Maak DEPLOY_PATH configureerbaar via Gitea Actions variable i.p.v. hardcoded #7

Merged
Sluijsens merged 10 commits from feature/production_deploy_automation into master 2026-07-30 23:58:06 +02:00
10 Commits
Author SHA1 Message Date
Sluijsens 6b3194320b Fix SCP-deploy: geef secrets via env: door i.p.v. inline in het script
Continuous Integration / config (pull_request) Successful in 10s
Continuous Integration / prepare (pull_request) Successful in 1m27s
Continuous Integration / build-production (pull_request) Skipped
Continuous Integration / build (pull_request) Successful in 2m6s
Continuous Integration / test (pull_request) Successful in 1m58s
Continuous Integration / deploy-production (pull_request) Skipped
Deploy / deploy (pull_request) Successful in 35s
Continuous Integration / deploy-test (pull_request) Successful in 34s
Gitea Actions plakt ${{ secrets.* }} als platte tekst in het run-script
vóórdat bash het uitvoert. Bevat het wachtwoord een shell-metateken
zoals '$', dan interpreteert bash dat alsnog, waardoor sshpass een
ander wachtwoord krijgt dan bedoeld ("Permission denied"). Via env:
en sshpass -e komt de waarde als kant-en-klare string binnen, zonder
die tweede interpretatieslag.
2026-07-30 14:27:49 +02:00
Sluijsens 5ded994626 Deploy testomgeving tijdelijk ook bij elke PR (vereenvoudigt testen)
Continuous Integration / config (pull_request) Successful in 9s
Continuous Integration / prepare (pull_request) Successful in 1m31s
Continuous Integration / build-production (pull_request) Skipped
Continuous Integration / build (pull_request) Successful in 2m7s
Continuous Integration / test (pull_request) Successful in 2m0s
Continuous Integration / deploy-production (pull_request) Skipped
Deploy / deploy (pull_request) Failing after 37s
Continuous Integration / deploy-test (pull_request) Failing after 38s
2026-07-30 13:37:49 +02:00
Sluijsens 6c08d0a842 Hernoem PI_MAIN_HOST secret naar PI_MAIN_ADDRESS
Continuous Integration / config (pull_request) Successful in 10s
Continuous Integration / prepare (pull_request) Successful in 1m33s
Continuous Integration / build-production (pull_request) Skipped
Continuous Integration / build (pull_request) Successful in 2m13s
Continuous Integration / test (pull_request) Successful in 2m3s
Continuous Integration / deploy-test (pull_request) Skipped
Continuous Integration / deploy-production (pull_request) Skipped
2026-07-30 13:32:42 +02:00
SluijsensandClaude Sonnet 5 ecad3c3b4e Verwijder live-configs map: configs zijn al handmatig op de Pi's toegepast
Continuous Integration / config (pull_request) Successful in 9s
Continuous Integration / prepare (pull_request) Successful in 1m20s
Continuous Integration / build-production (pull_request) Skipped
Continuous Integration / build (pull_request) Successful in 1m53s
Continuous Integration / test (pull_request) Successful in 1m49s
Continuous Integration / deploy-test (pull_request) Skipped
Continuous Integration / deploy-production (pull_request) Skipped
Deze snapshot bleek achteraf niet nodig - de configs staan inmiddels op
pi-entry/pi-main zelf, en hoeven niet ook nog los in de repo bewaard te
worden.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 17:28:44 +02:00
SluijsensandClaude Sonnet 5 d1f544555d Bewaar gecorrigeerde live nginx-configs als referentie in de repo
De configs die deze sessie zijn nagelopen en gefixt (slpsoftware-analytics.conf,
slpsoftware-test-webserver.conf, slpsoftware.conf) stonden alleen als geplakte
tekst in de chat en een tijdelijke scratchpad-map, niet in de repo of op de
Pi's zelf toegepast. Dit zet ze duurzaam vast als referentiesnapshot, met een
README die per bestand aangeeft wat er is aangepast en waarom. Nog steeds
handmatig te kopiëren naar de Pi's; niet automatisch gesynchroniseerd.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 14:49:11 +02:00
SluijsensandClaude Sonnet 5 b5e8ae1820 Voeg productie-nginx-voorbeeldconfiguratie toe voor de reverse-proxy-Pi
Continuous Integration / config (pull_request) Successful in 10s
Continuous Integration / prepare (pull_request) Successful in 1m15s
Continuous Integration / build-production (pull_request) Skipped
Continuous Integration / build (pull_request) Successful in 1m57s
Continuous Integration / test (pull_request) Successful in 1m51s
