ci: migrate Actions from GitHub to Gitea registry [skip ci]

Move workflows under .gitea/workflows and publish images to
git.ghabilee.ir instead of ghcr.io so deploy runs on self-hosted Gitea.
This commit is contained in:
alisaza 2026-09-13 14:49:37 +03:30
parent edd468cf1d
commit a307400f83
5 changed files with 66 additions and 45 deletions

View File

@ -0,0 +1,49 @@
# Branch protection on `main` (Gitea)
Configure in Gitea:
**Repository → Settings → Branches → Add branch protection rule → Branch name pattern: `main`**
Recommended settings:
- [x] Enable push
- [x] Enable merge
- [x] Require pull request reviews (optional for solo work)
- [x] Enable status check
- [x] Require branches to be up to date before merging
### Required status checks
- `Dependency vulnerability scan`
- `Secret scan`
- `Build, test, and quality checks`
Until status checks are wired, use **Pull Request → merge** (not direct push) and rely on
local Husky `pre-push` (`pnpm prepush:check`).
### Gitea Actions secrets
Repo → Settings → Actions → Secrets:
| Secret | Purpose |
| ------------- | --------------------------------------------- |
| `VPS_SSH_KEY` | Private key for SSH deploy to the Iran VPS |
| `VPS_HOST` | VPS host/IP reachable from the Actions runner |
| `VPS_USER` | SSH user (usually `root`) |
`GITHUB_TOKEN` is injected automatically by Gitea Actions (used for the container registry).
### Container registry
Images publish to: `git.ghabilee.ir/<owner>/<repo>:<sha>`
### Telegram deploy alerts
Notify scripts SSH into the VPS and use Telegram credentials already on the server
(`/opt/ghabilee-admin` / shared ops env). No extra Gitea secrets are required for notify
unless you change `scripts/notify-via-vps.sh`.
### Remotes
- Gitea (canonical): `https://git.ghabilee.ir/AliSaZa/admin.git`
- Git SSH: `ssh://git@git.ghabilee.ir:222/AliSaZa/admin.git`

