#!/usr/bin/env bash # deploy-server.sh — deploy the backend binary + nginx config. # Two source modes: uses dist/ built in the same job, or downloads the release # assets by tag (manual rollback). Does NOT touch the web app, marketing site, # or version.yaml. # # Target is EC2 by default. During the EC2→Ali migration, set DEPLOY_TARGET=ali # plus DEPLOY_HOST/DEPLOY_USER/DEPLOY_SSH_KEY to deploy to the Alibaba Cloud box. # - ec2 (default): stop jiu → swap binary → start jiu → health check → # reload nginx inside the pangolin-edge container. # - ali: swap binary only (jiu.service stays stopped — the Ali DB is a # read-only replica until cutover; backend is started at cutover) → # reload the host nginx with the standalone (listen 443) config. set -euo pipefail # shellcheck source=scripts/ci/lib-forgejo.sh . "$(dirname "$0")/lib-forgejo.sh" TAG="$1" DEPLOY_TARGET="${DEPLOY_TARGET:-ec2}" TARGET_HOST="${DEPLOY_HOST:-$EC2_HOST}" TARGET_USER="${DEPLOY_USER:-$EC2_USER}" echo "==> deploy-server: tag=${TAG} target=${DEPLOY_TARGET} host=${TARGET_HOST}" if [ ! -f dist/jiu-server ] || [ ! -f dist/configs.tar.gz ]; then download_release_assets "$TAG" fi echo "==> deploy-server: dist/ contents:" ls -lh dist/ rm -rf /tmp/jiu-configs mkdir -p /tmp/jiu-configs tar -xzf dist/configs.tar.gz -C /tmp/jiu-configs # Pick the nginx config matching the target's reverse-proxy topology. if [ "$DEPLOY_TARGET" = "ali" ]; then NGINX_SRC=/tmp/jiu-configs/deploy/nginx-jiu-ali.conf else NGINX_SRC=/tmp/jiu-configs/deploy/nginx-jiu.conf fi setup_ssh echo "==> deploy-server: uploading files to ${TARGET_HOST}" ${SCP} dist/jiu-server "${TARGET_USER}@${TARGET_HOST}:/tmp/jiu-server" ${SCP} "${NGINX_SRC}" "${TARGET_USER}@${TARGET_HOST}:/tmp/nginx-jiu.conf" # Platform code-minting CLI + wrapper (absent when rolling back to a pre-gencode # release — upload only when present). if [ -f dist/jiu-gencode ]; then ${SCP} dist/jiu-gencode "${TARGET_USER}@${TARGET_HOST}:/tmp/jiu-gencode" ${SCP} /tmp/jiu-configs/deploy/jiu-gencode.sh "${TARGET_USER}@${TARGET_HOST}:/tmp/jiu-gencode.sh" fi if [ "$DEPLOY_TARGET" = "ali" ]; then # --- Alibaba Cloud (shadow target, pre-cutover) --- # Swap the binary but DO NOT start jiu: the Ali DB is a read-only replica, so # the backend's startup AutoMigrate/backfill would fail. jiu.service is started # only at cutover (after the replica is promoted to primary). Reload the host # nginx with the standalone listen-443 config. ${SSH} "${TARGET_USER}@${TARGET_HOST}" << 'ENDSSH' set -e cp /tmp/jiu-server /opt/jiu/backend/jiu-server chmod +x /opt/jiu/backend/jiu-server if [ -f /tmp/jiu-gencode ]; then cp /tmp/jiu-gencode /opt/jiu/backend/jiu-gencode chmod +x /opt/jiu/backend/jiu-gencode if [ -f /tmp/jiu-gencode.sh ]; then cp /tmp/jiu-gencode.sh /opt/jiu/backend/jiu-gencode.sh chmod +x /opt/jiu/backend/jiu-gencode.sh fi fi cp /tmp/nginx-jiu.conf /etc/nginx/conf.d/jiu.conf nginx -t && systemctl reload nginx echo "Ali server staged (binary swapped, jiu.service left stopped, nginx reloaded)" ENDSSH else # --- EC2 (live primary) --- ${SSH} "${TARGET_USER}@${TARGET_HOST}" << 'ENDSSH' set -e # Replace backend binary sudo systemctl stop jiu cp /tmp/jiu-server /opt/jiu/backend/jiu-server chmod +x /opt/jiu/backend/jiu-server # Refresh the code-minting CLI if shipped in this release (skip gracefully on # rollback to a pre-gencode release). Not a service — just a host-side binary. if [ -f /tmp/jiu-gencode ]; then cp /tmp/jiu-gencode /opt/jiu/backend/jiu-gencode chmod +x /opt/jiu/backend/jiu-gencode if [ -f /tmp/jiu-gencode.sh ]; then cp /tmp/jiu-gencode.sh /opt/jiu/backend/jiu-gencode.sh chmod +x /opt/jiu/backend/jiu-gencode.sh fi fi # Start and health check sudo systemctl start jiu echo "Waiting for health check..." for i in $(seq 1 30); do if curl -f http://localhost:8080/health > /dev/null 2>&1; then echo "Health check passed" break fi sleep 2 done curl -f http://localhost:8080/health > /dev/null || { echo "Health check failed!"; exit 1; } # Update jiu nginx config in the pangolin-edge reverse proxy (host-bind-mounted # conf.d; reload nginx inside the container). cp /tmp/nginx-jiu.conf /home/ec2-user/pangolin/edge/conf.d/jiu.conf docker exec pangolin-edge nginx -t && docker exec pangolin-edge nginx -s reload echo "Server deploy complete!" ENDSSH fi teardown_ssh rm -rf /tmp/jiu-configs echo "==> deploy-server: done (target=${DEPLOY_TARGET})"