# .gitea/workflows/deploy.yml name: Build and Deploy on: push: branches: [ "master" ] workflow_dispatch: {} concurrency: group: deploy-${{ gitea.ref }} cancel-in-progress: true jobs: build-deploy: # Gitea's runner images are lean, so the toolchain is installed below rather # than assumed. The glibc that libchess_engine.so links against comes from # this image, not from the runner host — keep it matched to the prod server. runs-on: ubuntu-latest steps: - name: Install toolchain run: | apt-get update apt-get install -y --no-install-recommends \ cmake build-essential rsync openssh-client - name: Checkout uses: actions/checkout@v4 - name: Setup .NET uses: actions/setup-dotnet@v4 with: dotnet-version: '8.0.x' - name: Restore run: dotnet restore JoshHeaps.Net/JoshHeaps.Net.csproj - name: Build native chess engine (libchess_engine.so) run: | cmake -S native/chess_engine -B native/chess_engine/build -DCMAKE_BUILD_TYPE=Release cmake --build native/chess_engine/build cp native/chess_engine/build/libchess_engine.so JoshHeaps.Net/Resources/ # Publishing the project rather than the solution keeps chess_engine.vcxproj # (Windows-only MSBuild C++ targets) and the UiTests assemblies out of it. - name: Publish run: dotnet publish JoshHeaps.Net/JoshHeaps.Net.csproj -c Release -o ./publish - name: Verify payload run: | set -euo pipefail test -f publish/Resources/libchess_engine.so \ || { echo "libchess_engine.so missing from publish output"; exit 1; } test -x publish/Resources/stockfish-ubuntu-x86-64-sse41-popcnt \ || { echo "stockfish is not executable"; exit 1; } - name: Prepare SSH env: SSH_KEY: ${{ secrets.SSH_KEY }} SSH_HOST: ${{ secrets.SSH_HOST }} SSH_PORT: ${{ secrets.SSH_PORT }} run: | set -euo pipefail PORT="${SSH_PORT:-22}" install -m 700 -d ~/.ssh printf '%s\n' "$SSH_KEY" > ~/.ssh/deploy_key chmod 600 ~/.ssh/deploy_key ssh-keyscan -p "$PORT" "$SSH_HOST" >> ~/.ssh/known_hosts 2>/dev/null # --exclude chess-data: never let --delete remove the learned-engine training # data, which lives in the deploy dir unless ChessEngine__WeightsPath is set. - name: Rsync to server env: SSH_HOST: ${{ secrets.SSH_HOST }} SSH_PORT: ${{ secrets.SSH_PORT }} SSH_USER: ${{ secrets.SSH_USER }} TARGET_DIR: ${{ secrets.TARGET_DIR }} run: | set -euo pipefail PORT="${SSH_PORT:-22}" rsync -az --delete --exclude 'chess-data' \ -e "ssh -p $PORT -i ~/.ssh/deploy_key -o StrictHostKeyChecking=yes" \ publish/ "$SSH_USER@$SSH_HOST:$TARGET_DIR/" - name: Reload and restart service env: SSH_HOST: ${{ secrets.SSH_HOST }} SSH_PORT: ${{ secrets.SSH_PORT }} SSH_USER: ${{ secrets.SSH_USER }} SERVICE_NAME: ${{ secrets.SERVICE_NAME }} run: | set -euo pipefail PORT="${SSH_PORT:-22}" ssh -p "$PORT" -i ~/.ssh/deploy_key "$SSH_USER@$SSH_HOST" \ "sudo systemctl daemon-reload \ && sudo systemctl restart '$SERVICE_NAME' \ && systemctl --no-pager status '$SERVICE_NAME' --lines=0"