D
Setup

Deployment

Pipeline deploy Konco — branch production & staging, self-hosted GitHub Actions runner, deploy via SSH script (/usr/local/bin/deploy-konco.sh & /usr/local/bin/deploy-api.sh). Web app & API engine deploy terpisah.

Konco di-deploy via GitHub Actions di self-hosted runner. Web app (dazo-whitelist) dan API engine (dazo-whitelist-api) masing-masing punya pipeline terpisah, tetapi struktur branch sama: production untuk live, staging untuk testing.

Arsitektur deploy

text
┌─────────────────────────────────────────────────────────────────────┐
│                        GitHub Repository                            │
│                                                                     │
│   dazo-whitelist          ──── push production ────►  trigger       │
│   dazo-whitelist-api      ──── push staging ──────►  trigger        │
└────────────────────────────────┬────────────────────────────────────┘
                                 │
                                 ▼
┌─────────────────────────────────────────────────────────────────────┐
│                  GitHub Actions (self-hosted runner)                │
│                                                                     │
│   ┌─────────────────────────┐    ┌─────────────────────────────┐   │
│   │ label: production       │    │ label: staging              │   │
│   │  - deploy-konco.sh      │    │  - composer install --no-dev│   │
│   │  - deploy-api.sh        │    │  - npm ci && npm run build  │   │
│   │  (SSH ke server prod)   │    │  - artisan cache:clear      │   │
│   │                         │    │  - artisan optimize         │   │
│   └─────────────────────────┘    └─────────────────────────────┘   │
└────────────────────────────────┬────────────────────────────────────┘
                                 │
                                 ▼
┌─────────────────────────────────────────────────────────────────────┐
│                     Target Server (self-hosted)                     │
│                                                                     │
│   /var/www/konco/                  /var/www/konco-api/               │
│   (web app — port 8000 atau        (API engine — port 8081 atau     │
│    di balik Nginx/Apache)           di balik Nginx/Apache)          │
│   storage/rsa_keys/private_key.pem ←──→ tabel applications          │
│   storage/logs/                    storage/logs/                     │
└─────────────────────────────────────────────────────────────────────┘

Branch convention

BranchTujuanRunner labelTrigger
productionLive productionself-hosted, productionpush ke production
stagingStaging/testingself-hosted, stagingpush ke staging
features/*Development—PR ke staging
enhancements/*Development—PR ke staging

Pipeline staging

dazo-whitelist (deploy_staging.yml)

Eksekusi langsung di self-hosted runner:

bash
cd $PROJECT_DIR_DEVELOPMENT

git fetch --all
git reset --hard origin/staging

composer install --no-dev --optimize-autoloader --ignore-platform-req=ext-mongodb
npm ci
npm run build

# Verifikasi build — wajib manifest.json ada
if [ ! -f "public/build/manifest.json" ]; then
  echo "ERROR: Build failed - manifest.json not found!"
  exit 1
fi

php artisan cache:clear
php artisan config:clear
php artisan route:clear
php artisan view:clear
php artisan optimize:clear

php artisan config:cache
php artisan route:cache
php artisan view:cache

dazo-whitelist-api (deploy_staging.yml)

Lebih ringan — tidak ada build Vite:

bash
cd $PROJECT_DIR_DEVELOPMENT

php artisan cache:clear
php artisan config:clear
php artisan route:clear
php artisan optimize:clear
php artisan config:cache
php artisan view:cache

git fetch --all
git reset --hard origin/staging

composer install --no-dev --optimize-autoloader --ignore-platform-req=ext-mongodb
npm i

Pipeline production

Pipeline produksi menyembunyikan detail — tidak menjalankan build di runner, melainkan memanggil script shell di target server via SSH.

dazo-whitelist (deploy_production.yml)

yaml
jobs:
  deploy:
    runs-on: [self-hosted, production]
    steps:
      - name: Deploy
        run: /usr/local/bin/deploy-konco.sh
      - name: Notify on failure
        if: failure()
        run: echo "❌ Deploy failed! Check logs at /var/www/konco/shared/storage/logs"

dazo-whitelist-api (deploy_production.yml)

yaml
jobs:
  deploy:
    runs-on: [self-hosted, production]
    steps:
      - name: Deploy
        run: /usr/local/bin/deploy-api.sh
      - name: Notify on failure
        if: failure()
        run: echo "❌ API Deploy failed! Check logs at /var/www/konco-api/shared/storage/logs"

Path produksi (asumsi)

RepoPath produksiLog path
dazo-whitelist/var/www/konco//var/www/konco/shared/storage/logs
dazo-whitelist-api/var/www/konco-api//var/www/konco-api/shared/storage/logs

Variabel GitHub Actions

VariableLokasiKegunaan
PROJECT_DIR_DEVELOPMENTrepo settings → variablesPath project di runner staging

Post-deploy checklist

Setelah push ke production:

  1. Cek GitHub Actions — pastikan workflow Deploy Konco to Production & Deploy Konco API to Production sukses (green).
  2. Cek log aplikasi — storage/logs/laravel.log di /var/www/konco/ & /var/www/konco-api/. Cari error 401 Unauthorized atau Key tidak ditemukan!.
  3. Verifikasi handshake RSA — buka web app, login sebagai member, akses menu Facebook Ads. Bila akun iklan muncul, handshake sukses.
  4. Verifikasi queue worker — cek process php artisan queue:work jalan di server (API engine butuh ini untuk import massal akun).
  5. Verifikasi scheduler — php artisan schedule:work atau cron entry di server. Lihat Scheduler.
  6. Verifikasi Reverb — bila realtime tiket dipakai, pastikan WebSocket server jalan.

Rollback

Rollback manual — tidak ada fitur auto-rollback di workflow:

bash
# Di server target
cd /var/www/konco
git log --oneline -10
git reset --hard <commit-hash-yang-stable>
php artisan optimize:clear
# Restart PHP-FPM bila perlu

Lakukan serupa untuk dazo-whitelist-api di /var/www/konco-api.

Langkah berikutnya

  • Detail workflow file? Lihat CI/CD.
  • Engineer baru wajib baca Auth & Security — RSA handshake rentan putus saat deploy bila key tidak sinkron.