Something went wrong. Try again.
Pretty cool forms service. Code is slop btw. forms.alivetech.org
Something went wrong. Try again.
3.9 kB · 138 lines
Shell
at main
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139#!/usr/bin/env bashset -euo pipefail
DEPLOY_HOST="${DEPLOY_HOST:-root@10.72.30.114}"DEPLOY_DIR="${DEPLOY_DIR:-/opt/lively-forms}"PORT="${PORT:-8000}"# Stage is public at forms.alivetech.org. Caddy terminates HTTPS there and# proxies requests over the private network to http://10.72.30.114:8000.# OAuth URLs must always use the public HTTPS origin, never the upstream URL.PUBLIC_URL="${PUBLIC_URL:-https://forms.alivetech.org}"PROXY_UPSTREAM="${PROXY_UPSTREAM:-http://10.72.30.114:8000}"SERVICE_NAME="${SERVICE_NAME:-lively-forms}"
echo "Deploying to ${DEPLOY_HOST}:${DEPLOY_DIR} on port ${PORT}"echo "Public URL: ${PUBLIC_URL} (proxied to ${PROXY_UPSTREAM})"
ssh "${DEPLOY_HOST}" "mkdir -p '${DEPLOY_DIR}'"
COPYFILE_DISABLE=1 tar \ --no-xattrs \ --exclude='.git' \ --exclude='.env' \ --exclude='.next' \ --exclude='node_modules' \ --exclude='coverage' \ --exclude='test-results' \ --exclude='playwright-report' \ --exclude='.DS_Store' \ -czf - . | ssh "${DEPLOY_HOST}" "tar -xzf - -C '${DEPLOY_DIR}'"
ssh "${DEPLOY_HOST}" bash -s -- "${DEPLOY_DIR}" "${PORT}" "${PUBLIC_URL}" "${SERVICE_NAME}" <<'REMOTE'set -euo pipefail
DEPLOY_DIR="$1"PORT="$2"PUBLIC_URL="$3"SERVICE_NAME="$4"
if ! command -v podman >/dev/null 2>&1 || ! command -v podman-compose >/dev/null 2>&1 || ! command -v unzip >/dev/null 2>&1 || ! command -v openssl >/dev/null 2>&1; then apt-get update apt-get install -y podman podman-compose unzip opensslfi
if ! command -v node >/dev/null 2>&1 || ! node -e 'process.exit(Number(process.versions.node.split(".")[0]) >= 22 ? 0 : 1)'; then apt-get update . /etc/os-release if [ "${ID:-}" = "altlinux" ]; then apt-get install -y node else apt-get install -y ca-certificates curl gnupg curl -fsSL https://deb.nodesource.com/setup_22.x | bash - apt-get install -y nodejs fifi
export BUN_INSTALL="${HOME}/.bun"export PATH="${BUN_INSTALL}/bin:${PATH}"if ! command -v bun >/dev/null 2>&1; then curl -fsSL https://bun.sh/install | bashfi
cd "${DEPLOY_DIR}"
if [ ! -f .env ]; then AUTH_SECRET="$(openssl rand -base64 32)" cat > .env <<ENVDATABASE_URL="postgresql://the_forms:the_forms@127.0.0.1:5432/the_forms?schema=public"AUTH_SECRET="${AUTH_SECRET}"NEXTAUTH_URL="${PUBLIC_URL}"ATPROTO_PUBLIC_URL="${PUBLIC_URL}"ATPROTO_CLIENT_ID="${PUBLIC_URL}/api/atproto/client-metadata"ATPROTO_REDIRECT_URI="${PUBLIC_URL}/api/auth/atproto/callback"ATPROTO_CLIENT_NAME="Lively Forms"ENVfi
python3 - "${PUBLIC_URL}" <<'PY'from pathlib import Pathimport syspublic_url = sys.argv[1]path = Path('.env')lines = path.read_text().splitlines()updates = { 'NEXTAUTH_URL': f'"{public_url}"', 'ATPROTO_PUBLIC_URL': f'"{public_url}"', 'ATPROTO_CLIENT_ID': f'"{public_url}/api/atproto/client-metadata"', 'ATPROTO_REDIRECT_URI': f'"{public_url}/api/auth/atproto/callback"',}seen = set()out = []for line in lines: key = line.split('=', 1)[0] if '=' in line else None if key in updates: out.append(f'{key}={updates[key]}') seen.add(key) else: out.append(line)for key, value in updates.items(): if key not in seen: out.append(f'{key}={value}')path.write_text('\n'.join(out) + '\n')PY
set -a. ./.envset +a
bun install --frozen-lockfilepodman-compose up -dbunx prisma migrate deploybun run build
cat > "/etc/systemd/system/${SERVICE_NAME}.service" <<UNIT[Unit]Description=Lively FormsAfter=network.target
[Service]Type=simpleWorkingDirectory=${DEPLOY_DIR}Environment=NODE_ENV=productionEnvironment=PORT=${PORT}EnvironmentFile=${DEPLOY_DIR}/.envExecStart=${BUN_INSTALL}/bin/bun run start -- -H 0.0.0.0 -p ${PORT}Restart=alwaysRestartSec=5
[Install]WantedBy=multi-user.targetUNIT
systemctl daemon-reloadsystemctl enable --now "${SERVICE_NAME}"systemctl restart "${SERVICE_NAME}"systemctl --no-pager --full status "${SERVICE_NAME}"REMOTE
echo "Deployed: ${PUBLIC_URL}"