
--restart
|
|
|
|
# The two Telegram bots and the news.pex.mom assistant run on the cloud
|
|
# Supabase project, reached by webhook at
|
|
# vbhftvdayqfmcgmzdxfv.supabase.co/functions/v1/telegram-bot?bot=krd|dks.
|
|
# These were deployed by hand for months, which let the source in git drift
|
|
# behind what was actually running — badly enough that on 2026-07-21 the live
|
|
# function body had to be pulled back out of the deployed bundle to recover it.
|
|
deploy-cloud-functions:
|
|
name: Deploy edge functions (cloud)
|
|
needs: deploy
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Deploy telegram-bot and ask
|
|
env:
|
|
SUPABASE_ACCESS_TOKEN: ${{ secrets.SUPABASE_ACCESS_TOKEN }}
|
|
run: |
|
|
set -e
|
|
if [ -z "$SUPABASE_ACCESS_TOKEN" ]; then
|
|
echo "::error::SUPABASE_ACCESS_TOKEN is not set — the bots would silently keep running old code"
|
|
exit 1
|
|
fi
|
|
for fn in telegram-bot ask; do
|
|
npx --yes supabase@latest functions deploy "$fn" \
|
|
--project-ref vbhftvdayqfmcgmzdxfv \
|
|
--no-verify-jwt
|
|
done
|