Continuous Integration / deploy-test (pull_request) Skipped
Continuous Integration / deploy-production (pull_request) Skipped
production-nginx.conf.example (vóór certbot) en
production-nginx.conf.post-certbot.example (referentie, na certbot) dekken
alléén de react-frontend-site op slpsoftware.nl/www.slpsoftware.nl; de
mail/iRedAdmin-proxying die op de daadwerkelijke productieserver ook op dit
domein draait valt buiten de scope van deze feature en is bewust
weggelaten. Bevat de acme-challenge location in het 443-blok (niet het
poort-80-blok) en de sentry-tunnel-proxy, analoog aan de testomgeving-
configuratie. Documentatie in deployment-plan.md en
deployment-instructions.md bijgewerkt met productie-nginx-setupstappen.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 13:11:47 +02:00
SluijsensandClaude Sonnet 5 3af15159fe Consistente _TEST/_PRODUCTION postfix voor omgevingsspecifieke Gitea variables
Continuous Integration / config (pull_request) Successful in 10s
Continuous Integration / prepare (pull_request) Successful in 1m14s
Continuous Integration / build-production (pull_request) Skipped
Continuous Integration / build (pull_request) Successful in 1m56s
Continuous Integration / test (pull_request) Successful in 1m48s
Continuous Integration / deploy-test (pull_request) Skipped
Continuous Integration / deploy-production (pull_request) Skipped
Hernoemt de Gitea-variable achter VITE_UMAMI_WEBSITE_ID naar
VITE_UMAMI_WEBSITE_ID_TEST, zodat deze consistent is met
VITE_UMAMI_WEBSITE_ID_PRODUCTION en DEPLOY_PATH_TEST/DEPLOY_PATH_PRODUCTION.
De Vite build-time envvar-naam die de app zelf verwacht
(VITE_UMAMI_WEBSITE_ID) verandert niet, alleen de naam van de Gitea
repository variable erachter. Bewust gedeelde variabelen (VITE_UMAMI_SCRIPT_URL,
VITE_SENTRY_DSN, PI_MAIN_* secrets) krijgen geen postfix, want die zijn
geen omgevingsspecifieke waarden. Documentatie in umami-setup.md,
deployment-instructions.md en monitoring-plan.md bijgewerkt.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 12:16:10 +02:00
SluijsensandClaude Sonnet 5 4bddcbbc50 Splits Umami website-ID per omgeving in productie-build (was per ongeluk gedeeld)
build-production hergebruikte vars.VITE_UMAMI_WEBSITE_ID van de testbuild,
maar Umami-website-ID's horen bij één specifieke domeinentry in het
dashboard. Zonder deze fix zou productieverkeer in de teststatistieken
terechtkomen. Introduceert VITE_UMAMI_WEBSITE_ID_PRODUCTION als losse Gitea
variable, en documenteert dat er twee aparte Umami-website-entries nodig
zijn (test.slpsoftware.nl / slpsoftware.nl). VITE_UMAMI_SCRIPT_URL en
VITE_SENTRY_DSN blijven bewust gedeeld tussen omgevingen.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 12:12:13 +02:00
SluijsensandClaude Sonnet 5 a208aebae0 Automatiseer productie-deploy als opt-in stap naast de bestaande testdeploy
Voegt build-production en deploy-production jobs toe aan
continuous_integration.yaml, alleen actief bij een handmatige
workflow_dispatch-run met het deploy_production-vinkje aangevinkt (nooit
automatisch bij een push naar master). Een aparte build-production job is
nodig omdat VITE_APP_ENV een build-time Vite-variabele is: dezelfde bundel
kan niet zowel als test als production getagd zijn in Sentry/analytics.
Uploadpad komt uit de nieuwe Gitea-variable DEPLOY_PATH_PRODUCTION, analoog
aan DEPLOY_PATH_TEST. Documentatie en production-readiness-checklist
bijgewerkt om dit open item als opgelost te markeren.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 12:05:19 +02:00
SluijsensandClaude Sonnet 5 78f68d52f7 Maak DEPLOY_PATH configureerbaar via Gitea Actions variable i.p.v. hardcoded
Continuous Integration / config (pull_request) Successful in 10s
Continuous Integration / prepare (pull_request) Successful in 1m18s
Continuous Integration / build (pull_request) Successful in 1m55s
Continuous Integration / test (pull_request) Successful in 1m50s
Continuous Integration / deploy-test (pull_request) Skipped
Vervangt het hardcoded testpad in continuous_integration.yaml door de
Gitea repository variable DEPLOY_PATH_TEST, zodat het uploadpad aan te
passen is zonder de workflow zelf te wijzigen. Documentatie bijgewerkt
met de vereiste eenmalige Gitea-variable-setup.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 11:59:16 +02:00