ci.yml: vet, race tests, clippy, full web build, AI-attribution and action-pin enforcement. release.yml: gate job verifies tag against versions.go/docker-compose/Cargo/CHANGELOG, forward-only and on public, before anything builds; web UI staged into the embed path (gitignored dist made a bare go build ship an empty dashboard); binaries and docker image must self-report the tag; release created via Gitea's own API. scripts/release.sh is the operator path: checks runner, secret, branch, versions, changelog — asks before every mutation, watches the run after. bump-version.sh gains current-version display, dirty-tree warning, duplicate check, changelog check, confirmation. build-secure-agent.sh retired (bare go build, no version injection, single Makefile caller).
52 lines
1.3 KiB
YAML
52 lines
1.3 KiB
YAML
services:
|
|
postgres:
|
|
image: postgres:16-alpine
|
|
container_name: redflag-postgres
|
|
volumes:
|
|
- postgres-data:/var/lib/postgresql/data
|
|
- ./config/.env:/shared/.env:z
|
|
ports:
|
|
- "31338:5432"
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U redflag"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
restart: unless-stopped
|
|
env_file:
|
|
- ./config/.env
|
|
|
|
server:
|
|
build:
|
|
context: .
|
|
dockerfile: ./server/Dockerfile
|
|
args:
|
|
BUILD_VERSION: ${BUILD_VERSION:-0.2.7.1}
|
|
container_name: redflag-server
|
|
volumes:
|
|
- server-config:/app/config
|
|
- server-data:/app/data
|
|
- ./config/.env:/shared/.env:z
|
|
depends_on:
|
|
postgres:
|
|
condition: service_healthy
|
|
healthcheck:
|
|
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:8080/api/health"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
start_period: 15s
|
|
retries: 3
|
|
ports:
|
|
# 31337 = agent/API endpoint, 31336 = dashboard. Same process now —
|
|
# the UI is embedded in the server binary; the nginx web container is gone.
|
|
- "31337:8080"
|
|
- "31336:8080"
|
|
command: ["./redflag-server"]
|
|
restart: unless-stopped
|
|
env_file:
|
|
- ./config/.env
|
|
|
|
volumes:
|
|
postgres-data:
|
|
server-data:
|
|
server-config:
|