fix: build demo AIUI from the reviewed source revision
This commit is contained in:
+7
-1
@@ -4,7 +4,13 @@
|
||||
# Allow neode-ui (frontend + mock backend + docker configs)
|
||||
!neode-ui/
|
||||
|
||||
# Allow demo assets (AIUI pre-built dist)
|
||||
!aiui/
|
||||
aiui/**/node_modules
|
||||
aiui/**/dist
|
||||
aiui/**/.turbo
|
||||
aiui/**/.build-aiui-last-*
|
||||
|
||||
# Allow curated demo assets
|
||||
!demo/
|
||||
|
||||
# Allow the Bitcoin UI + ElectrumX UI mock shells (served from /docker/*)
|
||||
|
||||
@@ -17,6 +17,9 @@ on:
|
||||
branches: [main]
|
||||
paths:
|
||||
- 'neode-ui/**'
|
||||
- 'aiui/**'
|
||||
- 'scripts/build-aiui.sh'
|
||||
- '.dockerignore'
|
||||
- 'docker-compose.demo.yml'
|
||||
- '.gitea/workflows/demo-images.yml'
|
||||
workflow_dispatch:
|
||||
@@ -65,6 +68,7 @@ jobs:
|
||||
push: true
|
||||
build-args: |
|
||||
VITE_DEMO=1
|
||||
SOURCE_REVISION=${{ github.sha }}
|
||||
tags: |
|
||||
${{ vars.DEMO_REGISTRY }}/archy-demo-web:demo
|
||||
${{ vars.DEMO_REGISTRY }}/archy-demo-web:${{ github.sha }}
|
||||
|
||||
@@ -17,6 +17,9 @@ on:
|
||||
branches: [main]
|
||||
paths:
|
||||
- 'neode-ui/**'
|
||||
- 'aiui/**'
|
||||
- 'scripts/build-aiui.sh'
|
||||
- '.dockerignore'
|
||||
- 'docker-compose.demo.yml'
|
||||
- '.github/workflows/demo-images.yml'
|
||||
workflow_dispatch:
|
||||
@@ -65,6 +68,7 @@ jobs:
|
||||
push: true
|
||||
build-args: |
|
||||
VITE_DEMO=1
|
||||
SOURCE_REVISION=${{ github.sha }}
|
||||
tags: |
|
||||
${{ vars.DEMO_REGISTRY }}/archy-demo-web:demo
|
||||
${{ vars.DEMO_REGISTRY }}/archy-demo-web:${{ github.sha }}
|
||||
|
||||
@@ -31,3 +31,18 @@ redeploy here. No source lives in this repo.
|
||||
- **Wallet/Bitcoin** — signet-flavored; use the in-UI faucet for test sats.
|
||||
- **Files** — real per-session upload/rename/delete, 50 MB quota, wiped on reap.
|
||||
- **Intro** — replays once per calendar day per browser.
|
||||
|
||||
## Building a reviewed demo revision
|
||||
|
||||
The web image builds both the dashboard and AIUI from the checked-out source;
|
||||
it does not use the historical `demo/aiui` bundle. CI supplies the full commit
|
||||
as `SOURCE_REVISION`. For a local source build, run:
|
||||
|
||||
```sh
|
||||
SOURCE_REVISION=$(git rev-parse HEAD) docker compose -f docker-compose.demo.yml build
|
||||
```
|
||||
|
||||
AIUI uses its frozen dependency lockfile, type checking and the canonical
|
||||
`/aiui/` build verifier. Its `BUILD-INFO` identifies that exact source revision.
|
||||
Prepare and test the images before changing the public demo stack; retain the
|
||||
previous image IDs for rollback.
|
||||
|
||||
@@ -44,6 +44,7 @@ services:
|
||||
dockerfile: neode-ui/Dockerfile.web
|
||||
args:
|
||||
VITE_DEMO: "1"
|
||||
SOURCE_REVISION: ${SOURCE_REVISION:?Set SOURCE_REVISION to git rev-parse HEAD}
|
||||
container_name: archy-demo-web
|
||||
ports:
|
||||
- "2100:80"
|
||||
|
||||
@@ -696,3 +696,24 @@ and this qualified helper; an A5 restart can reinstall its older helper. Do not
|
||||
claim final persistence until the new binary is deployed and restart is retested.
|
||||
No certificate verification was disabled for a public application or upstream.
|
||||
Raw-IP/unknown-SNI negative routing probes alone bypass hostname matching.
|
||||
|
||||
### NPM final source qualification and demo packaging
|
||||
|
||||
Backend source e0b2181a: all1,681 isolated tests pass (zero failures, four
|
||||
explicit ignores). Corrected nested-layout NPM integration also passes real
|
||||
local ACME issuance/renewal,40 cross-certificate TLS requests, WSS, ACLs,
|
||||
restart, failed-bind rollback and host enable/delete propagation. Real public
|
||||
Let’s Encrypt staging issuance plus forced renewal pass on migrated Shorty;
|
||||
production certificate files and NPM container identity/start time are unchanged.
