From b0f299fc70100a7708e8755cf52289babe2e0586 Mon Sep 17 00:00:00 2001 From: mahyargdz Date: Wed, 27 Aug 2025 09:03:50 +0330 Subject: [PATCH] feat: add ci cd files --- .github/workflows/deploy.yaml | 48 +++++++++++++++++++++++++++++++++++ Dockerfile | 40 +++++++++++++++++++++++++++++ next.config.ts | 32 ++++++++++++++++++++++- 3 files changed, 119 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/deploy.yaml create mode 100644 Dockerfile diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml new file mode 100644 index 0000000..c812f64 --- /dev/null +++ b/.github/workflows/deploy.yaml @@ -0,0 +1,48 @@ +name: deploy to danak + +on: + push: + branches: + - master + +jobs: + build_and_deploy: + runs-on: ubuntu-latest + + env: + DANAK_SERVER: "https://captain.dev.danakcorp.com" + APP_TOKEN: 111ac60c637716478be8ab8b888fd20baba808a10b0fc0c18bf788766883ec9e + APP_NAME: e-commerce-front + GITHUB_TOKEN: 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 + + steps: + - name: Check out repositorys + uses: actions/checkout@v4 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Login to Container Registry + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: zmihamid + password: ${{ env.GITHUB_TOKEN }} + + - name: Preset Image Name + run: echo "IMAGE_URL=$(echo ghcr.io/zmihamid/${{ github.event.repository.name }}:$(echo ${{ github.sha }} | cut -c1-7) | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV + + - name: Build and push Docker Image + uses: docker/build-push-action@v5 + with: + context: . + file: ./Dockerfile + push: true + tags: ${{ env.IMAGE_URL }} + + - name: Install CapRover CLI + run: npm install -g caprover + + - name: deploy to server + run: | + caprover deploy -a $APP_NAME -u $DANAK_SERVER --appToken $APP_TOKEN -i "$IMAGE_URL" diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..bbc5d5f --- /dev/null +++ b/Dockerfile @@ -0,0 +1,40 @@ +FROM node:22-alpine AS base + +RUN apk add --no-cache tzdata && \ + cp /usr/share/zoneinfo/Asia/Tehran /etc/localtime && \ + echo "Asia/Tehran" > /etc/timezone + +WORKDIR /app + +FROM base AS deps +RUN apk add --no-cache libc6-compat git +COPY package*.json ./ +RUN npm ci --only=production --ignore-scripts + +FROM base AS builder +WORKDIR /build +COPY --from=deps /app/node_modules ./node_modules +COPY . . +RUN npm run build && npm ci --only=production --ignore-scripts + +FROM base AS runner +WORKDIR /app + +ENV NODE_ENV=production +ENV NEXT_TELEMETRY_DISABLED=1 + +RUN addgroup -S appgroup && adduser -S appuser -G appgroup +RUN mkdir .next && chown appuser:appgroup .next + +COPY --from=builder --chown=appuser:appgroup /build/.next/standalone ./ +COPY --from=builder --chown=appuser:appgroup /build/.next/static ./.next/static +COPY --from=builder --chown=appuser:appgroup /build/public ./public +COPY --from=builder --chown=appuser:appgroup /build/package.json ./package.json + +USER appuser + +EXPOSE 3000 +ENV PORT=3000 +ENV HOSTNAME="0.0.0.0" + +CMD ["node", "server.js"] \ No newline at end of file diff --git a/next.config.ts b/next.config.ts index 9f749f9..9bc6f20 100644 --- a/next.config.ts +++ b/next.config.ts @@ -1,8 +1,12 @@ import type { NextConfig } from "next"; const nextConfig: NextConfig = { + output: "standalone", /* config options here */ + poweredByHeader: false, + images: { + domains: ["*"], remotePatterns: [ { protocol: "https", @@ -13,8 +17,34 @@ const nextConfig: NextConfig = { hostname: "**", }, ], - unoptimized: false, }, + headers: async () => [ + { + source: "/:path*", + headers: [ + { + key: "X-DNS-Prefetch-Control", + value: "on", + }, + { + key: "X-XSS-Protection", + value: "1; mode=block", + }, + { + key: "X-Frame-Options", + value: "SAMEORIGIN", + }, + { + key: "X-Content-Type-Options", + value: "nosniff", + }, + { + key: "Referrer-Policy", + value: "origin-when-cross-origin", + }, + ], + }, + ], }; export default nextConfig;