From 38a2e08062f8ee6044ce22c27bba296d028feaa5 Mon Sep 17 00:00:00 2001 From: David Date: Sat, 26 Sep 2026 14:01:29 +0200 Subject: [PATCH] fix preprod --- .gitea/workflows/cd-preprod.yml | 13 +++++++------ docs/CI-CD-SECURITY.md | 10 +++++++++- 2 files changed, 16 insertions(+), 7 deletions(-) diff --git a/.gitea/workflows/cd-preprod.yml b/.gitea/workflows/cd-preprod.yml index 8793c3f..d32c189 100644 --- a/.gitea/workflows/cd-preprod.yml +++ b/.gitea/workflows/cd-preprod.yml @@ -9,9 +9,10 @@ name: CD Preprod # NEXT_PUBLIC_APP_URL — https://preprod.xpeditis.com # PORTAINER_WEBHOOK_BACKEND — Portainer webhook (preprod backend) # PORTAINER_WEBHOOK_FRONTEND— Portainer webhook (preprod frontend) -# PREPROD_BACKEND_URL — https://api.preprod.xpeditis.com -# PREPROD_FRONTEND_URL — https://preprod.xpeditis.com # DISCORD_WEBHOOK_URL +# Optional health URL overrides (secrets, then repository variables): +# PREPROD_BACKEND_URL — defaults to https://api.preprod.xpeditis.com +# PREPROD_FRONTEND_URL — defaults to https://app.preprod.xpeditis.com on: push: @@ -380,12 +381,12 @@ jobs: - name: Verify backend health env: - BASE_URL: ${{ secrets.PREPROD_BACKEND_URL }} - run: bash scripts/ci/health-check.sh "${BASE_URL:?Missing PREPROD_BACKEND_URL}/api/v1/health" + BASE_URL: ${{ secrets.PREPROD_BACKEND_URL || vars.PREPROD_BACKEND_URL || 'https://api.preprod.xpeditis.com' }} + run: bash scripts/ci/health-check.sh "${BASE_URL%/}/api/v1/health" - name: Verify frontend health env: - BASE_URL: ${{ secrets.PREPROD_FRONTEND_URL }} - run: bash scripts/ci/health-check.sh "${BASE_URL:?Missing PREPROD_FRONTEND_URL}" + BASE_URL: ${{ secrets.PREPROD_FRONTEND_URL || vars.PREPROD_FRONTEND_URL || 'https://app.preprod.xpeditis.com' }} + run: bash scripts/ci/health-check.sh "${BASE_URL%/}/api/health" - name: Mark successfully deployed preprod images env: diff --git a/docs/CI-CD-SECURITY.md b/docs/CI-CD-SECURITY.md index 4eaf551..527645e 100644 --- a/docs/CI-CD-SECURITY.md +++ b/docs/CI-CD-SECURITY.md @@ -94,9 +94,17 @@ comme des protections effectives dans les workflows adaptés. Choisir les noms exacts proposés après la première exécution. Les approbations humaines doivent être imposées sur les PR, pas via `environment`. 4. Renseigner les secrets/variables dans **Settings → Actions** du dépôt Gitea : - registre, webhooks Portainer, URLs préprod, URLs de build et identifiants + registre, webhooks Portainer, URLs de build et identifiants SSH/Hetzner déjà référencés. Les secrets ne sont pas des secrets d'environnement GitHub. Les clés SSH temporaires sont écrites dans le répertoire du job. + Les contrôles de santé préprod utilisent par défaut + `https://api.preprod.xpeditis.com/api/v1/health` et + `https://app.preprod.xpeditis.com/api/health`, conformément aux routes Traefik + de la stack. Le contrôle frontend cible son endpoint de santé pour éviter + la redirection HTTP 307 de la page d’accueil. + `PREPROD_BACKEND_URL` et `PREPROD_FRONTEND_URL` sont des surcharges facultatives + (URL de base sans chemin API), lues dans les secrets puis les variables du dépôt. + Une réponse HTTP 200 reste obligatoire pour valider le déploiement. 5. Les fonctions manuelles `workflow_dispatch` ne sont pas disponibles sur 1.22. L'ancien workflow de rollback est conservé hors du dossier actif dans `.gitea/manual/rollback.reference.yml` comme référence, sans prétendre qu'il est