npm install with no committed package-lock.json re-resolved semver ranges fresh on every deploy instead of pinning to bun.lock (the project's actual lockfile) — a supply-chain integrity gap flagged by automated commit review. Use bun, the frontend's real package manager, with --frozen-lockfile so deploys are reproducible. Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
29 lines
699 B
Bash
Executable file
29 lines
699 B
Bash
Executable file
#!/bin/bash
|
|
# Idempotent redeploy for LoVisual. Run as: /opt/lovisual/deploy.sh
|
|
set -euo pipefail
|
|
|
|
REPO_DIR=/opt/lovisual
|
|
FRONTEND_ROOT=/var/www/visual.loki-code.dev/html
|
|
|
|
cd "$REPO_DIR"
|
|
git pull --ff-only
|
|
|
|
echo "==> Building & (re)starting backend services"
|
|
cd "$REPO_DIR/backend"
|
|
docker compose -f docker-compose.prod.yml up -d --build
|
|
|
|
echo "==> Building frontend"
|
|
cd "$REPO_DIR/frontend"
|
|
bun install --frozen-lockfile
|
|
bun run build
|
|
|
|
echo "==> Syncing frontend build to $FRONTEND_ROOT"
|
|
mkdir -p "$FRONTEND_ROOT"
|
|
rsync -a --delete dist/ "$FRONTEND_ROOT/"
|
|
|
|
echo "==> Reloading nginx"
|
|
nginx -t
|
|
systemctl reload nginx
|
|
|
|
echo "==> Done"
|
|
docker compose -f "$REPO_DIR/backend/docker-compose.prod.yml" ps
|