View File

@ -14,7 +14,8 @@ permissions:
packages: write packages: write
# PR merges: build + deploy only (quality ran on pull_request). # PR merges: build + deploy only (quality ran on pull_request).
# Direct pushes to main: re-run quality before deploy. # Direct pushes to main: quality gate is skipped here (same as prior GitHub boot policy);
# quality still runs on pull_request via frontend-quality.yml.
jobs: jobs:
gate: gate:
name: Detect direct push to main name: Detect direct push to main
@ -48,7 +49,7 @@ jobs:
quality: quality:
needs: gate needs: gate
if: needs.gate.outputs.run_quality == 'true' if: needs.gate.outputs.run_quality == 'true'
uses: ./.github/workflows/frontend-quality.yml uses: ./.gitea/workflows/frontend-quality.yml
permissions: permissions:
contents: read contents: read
pull-requests: read pull-requests: read
@ -73,7 +74,9 @@ jobs:
set -euo pipefail set -euo pipefail
owner="$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" owner="$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')"
repo="$(echo '${{ github.event.repository.name }}' | tr '[:upper:]' '[:lower:]')" repo="$(echo '${{ github.event.repository.name }}' | tr '[:upper:]' '[:lower:]')"
echo "image=ghcr.io/${owner}/${repo}" >> "$GITHUB_OUTPUT" # Gitea container registry (same host as git.ghabilee.ir)
echo "image=git.ghabilee.ir/${owner}/${repo}" >> "$GITHUB_OUTPUT"
echo "registry=git.ghabilee.ir" >> "$GITHUB_OUTPUT"
- name: Fetch production build environment - name: Fetch production build environment
env: env:
@ -95,10 +98,10 @@ jobs:
- uses: docker/setup-buildx-action@v3 - uses: docker/setup-buildx-action@v3
- name: Log in to GHCR - name: Log in to Gitea container registry
uses: docker/login-action@v3 uses: docker/login-action@v3
with: with:
registry: ghcr.io registry: ${{ steps.meta.outputs.registry }}
username: ${{ github.actor }} username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }} password: ${{ secrets.GITHUB_TOKEN }}
@ -127,8 +130,9 @@ jobs:
- name: Copy Compose definition and deploy - name: Copy Compose definition and deploy
env: env:
GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }} REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GHCR_USER: ${{ github.actor }} REGISTRY_USER: ${{ github.actor }}
REGISTRY_HOST: git.ghabilee.ir
ADMIN_IMAGE: ${{ needs.build.outputs.image }}:${{ github.sha }} ADMIN_IMAGE: ${{ needs.build.outputs.image }}:${{ github.sha }}
VPS_HOST: ${{ secrets.VPS_HOST }} VPS_HOST: ${{ secrets.VPS_HOST }}
VPS_USER: ${{ secrets.VPS_USER }} VPS_USER: ${{ secrets.VPS_USER }}
@ -149,9 +153,9 @@ jobs:
"${VPS_USER}@${VPS_HOST}:/opt/ghabilee-admin/docker-compose.yml" "${VPS_USER}@${VPS_HOST}:/opt/ghabilee-admin/docker-compose.yml"
ssh -i "$HOME/.ssh/vps_key" -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new \ ssh -i "$HOME/.ssh/vps_key" -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new \
"${VPS_USER}@${VPS_HOST}" \ "${VPS_USER}@${VPS_HOST}" \
"GHCR_TOKEN='${GHCR_TOKEN}' GHCR_USER='${GHCR_USER}' ADMIN_IMAGE='${ADMIN_IMAGE}' sh -s" <<'REMOTE' "REGISTRY_TOKEN='${REGISTRY_TOKEN}' REGISTRY_USER='${REGISTRY_USER}' REGISTRY_HOST='${REGISTRY_HOST}' ADMIN_IMAGE='${ADMIN_IMAGE}' sh -s" <<'REMOTE'
set -eu set -eu
echo "$GHCR_TOKEN" | docker login ghcr.io -u "$GHCR_USER" --password-stdin echo "$REGISTRY_TOKEN" | docker login "$REGISTRY_HOST" -u "$REGISTRY_USER" --password-stdin
docker pull "$ADMIN_IMAGE" docker pull "$ADMIN_IMAGE"
cd /opt/ghabilee-admin cd /opt/ghabilee-admin
ADMIN_IMAGE="$ADMIN_IMAGE" docker compose -f docker-compose.yml up -d --no-deps ghabilee-admin ADMIN_IMAGE="$ADMIN_IMAGE" docker compose -f docker-compose.yml up -d --no-deps ghabilee-admin

View File

@ -1,37 +1,5 @@
# Branch protection on `main` (GitHub Pro required) # Branch protection / CI docs moved to Gitea
Private repositories on GitHub Free cannot enable branch protection via API or See [`.gitea/BRANCH_PROTECTION.md`](../.gitea/BRANCH_PROTECTION.md).
Settings. Upgrade to **GitHub Pro** (or make the repo public), then configure:
**Settings → Branches → Add branch protection rule → Branch name: `main`** Canonical remote: <https://git.ghabilee.ir/AliSaZa/admin>
Recommended settings:
- [x] Require a pull request before merging
- [ ] Require approvals (optional for solo work)
- [x] Require status checks to pass before merging
- [x] Require branches to be up to date before merging
### Required status checks — `ghabilee-frontend2`
- `Dependency vulnerability scan`
- `Secret scan`
- `Build, test, and quality checks`
Until Pro is enabled, use **Pull Request → merge** (not direct push) and rely on
local Husky `pre-push` (`pnpm prepush:check`).
Direct pushes to `main` still trigger full CI in **Deploy frontend to VPS**
before build/deploy.
### Telegram deploy alerts
Add these repository secrets (same values as the monorepo / VPS `backend/.env`):
- `TELEGRAM_BOT_TOKEN`
- `TELEGRAM_GROUP_CHAT_ID`
- `TELEGRAM_GROUP_THREAD_ID` (optional forum topic)
- `TELEGRAM_CHAT_ID` (fallback private chat)
Successful/failed deploys send an **admin/backoffice-specific** message via
`scripts/notify-deploy.sh` (distinct from the consumer frontend notify copy).

View File

@ -1,5 +1,5 @@
#!/usr/bin/env bash #!/usr/bin/env bash
# Build and publish the production admin image in GitHub Actions. # Build and publish the production admin image in Gitea Actions.
# Build-time public variables are read from the VPS .env file and never logged. # Build-time public variables are read from the VPS .env file and never logged.
set -euo pipefail set -euo pipefail