#!/usr/bin/env bash set -euo pipefail REPO_DIR="/opt/NextWks" TARGET_DIR="/opt/nextworkspace" SERVICE_NAME="nextworkspace" BINARY_NAME="nextworkspace" HEALTH_CHECK_RETRIES=10 HEALTH_CHECK_INTERVAL=2 # --- Load .env from runtime root --- ENV_FILE="$TARGET_DIR/.env" if [ -f "$ENV_FILE" ]; then set -a source "$ENV_FILE" set +a fi # Default domain if .env wasn't loaded DOMAIN="${DOMAIN:-nextwks.eu}" # --- Mode detection --- GREENFIELD=false if [ "${1:-}" = "--destroy" ]; then GREENFIELD=true echo "[MODE] Greenfield deploy (--destroy)" elif [ ! -d "$TARGET_DIR" ]; then GREENFIELD=true echo "[MODE] Greenfield deploy (target missing)" else echo "[MODE] Smart update (target exists)" fi # --- Common: pull + build --- cd "$REPO_DIR" echo "[1/6] Pulling latest code..." git pull echo "[2/6] Building binary..." export PATH=$PATH:/usr/local/go/bin go build -o "$BINARY_NAME" . # --- Greenfield path --- if [ "$GREENFIELD" = true ]; then echo "[3/6] Removing old deployment..." # Preserve .env across greenfield destroy if [ -f "$TARGET_DIR/.env" ]; then cp "$TARGET_DIR/.env" /tmp/nextworkspace.env.bak echo "[INFO] Preserved .env" fi rm -rf "$TARGET_DIR" echo "[4/6] Creating target directories..." mkdir -p "$TARGET_DIR/config/nextworkspace" mkdir -p "$TARGET_DIR/config/zoraxy/conf/proxy" mkdir -p "$TARGET_DIR/data/zoraxy" mkdir -p "$TARGET_DIR/compose" mkdir -p "$TARGET_DIR/logs" # Restore preserved .env if [ -f /tmp/nextworkspace.env.bak ]; then mv /tmp/nextworkspace.env.bak "$TARGET_DIR/.env" chmod 600 "$TARGET_DIR/.env" echo "[INFO] Restored .env" fi echo "[5/6] Copying binary..." cp "$BINARY_NAME" "$TARGET_DIR/$BINARY_NAME" echo "[6/6] Deploying Zoraxy..." cp compose/zoraxy.yaml "$TARGET_DIR/compose/zoraxy.yaml" podman-compose -f "$TARGET_DIR/compose/zoraxy.yaml" up -d 2>&1 || echo "[WARN] Zoraxy deploy had issues (see above)" # Generate Zoraxy proxy configs with full schema (prevents Zoraxy from clearing OriginIpOrDomain on expand) echo "[*] Generating Zoraxy proxy configs..." cat > "$TARGET_DIR/config/zoraxy/conf/proxy/app.$DOMAIN.config" < "$TARGET_DIR/config/zoraxy/conf/proxy/dns.$DOMAIN.config" < "$TARGET_DIR/config/nextworkspace/apps.yaml" < /dev/null 2>&1; then break fi echo " Waiting for Zoraxy... ($i/15)" sleep 2 done # Fetch CSRF token and create admin COOKIE_JAR="/tmp/zoraxy_cookies.txt" rm -f "$COOKIE_JAR" LOGIN_PAGE=$(curl -sL -c "$COOKIE_JAR" http://127.0.0.1:8000/) CSRF_TOKEN=$(echo "$LOGIN_PAGE" | grep -oP '(?<=&1) if echo "$ADMIN_CREATE" | grep -qi '"success"\|"ok"\|"registered'; then echo "[OK] Zoraxy admin account created" else echo "[INFO] Admin API response: $ADMIN_CREATE" fi fi # Login to Zoraxy for LE config LOGIN_PAGE=$(curl -sL -c "$COOKIE_JAR" http://127.0.0.1:8000/) CSRF_TOKEN=$(echo "$LOGIN_PAGE" | grep -oP '(?<= /dev/null # Configure Let's Encrypt echo "[*] Setting Let's Encrypt email..." curl -s -b "$COOKIE_JAR" -X POST "http://127.0.0.1:8000/api/acme/autoRenew/email" \ -d "set=${TLS_EMAIL}" > /dev/null echo "[*] Obtaining certificates for app.${DOMAIN}..." curl -s -b "$COOKIE_JAR" -X GET "http://127.0.0.1:8000/api/acme/obtainCert" \ -G -d "domains=app.${DOMAIN}" -d "filename=app.${DOMAIN}" \ -d "email=${TLS_EMAIL}" -d "ca=Let's Encrypt" -d "dns=false" > /dev/null || true echo "[*] Enabling auto-renew..." curl -s -b "$COOKIE_JAR" -X POST "http://127.0.0.1:8000/api/acme/autoRenew/enable" \ -d "enable=true" > /dev/null fi # Restart Zoraxy to pick up configs echo "[*] Restarting Zoraxy to apply configs..." podman-compose -f "$TARGET_DIR/compose/zoraxy.yaml" restart 2>&1 || true sleep 2 # Write systemd service with EnvironmentFile for .env vars echo "[*] Writing systemd service..." cat > /etc/systemd/system/$SERVICE_NAME.service </dev/null || true echo "[4/6] Swapping binary..." cp "$BINARY_NAME" "$TARGET_DIR/$BINARY_NAME" echo "[5/6] Refreshing configs..." if [ -f config/nextworkspace/apps.yaml ]; then cp config/nextworkspace/apps.yaml "$TARGET_DIR/config/nextworkspace/apps.yaml" fi if [ -d config/zoraxy/conf/proxy ]; then cp config/zoraxy/conf/proxy/* "$TARGET_DIR/config/zoraxy/conf/proxy/" 2>/dev/null || true fi echo "[6/6] Restarting Zoraxy and launcher..." podman-compose -f "$TARGET_DIR/compose/zoraxy.yaml" restart 2>&1 || true systemctl restart $SERVICE_NAME fi # --- Health check --- echo "[*] Running health check..." for i in $(seq 1 $HEALTH_CHECK_RETRIES); do if curl -sf http://127.0.0.1:9000/health > /dev/null 2>&1; then echo "[OK] NextWorkspace launcher is healthy on http://127.0.0.1:9000/" exit 0 fi echo " Attempt $i/$HEALTH_CHECK_RETRIES — not ready yet..." sleep $HEALTH_CHECK_INTERVAL done echo "[FAIL] Health check failed — launcher did not respond on port 9000" exit 1