CI/CD Konco pakai GitHub Actions dengan self-hosted runner. Setiap repo punya dua workflow: deploy_staging.yml dan deploy_production.yml. Tidak ada workflow untuk PR (pull_request) — hanya push ke staging dan production yang memicu deploy.
Struktur workflow
dazo-whitelist/
└── .github/workflows/
├── deploy_staging.yml # push ke staging
└── deploy_production.yml # push ke production
dazo-whitelist-api/
└── .github/workflows/
├── deploy_staging.yml # push ke staging
└── deploy_production.yml # push ke productionRepo Variables
| Variable | Dipakai di | Kegunaan |
|---|---|---|
PROJECT_DIR_DEVELOPMENT | deploy_staging.yml (kedua repo) | Path project di runner staging |
Trigger matrix
| Workflow File | Repo | Branch Trigger | Runner Label | Output |
|---|---|---|---|---|
deploy_staging.yml | dazo-whitelist | staging | self-hosted, staging | Build Vite + cache clear |
deploy_staging.yml | dazo-whitelist-api | staging | self-hosted, staging | Cache clear + composer install |
deploy_production.yml | dazo-whitelist | production | self-hosted, production | SSH ke server, jalankan deploy-konco.sh |
deploy_production.yml | dazo-whitelist-api | production | self-hosted, production | SSH ke server, jalankan deploy-api.sh |
Workflow 1 — deploy_staging.yml (dazo-whitelist)
name: Deploy Dazo Whitelist to Staging
on:
push:
branches:
- staging
jobs:
deploy:
runs-on: [self-hosted, staging]
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Deploy Konco App staging
run: |
cd ${{ vars.PROJECT_DIR_DEVELOPMENT }}
echo "Pulling latest code..."
git fetch --all
git reset --hard origin/staging
echo "Installing Dependencies..."
composer install --no-dev --optimize-autoloader --ignore-platform-req=ext-mongodb
npm ci
echo "Building assets..."
npm run build
echo "Verifying build..."
if [ ! -f "public/build/manifest.json" ]; then
echo "ERROR: Build failed - manifest.json not found!"
exit 1
fi
echo "Build verified successfully"
cat public/build/manifest.json
echo "Clearing Cache..."
php artisan cache:clear
php artisan config:clear
php artisan route:clear
php artisan view:clear
php artisan optimize:clear
echo "Optimizing..."
php artisan config:cache
php artisan route:cache
php artisan view:cache
echo "Deploy Successfully..."Tahapan staging (web app)
| Step | Aksi | Catatan |
|---|---|---|
| 1 | Checkout code | via actions/checkout@v3 |
| 2 | Pull latest | git fetch --all && git reset --hard origin/staging |
| 3 | Install PHP deps | composer install --no-dev --optimize-autoloader |
| 4 | Install JS deps | npm ci — memakai package-lock.json |
| 5 | Build Vite | npm run build — output ke public/build/ |
| 6 | Verifikasi build | Cek public/build/manifest.json ada — exit 1 bila tidak |
| 7 | Clear cache | cache:clear, config:clear, route:clear, view:clear, optimize:clear |
| 8 | Optimize | config:cache, route:cache, view:cache |
Workflow 2 — deploy_staging.yml (dazo-whitelist-api)
name: Deploy Dazo Whitelist to Staging
on:
push:
branches:
- staging
jobs:
deploy:
runs-on: [self-hosted, staging]
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Deploy Dazo App staging
run: |
cd ${{ vars.PROJECT_DIR_DEVELOPMENT }}
echo "Clearing Cache..."
php artisan cache:clear
php artisan config:clear
php artisan route:clear
php artisan optimize:clear
php artisan config:cache
php artisan view:cache
echo "Pulling latest code..."
git fetch --all
git reset --hard origin/staging
echo "Installing Dependencies..."
composer install --no-dev --optimize-autoloader --ignore-platform-req=ext-mongodb
npm i
echo "Deploy Successfully..."Perbedaan dengan web app staging
| Aspek | dazo-whitelist | dazo-whitelist-api |
|---|---|---|
| Build Vite | npm ci && npm run build | npm i (tanpa build — tidak ada Vite) |
| Verifikasi manifest | Ada — exit 1 bila gagal | Tidak ada |
| Urutan step | Pull → install → build → clear → optimize | Clear → pull → install — urutan berbeda |
npm ci vs npm i | npm ci (strict lockfile) | npm i (boleh update lockfile) |
Workflow 3 — deploy_production.yml
dazo-whitelist
name: Deploy Konco to Production
on:
push:
branches:
- production
jobs:
deploy:
runs-on: [self-hosted, production]
steps:
- name: Deploy
run: /usr/local/bin/deploy-konco.sh
- name: Notify on failure
if: failure()
run: echo "Deploy failed! Check logs at /var/www/konco/shared/storage/logs"dazo-whitelist-api
name: Deploy Konco API to Production
on:
push:
branches:
- production
jobs:
deploy:
runs-on: [self-hosted, production]
steps:
- name: Deploy
run: /usr/local/bin/deploy-api.sh
- name: Notify on failure
if: failure()
run: echo "API Deploy failed! Check logs at /var/www/konco-api/shared/storage/logs"Yang TIDAK ada di CI/CD Konco
| Aspek | Status | Catatan |
|---|---|---|
Workflow pull_request | Tidak ada | PR hanya di-review manual, tidak ada auto-build/test |
| Auto-rollback | Tidak ada | Rollback manual via git reset di server |
| Build artifact upload | Tidak ada | Build langsung di runner staging |
| Test runner | Tidak ada | Tidak ada php artisan test atau Pest di workflow |
| Linting (Pint) | Tidak ada | Tidak ada step ./vendor/bin/pint --test |
| Schedule deploy | Tidak ada | Hanya trigger via push |
| Multi-environment matrix | Tidak ada | Hanya 2 environment: staging & production |
| Secrets usage | Tidak terlihat | Workflow tidak memakai secrets.* — semua via self-hosted runner yang sudah trusted |
Self-hosted runner setup
| Aspek | Keterangan |
|---|---|
Label staging | Runner yang deploy ke server staging |
Label production | Runner yang deploy ke server production |
| Trusted | Runner ini punya SSH access ke target server — tidak butuh secrets di GitHub |
| OS | Linux (asumsi — echo bash syntax) |
| Tools wajib | PHP, Composer, Node.js, npm, Git, OpenSSL |
Tips operasional
Langkah berikutnya
- Baru mulai setup local? Baca Local Development.
- Detail path production & rollback? Lihat Deployment.
- Engineer baru wajib baca Auth & Security — RSA handshake rentan putus saat deploy bila key tidak sinkron.