D
Setup

CI/CD

Dua workflow GitHub Actions per repo Konco — deploy_staging.yml (build + cache + optimize) & deploy_production.yml (SSH script /usr/local/bin/deploy-konco.sh & deploy-api.sh). Self-hosted runner dengan label production & staging.

CI/CD Konco pakai GitHub Actions dengan self-hosted runner. Setiap repo punya dua workflow: deploy_staging.yml dan deploy_production.yml. Tidak ada workflow untuk PR (pull_request) — hanya push ke staging dan production yang memicu deploy.

Struktur workflow

text
dazo-whitelist/
└── .github/workflows/
    ├── deploy_staging.yml       # push ke staging
    └── deploy_production.yml    # push ke production

dazo-whitelist-api/
└── .github/workflows/
    ├── deploy_staging.yml       # push ke staging
    └── deploy_production.yml    # push ke production

Repo Variables

VariableDipakai diKegunaan
PROJECT_DIR_DEVELOPMENTdeploy_staging.yml (kedua repo)Path project di runner staging

Trigger matrix

Workflow FileRepoBranch TriggerRunner LabelOutput
deploy_staging.ymldazo-whiteliststagingself-hosted, stagingBuild Vite + cache clear
deploy_staging.ymldazo-whitelist-apistagingself-hosted, stagingCache clear + composer install
deploy_production.ymldazo-whitelistproductionself-hosted, productionSSH ke server, jalankan deploy-konco.sh
deploy_production.ymldazo-whitelist-apiproductionself-hosted, productionSSH ke server, jalankan deploy-api.sh

Workflow 1 — deploy_staging.yml (dazo-whitelist)

yaml
name: Deploy Dazo Whitelist to Staging

on:
  push:
    branches:
      - staging

jobs:
  deploy:
    runs-on: [self-hosted, staging]

    steps:
      - name: Checkout code
        uses: actions/checkout@v3

      - name: Deploy Konco App staging
        run: |
          cd ${{ vars.PROJECT_DIR_DEVELOPMENT }}

          echo "Pulling latest code..."
          git fetch --all
          git reset --hard origin/staging

          echo "Installing Dependencies..."
          composer install --no-dev --optimize-autoloader --ignore-platform-req=ext-mongodb
          npm ci

          echo "Building assets..."
          npm run build

          echo "Verifying build..."
          if [ ! -f "public/build/manifest.json" ]; then
            echo "ERROR: Build failed - manifest.json not found!"
            exit 1
          fi

          echo "Build verified successfully"
          cat public/build/manifest.json

          echo "Clearing Cache..."
          php artisan cache:clear
          php artisan config:clear
          php artisan route:clear
          php artisan view:clear
          php artisan optimize:clear

          echo "Optimizing..."
          php artisan config:cache
          php artisan route:cache
          php artisan view:cache

          echo "Deploy Successfully..."

Tahapan staging (web app)

StepAksiCatatan
1Checkout codevia actions/checkout@v3
2Pull latestgit fetch --all && git reset --hard origin/staging
3Install PHP depscomposer install --no-dev --optimize-autoloader
4Install JS depsnpm ci — memakai package-lock.json
5Build Vitenpm run build — output ke public/build/
6Verifikasi buildCek public/build/manifest.json ada — exit 1 bila tidak
7Clear cachecache:clear, config:clear, route:clear, view:clear, optimize:clear
8Optimizeconfig:cache, route:cache, view:cache

Workflow 2 — deploy_staging.yml (dazo-whitelist-api)

yaml
name: Deploy Dazo Whitelist to Staging

on:
  push:
    branches:
      - staging

jobs:
  deploy:
    runs-on: [self-hosted, staging]

    steps:
      - name: Checkout code
        uses: actions/checkout@v3

      - name: Deploy Dazo App staging
        run: |
          cd ${{ vars.PROJECT_DIR_DEVELOPMENT }}

          echo "Clearing Cache..."
          php artisan cache:clear
          php artisan config:clear
          php artisan route:clear
          php artisan optimize:clear
          php artisan config:cache
          php artisan view:cache

          echo "Pulling latest code..."
          git fetch --all
          git reset --hard origin/staging

          echo "Installing Dependencies..."
          composer install --no-dev --optimize-autoloader --ignore-platform-req=ext-mongodb
          npm i

          echo "Deploy Successfully..."

Perbedaan dengan web app staging

Aspekdazo-whitelistdazo-whitelist-api
Build Vitenpm ci && npm run buildnpm i (tanpa build — tidak ada Vite)
Verifikasi manifestAda — exit 1 bila gagalTidak ada
Urutan stepPull → install → build → clear → optimizeClear → pull → install — urutan berbeda
npm ci vs npm inpm ci (strict lockfile)npm i (boleh update lockfile)

Workflow 3 — deploy_production.yml

dazo-whitelist

yaml
name: Deploy Konco to Production

on:
  push:
    branches:
      - production

jobs:
  deploy:
    runs-on: [self-hosted, production]

    steps:
      - name: Deploy
        run: /usr/local/bin/deploy-konco.sh

      - name: Notify on failure
        if: failure()
        run: echo "Deploy failed! Check logs at /var/www/konco/shared/storage/logs"

dazo-whitelist-api

yaml
name: Deploy Konco API to Production

on:
  push:
    branches:
      - production

jobs:
  deploy:
    runs-on: [self-hosted, production]

    steps:
      - name: Deploy
        run: /usr/local/bin/deploy-api.sh

      - name: Notify on failure
        if: failure()
        run: echo "API Deploy failed! Check logs at /var/www/konco-api/shared/storage/logs"

Yang TIDAK ada di CI/CD Konco

AspekStatusCatatan
Workflow pull_requestTidak adaPR hanya di-review manual, tidak ada auto-build/test
Auto-rollbackTidak adaRollback manual via git reset di server
Build artifact uploadTidak adaBuild langsung di runner staging
Test runnerTidak adaTidak ada php artisan test atau Pest di workflow
Linting (Pint)Tidak adaTidak ada step ./vendor/bin/pint --test
Schedule deployTidak adaHanya trigger via push
Multi-environment matrixTidak adaHanya 2 environment: staging & production
Secrets usageTidak terlihatWorkflow tidak memakai secrets.* — semua via self-hosted runner yang sudah trusted

Self-hosted runner setup

AspekKeterangan
Label stagingRunner yang deploy ke server staging
Label productionRunner yang deploy ke server production
TrustedRunner ini punya SSH access ke target server — tidak butuh secrets di GitHub
OSLinux (asumsi — echo bash syntax)
Tools wajibPHP, Composer, Node.js, npm, Git, OpenSSL

Tips operasional

Langkah berikutnya

  • Baru mulai setup local? Baca Local Development.
  • Detail path production & rollback? Lihat Deployment.
  • Engineer baru wajib baca Auth & Security — RSA handshake rentan putus saat deploy bila key tidak sinkron.