irongit

Git hosting and a container registry in one Rust binary (axum + Astro)

Deploy on push: pre-push hook runs deploy.sh when main goes to git.hygo.ai

huncholanehuncholaneauthored
parent 1d300f5commit 69a304b3a5a2259ead73d0cfe54fcccb1b2da7a0Browse files

2 files changed, +47 -0

+41-0.githooks/pre-push
@@ -0,0 +1,41 @@
1+#!/bin/sh
2+# Deploys to production with ./deploy.sh when main is pushed to git.hygo.ai,
3+# before the push goes out: if the deploy fails, the push is stopped, so the
4+# repository never claims something production is not running.
5+#
6+# Enabled per clone with: git config core.hooksPath .githooks
7+# Skip once with: git push --no-verify (or SKIP_DEPLOY=1 git push)
8+set -eu
9+
10+url="$2"
11+[ "${SKIP_DEPLOY:-}" = 1 ] && exit 0
12+case "$url" in
13+ *git.hygo.ai/huncholane/irongit*) ;;
14+ *) exit 0 ;;
15+esac
16+
17+zero=0000000000000000000000000000000000000000
18+deploy=0
19+while read -r local_ref local_sha remote_ref remote_sha; do
20+ [ "$remote_ref" = refs/heads/main ] || continue
21+ [ "$local_sha" = "$zero" ] && continue # deleting main is not a deploy
22+ if [ "$local_sha" != "$(git rev-parse HEAD)" ]; then
23+ echo "pre-push: main is $(git rev-parse --short "$local_sha") but you have $(git rev-parse --short HEAD) checked out." >&2
24+ echo "pre-push: check out main to deploy it, or push with --no-verify." >&2
25+ exit 1
26+ fi
27+ deploy=1
28+done
29+[ "$deploy" = 1 ] || exit 0
30+
31+# The image is built from this folder, not the commit: refuse anything that
32+# is not committed (untracked files included) so prod matches main exactly.
33+if [ -n "$(git status --porcelain)" ]; then
34+ echo "pre-push: uncommitted or untracked files would be deployed:" >&2
35+ git status --short >&2
36+ echo "pre-push: commit or stash them, or push with --no-verify to skip the deploy." >&2
37+ exit 1
38+fi
39+
40+echo "pre-push: deploying $(git rev-parse --short HEAD) to production before pushing main"
41+./deploy.sh </dev/null
+6-0README.md
@@ -129,6 +129,12 @@ the `irongit` service in `/opt/hygo/docker-compose.yml`: same shared Postgres
129129 # publish the bundled ig to R2 when cli/Cargo.toml's version changed
130130 ```
131131
132+Pushing `main` to git.hygo.ai deploys automatically: `.githooks/pre-push` runs
133+`./deploy.sh` first and stops the push if the deploy fails (enable it per
134+clone with `git config core.hooksPath .githooks`; skip once with
135+`git push --no-verify` or `SKIP_DEPLOY=1 git push`). It refuses to deploy
136+uncommitted or untracked files, since the image is built from the folder.
137+
132138 Roll back:
133139
134140 ```sh