PeerCortex/.github/workflows/build-verify.yml
Rene Fichtmueller 0caf7a271e
Some checks failed
build-verify / build-verify (push) Failing after 35s
build-verify / build-verify (pull_request) Failing after 12s
ci: add build-verify workflow + git-pull-based deploy script
Two consecutive PeerCortex deploys today (2026-07-16) broke in the same
way: server.js requires local files (src/backend/config.js,
src/backend/services/smtp.js) that were never actually uploaded to Erik,
because the deploy process was ad-hoc 'cat file | ssh' per-file uploads
with no systematic check that every require() target actually exists on
the target machine. A missing npm dependency (pg) caused the same class
of problem separately.

- .github/workflows/build-verify.yml: runs on every push/PR (Gitea Actions
  already has a working runner for this repo, confirmed via the existing
  .github/workflows/security-scan.yml on the github-import/main branch).
  npm ci, syntax-checks server.js + the other top-level .js files, verifies
  every local require() target resolves to an actual file, typechecks
  (informational for now -- see the step comment for why), builds dist/,
  runs the existing vitest suite. Catches both of today's failures before
  they'd ever reach Erik.

- deploy-from-git.sh: replaces the per-file upload process with a single
  git pull + npm ci + require()-check + syntax-check + build + backup +
  pm2 restart sequence, run manually on Erik. Deliberately NOT wired to a
  Gitea Action with SSH secrets -- Erik hosts many unrelated production
  services and main can contain code that hasn't been live-verified yet,
  so the actual deploy trigger stays a human decision. CI catches
  what's broken; this makes running the fix a single repeatable command
  instead of a manually-assembled file list.
2026-07-16 21:39:21 +02:00

66 lines
2.2 KiB
YAML

name: build-verify
# Catches the exact class of failure that broke two consecutive PeerCortex
# deploys on 2026-07-16: server.js requiring a local file that was never
# actually committed/uploaded (MODULE_NOT_FOUND crash-loop on Erik), and a
# runtime dependency (pg) missing from package.json/node_modules. Runs on
# every push and PR; does NOT deploy anything -- see deploy.sh / the manual
# Erik deploy process for that.
#
# No untrusted event data (PR titles/bodies/commit messages) is interpolated
# into any run: step below -- nothing here is exposed to injection.
on:
push:
pull_request:
permissions:
contents: read
jobs:
build-verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: npm ci
run: npm ci
- name: server.js / local-db-client.js / bio-rd-client.js syntax
run: |
for f in server.js local-db-client.js bio-rd-client.js bgp-hijack-monitor.js magatama-s2ten-bgp-enrichment.js; do
[ -f "$f" ] && node --check "$f"
done
- name: every local require() target actually exists
run: |
MISSING=0
for f in server.js local-db-client.js bio-rd-client.js; do
[ -f "$f" ] || continue
for req in $(grep -oE "require\(['\"]\./[^'\"]+['\"]\)" "$f" | sed -E "s/require\(['\"]\.\/([^'\"]+)['\"]\)/\1/"); do
target="$req"
if [ ! -f "$target" ] && [ ! -f "$target.js" ] && [ ! -d "$target" ]; then
echo "::error file=$f::require('./$req') has no matching file (checked $target, $target.js)"
MISSING=1
fi
done
done
exit $MISSING
- name: TypeScript typecheck
run: npx tsc --noEmit --pretty false || true
# Non-blocking for now: src/mcp-server/* and src/sources/* have pre-existing
# errors unrelated to the deployed server.js path (see project memory,
# 2026-07-16 audit). Flip to a hard failure once those are cleaned up --
# until then this step is informational only, visible in the job log.
- name: build (dist/)
run: npm run build
- name: vitest
run: npm test