From c4d029b58edc1a059958cdfef87d2824bb553ceb Mon Sep 17 00:00:00 2001 From: Guido X Jansen Date: Sun, 14 Jun 2026 22:44:11 +0200 Subject: [PATCH] fix(ci): set AI_ENCRYPTION_KEY in smoke-test env (#114) * fix(ci): set AI_ENCRYPTION_KEY in smoke-test env The barazo-api env schema requires AI_ENCRYPTION_KEY to be >=32 chars. The smoke-test job omitted it, so compose passed an empty string and the API crash-looped on env validation, never became healthy, and the deploy gate failed with 'barazo-api is unhealthy'. Add a dummy >=32-char value. * fix(ci): repair smoke-test.sh local-mode checks Two latent bugs surfaced once the API became healthy: - Valkey ping omitted -a $VALKEY_PASSWORD, but valkey runs with --requirepass, so ping returned NOAUTH instead of PONG. - API and frontend HTTP checks hit localhost:3000/3001, but the compose stack publishes only Caddy (port 80). Route both through Caddy, which proxies /api/* to barazo-api and everything else to barazo-web. --- .github/workflows/deploy-staging.yml | 1 + scripts/smoke-test.sh | 11 +++++++---- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/workflows/deploy-staging.yml b/.github/workflows/deploy-staging.yml index af1162f..5e2384e 100644 --- a/.github/workflows/deploy-staging.yml +++ b/.github/workflows/deploy-staging.yml @@ -177,6 +177,7 @@ jobs: DATABASE_URL: postgresql://barazo:ci_smoke_test@postgres:5432/barazo TAP_ADMIN_PASSWORD: ci_smoke_test SESSION_SECRET: ci_session_secret_not_real_extend_to_32 + AI_ENCRYPTION_KEY: ci_ai_encryption_key_not_real_extend_to_32 RELAY_URL: wss://bsky.network COMMUNITY_DID: did:plc:ci-smoke-test COMMUNITY_NAME: CI Smoke Test diff --git a/scripts/smoke-test.sh b/scripts/smoke-test.sh index af4f4e7..70243b2 100755 --- a/scripts/smoke-test.sh +++ b/scripts/smoke-test.sh @@ -65,7 +65,7 @@ if [ -z "$REMOTE_URL" ]; then fi # Check Valkey connection - if docker compose -f "$COMPOSE_FILE" exec -T valkey valkey-cli ping 2>/dev/null | grep -q "PONG"; then + if docker compose -f "$COMPOSE_FILE" exec -T valkey valkey-cli -a "${VALKEY_PASSWORD:-}" ping 2>/dev/null | grep -q "PONG"; then pass "Valkey is responding" else fail "Valkey is not responding" @@ -79,8 +79,11 @@ if [ -n "$REMOTE_URL" ]; then BASE_URL="$REMOTE_URL" echo "Remote deployment checks ($BASE_URL):" else - BASE_URL="http://localhost:3000" - echo "HTTP checks (via localhost):" + # App ports are not published to the host -- only Caddy (port 80) is. + # Route local HTTP checks through Caddy, which proxies /api/* -> barazo-api + # and everything else -> barazo-web. + BASE_URL="http://localhost" + echo "HTTP checks (via Caddy on localhost):" fi # API health @@ -109,7 +112,7 @@ echo "Frontend checks:" if [ -n "$REMOTE_URL" ]; then HOMEPAGE=$(curl -s "$BASE_URL" 2>/dev/null || echo "") else - HOMEPAGE=$(curl -s "http://localhost:3001" 2>/dev/null || echo "") + HOMEPAGE=$(curl -s "$BASE_URL" 2>/dev/null || echo "") fi if echo "$HOMEPAGE" | grep -qi "barazo\|html"; then -- 2.51.2