|
||||
Evidence: `/tmp/archy-190-npm-guard-final-backend-tests.log`,
|
||||
`/tmp/archy-190-npm-multicert-nested-acme.log`,
|
||||
`/tmp/archy-190-shorty-migrated-staging-acme.log`.
|
||||
Optimized build and final deployment/restart acceptance are still pending.
|
||||
|
||||
Demo image preparation found the web Dockerfile copied historical prebuilt AIUI.
|
||||
It now builds the current source with the canonical script and frozen lockfile,
|
||||
with explicit source revision for archive/container builds. Both CI workflows
|
||||
track AIUI changes and pass the checkout revision. Actual image qualification
|
||||
and public demo deployment remain pending. The demo/release VPS currently has
|
||||
under1GiB free disk; capacity must be resolved before image/artifact publication.
|
||||
No running container, volume, release or repository was deleted.
|
||||
|
||||
+13
-2
@@ -1,3 +1,14 @@
|
||||
FROM node:22-alpine AS aiui-builder
|
||||
RUN apk add --no-cache bash git coreutils findutils && corepack enable
|
||||
WORKDIR /source
|
||||
COPY aiui/ ./aiui/
|
||||
COPY scripts/build-aiui.sh ./scripts/build-aiui.sh
|
||||
ARG SOURCE_REVISION
|
||||
ARG VITE_DEMO=1
|
||||
RUN test -n "$SOURCE_REVISION" && \
|
||||
if [ "$VITE_DEMO" = "1" ] || [ "$VITE_DEMO" = "true" ]; then export VITE_DEMO_CONTENT=true; fi && \
|
||||
ARCHY_SOURCE_REVISION="$SOURCE_REVISION" bash scripts/build-aiui.sh
|
||||
|
||||
FROM node:22-alpine AS builder
|
||||
|
||||
WORKDIR /app
|
||||
@@ -49,8 +60,8 @@ FROM nginx:alpine
|
||||
# Copy built files to nginx
|
||||
COPY --from=builder /app/dist /usr/share/nginx/html
|
||||
|
||||
# Copy AIUI pre-built dist
|
||||
COPY demo/aiui/ /usr/share/nginx/html/aiui/
|
||||
# Build AIUI from the same source revision as the dashboard.
|
||||
COPY --from=aiui-builder /source/aiui/packages/app/dist/ /usr/share/nginx/html/aiui/
|
||||
|
||||
# Copy nginx config template and entrypoint
|
||||
COPY neode-ui/docker/nginx-demo.conf /etc/nginx/nginx.conf.template
|
||||
|
||||
+14
-2
@@ -45,6 +45,18 @@ AIUI_APP_DIR="$AIUI_ROOT/packages/app"
|
||||
AIUI_DIST="$AIUI_APP_DIR/dist"
|
||||
AIUI_MOUNT_PATH="/aiui/"
|
||||
|
||||
# Source archives/container contexts omit .git. Require their caller to supply
|
||||
# the exact checkout revision; normal node builds always use the real checkout.
|
||||
if git -C "$PROJECT_DIR" rev-parse --verify HEAD >/dev/null 2>&1; then
|
||||
SOURCE_REVISION="$(git -C "$PROJECT_DIR" rev-parse HEAD)"
|
||||
else
|
||||
SOURCE_REVISION="${ARCHY_SOURCE_REVISION:-}"
|
||||
fi
|
||||
if [[ ! "$SOURCE_REVISION" =~ ^[0-9a-f]{40}$ ]]; then
|
||||
echo "FATAL: a full source commit is required (ARCHY_SOURCE_REVISION for archives)." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
timestamp() { echo "[$(date +%H:%M:%S)]"; }
|
||||
|
||||
# ── require_base_path ──────────────────────────────────────────────────
|
||||
@@ -113,7 +125,7 @@ verify_dist() {
|
||||
# Attribute this build to THIS repo's own current commit (D-19: no
|
||||
# second-repo pin file — this repo's own commit IS the answer now).
|
||||
local commit_sha
|
||||
commit_sha="$(git -C "$PROJECT_DIR" rev-parse HEAD)"
|
||||
commit_sha="$SOURCE_REVISION"
|
||||
{
|
||||
echo "commit=$commit_sha"
|
||||
echo "built_at=$(date -u +%Y-%m-%dT%H:%M:%SZ)"
|
||||
@@ -178,4 +190,4 @@ echo "$(timestamp) Building AIUI (vue-tsc --noEmit && vite build)..."
|
||||
echo "$(timestamp) Verifying dist..."
|
||||
verify_dist
|
||||
|
||||
echo "$(timestamp) AIUI build OK — $AIUI_DIST attributable to $(git -C "$PROJECT_DIR" rev-parse --short HEAD)"
|
||||
echo "$(timestamp) AIUI build OK — $AIUI_DIST attributable to ${SOURCE_REVISION:0:8}"
|
||||
|
||||
Reference in New Issue
Block a user