diff --git a/ct/webapp.sh b/ct/webapp.sh new file mode 100644 index 0000000..eab10f6 --- /dev/null +++ b/ct/webapp.sh @@ -0,0 +1,143 @@ +#!/usr/bin/env bash +# webapp — Next.js site deployed via a self-hosted Gitea Actions runner +# +# Creates an unprivileged Debian 12 LXC that: +# - installs Node.js + a Gitea act_runner in HOST mode (no Docker, no inbound port) +# - serves the built site with `next start` on :APP_PORT (behind your proxy) +# - lets the repo's .gitea/workflows/deploy.yml build & deploy on every push +# (deploy-as-code; the runner polls Gitea outbound, so nothing is exposed) +# +# Run on a Proxmox VE host: +# bash -c "$(curl -fsSL https://gitea.luki-net.org/luki-net/proxmox-scripts/raw/branch/main/ct/webapp.sh)" + +set -euo pipefail + +APP="webapp" +APP_DESCRIPTION="Next.js site deployed via a self-hosted Gitea Actions runner (deploy-as-code)" +APP_PORT="${APP_PORT:-3000}" + +LIB_URL="${LIB_URL:-https://gitea.luki-net.org/luki-net/proxmox-scripts/raw/branch/main/lib}" +INSTALL_SCRIPT_URL="${INSTALL_SCRIPT_URL:-https://gitea.luki-net.org/luki-net/proxmox-scripts/raw/branch/main/install/webapp-install.sh}" + +# LXC defaults (Next build is memory-hungry; runner workspace + live copy need disk) +DEFAULT_HOSTNAME="web" +DEFAULT_DISK="30" +DEFAULT_CORES="2" +DEFAULT_RAM="4096" + +# App / runner defaults (all overridable via env) +DEFAULT_GITEA_INSTANCE_URL="https://gitea.luki-net.org" +DEFAULT_REPO_URL="https://gitea.luki-net.org/l.kirchner/Redesign-ad2b.git" +DEFAULT_SITE_URL="https://sichere-wirtschaft.de" +DEFAULT_SANITY_DATASET="production" +DEFAULT_SANITY_API_VERSION="2026-06-02" +DEFAULT_NODE_MAJOR="22" +DEFAULT_RUNNER_VERSION="0.2.13" +DEFAULT_RUNNER_LABELS="webapp:host" + +source <(curl -fsSL "$LIB_URL/build.func") + +# ── app-specific prompts (host TTY; each skipped if the var is preset) ─────── +prompt_app_config() { + echo + echo "── App / runner configuration ───────────────────────────────" + if [[ -z "${GITEA_INSTANCE_URL:-}" ]]; then + read -rp "Gitea instance URL [$DEFAULT_GITEA_INSTANCE_URL]: " GITEA_INSTANCE_URL + GITEA_INSTANCE_URL="${GITEA_INSTANCE_URL:-$DEFAULT_GITEA_INSTANCE_URL}" + fi + # Repo → Settings → Actions → Runners → "Create new runner" gives this token. + if [[ -z "${RUNNER_TOKEN:-}" ]]; then + read -rsp "Gitea runner registration token: " RUNNER_TOKEN; echo + fi + [[ -n "${RUNNER_TOKEN:-}" ]] || { msg_err "RUNNER_TOKEN is required (Repo → Settings → Actions → Runners)"; exit 1; } + if [[ -z "${REPO_URL:-}" ]]; then + read -rp "Website repo URL (informational) [$DEFAULT_REPO_URL]: " REPO_URL + REPO_URL="${REPO_URL:-$DEFAULT_REPO_URL}" + fi + + if [[ -z "${NEXT_PUBLIC_SITE_URL:-}" ]]; then + read -rp "Public site URL [$DEFAULT_SITE_URL]: " NEXT_PUBLIC_SITE_URL + NEXT_PUBLIC_SITE_URL="${NEXT_PUBLIC_SITE_URL:-$DEFAULT_SITE_URL}" + fi + if [[ -z "${NEXT_PUBLIC_SANITY_PROJECT_ID:-}" ]]; then + read -rp "Sanity project ID: " NEXT_PUBLIC_SANITY_PROJECT_ID + fi + if [[ -z "${NEXT_PUBLIC_SANITY_DATASET:-}" ]]; then + read -rp "Sanity dataset [$DEFAULT_SANITY_DATASET]: " NEXT_PUBLIC_SANITY_DATASET + NEXT_PUBLIC_SANITY_DATASET="${NEXT_PUBLIC_SANITY_DATASET:-$DEFAULT_SANITY_DATASET}" + fi + if [[ -z "${NEXT_PUBLIC_SANITY_API_VERSION:-}" ]]; then + read -rp "Sanity API version [$DEFAULT_SANITY_API_VERSION]: " NEXT_PUBLIC_SANITY_API_VERSION + NEXT_PUBLIC_SANITY_API_VERSION="${NEXT_PUBLIC_SANITY_API_VERSION:-$DEFAULT_SANITY_API_VERSION}" + fi + if [[ -z "${NEXT_PUBLIC_CALENDLY_URL+x}" ]]; then + read -rp "Calendly URL (optional, empty for none): " NEXT_PUBLIC_CALENDLY_URL + fi + + NODE_MAJOR="${NODE_MAJOR:-$DEFAULT_NODE_MAJOR}" + RUNNER_VERSION="${RUNNER_VERSION:-$DEFAULT_RUNNER_VERSION}" + RUNNER_LABELS="${RUNNER_LABELS:-$DEFAULT_RUNNER_LABELS}" + RUNNER_NAME="${RUNNER_NAME:-$CT_HOSTNAME}" + + echo " → instance: $GITEA_INSTANCE_URL" + echo " → runner: $RUNNER_NAME labels: $RUNNER_LABELS (act_runner $RUNNER_VERSION, host mode)" + echo " → node: $NODE_MAJOR app port: $APP_PORT" +} + +# ── push gathered config into the container for the installer to consume ───── +push_app_config() { + msg_info "Pushing deploy config into container..." + local tmpf; tmpf=$(mktemp) + cat >"$tmpf" </dev/null | tr -d '\r\n') + cat <