Konco di-deploy via GitHub Actions di self-hosted runner. Web app (dazo-whitelist) dan API engine (dazo-whitelist-api) masing-masing punya pipeline terpisah, tetapi struktur branch sama: production untuk live, staging untuk testing.
Arsitektur deploy
┌─────────────────────────────────────────────────────────────────────┐
│ GitHub Repository │
│ │
│ dazo-whitelist ──── push production ────► trigger │
│ dazo-whitelist-api ──── push staging ──────► trigger │
└────────────────────────────────┬────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────────┐
│ GitHub Actions (self-hosted runner) │
│ │
│ ┌─────────────────────────┐ ┌─────────────────────────────┐ │
│ │ label: production │ │ label: staging │ │
│ │ - deploy-konco.sh │ │ - composer install --no-dev│ │
│ │ - deploy-api.sh │ │ - npm ci && npm run build │ │
│ │ (SSH ke server prod) │ │ - artisan cache:clear │ │
│ │ │ │ - artisan optimize │ │
│ └─────────────────────────┘ └─────────────────────────────┘ │
└────────────────────────────────┬────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────────┐
│ Target Server (self-hosted) │
│ │
│ /var/www/konco/ /var/www/konco-api/ │
│ (web app — port 8000 atau (API engine — port 8081 atau │
│ di balik Nginx/Apache) di balik Nginx/Apache) │
│ storage/rsa_keys/private_key.pem ←──→ tabel applications │
│ storage/logs/ storage/logs/ │
└─────────────────────────────────────────────────────────────────────┘Branch convention
| Branch | Tujuan | Runner label | Trigger |
|---|---|---|---|
production | Live production | self-hosted, production | push ke production |
staging | Staging/testing | self-hosted, staging | push ke staging |
features/* | Development | — | PR ke staging |
enhancements/* | Development | — | PR ke staging |
Pipeline staging
dazo-whitelist (deploy_staging.yml)
Eksekusi langsung di self-hosted runner:
cd $PROJECT_DIR_DEVELOPMENT
git fetch --all
git reset --hard origin/staging
composer install --no-dev --optimize-autoloader --ignore-platform-req=ext-mongodb
npm ci
npm run build
# Verifikasi build — wajib manifest.json ada
if [ ! -f "public/build/manifest.json" ]; then
echo "ERROR: Build failed - manifest.json not found!"
exit 1
fi
php artisan cache:clear
php artisan config:clear
php artisan route:clear
php artisan view:clear
php artisan optimize:clear
php artisan config:cache
php artisan route:cache
php artisan view:cachedazo-whitelist-api (deploy_staging.yml)
Lebih ringan — tidak ada build Vite:
cd $PROJECT_DIR_DEVELOPMENT
php artisan cache:clear
php artisan config:clear
php artisan route:clear
php artisan optimize:clear
php artisan config:cache
php artisan view:cache
git fetch --all
git reset --hard origin/staging
composer install --no-dev --optimize-autoloader --ignore-platform-req=ext-mongodb
npm iPipeline production
Pipeline produksi menyembunyikan detail — tidak menjalankan build di runner, melainkan memanggil script shell di target server via SSH.
dazo-whitelist (deploy_production.yml)
jobs:
deploy:
runs-on: [self-hosted, production]
steps:
- name: Deploy
run: /usr/local/bin/deploy-konco.sh
- name: Notify on failure
if: failure()
run: echo "❌ Deploy failed! Check logs at /var/www/konco/shared/storage/logs"dazo-whitelist-api (deploy_production.yml)
jobs:
deploy:
runs-on: [self-hosted, production]
steps:
- name: Deploy
run: /usr/local/bin/deploy-api.sh
- name: Notify on failure
if: failure()
run: echo "❌ API Deploy failed! Check logs at /var/www/konco-api/shared/storage/logs"Path produksi (asumsi)
| Repo | Path produksi | Log path |
|---|---|---|
dazo-whitelist | /var/www/konco/ | /var/www/konco/shared/storage/logs |
dazo-whitelist-api | /var/www/konco-api/ | /var/www/konco-api/shared/storage/logs |
Variabel GitHub Actions
| Variable | Lokasi | Kegunaan |
|---|---|---|
PROJECT_DIR_DEVELOPMENT | repo settings → variables | Path project di runner staging |
Post-deploy checklist
Setelah push ke production:
- Cek GitHub Actions — pastikan workflow
Deploy Konco to Production&Deploy Konco API to Productionsukses (green). - Cek log aplikasi —
storage/logs/laravel.logdi/var/www/konco/&/var/www/konco-api/. Cari error401 UnauthorizedatauKey tidak ditemukan!. - Verifikasi handshake RSA — buka web app, login sebagai member, akses menu Facebook Ads. Bila akun iklan muncul, handshake sukses.
- Verifikasi queue worker — cek process
php artisan queue:workjalan di server (API engine butuh ini untuk import massal akun). - Verifikasi scheduler —
php artisan schedule:workatau cron entry di server. Lihat Scheduler. - Verifikasi Reverb — bila realtime tiket dipakai, pastikan WebSocket server jalan.
Rollback
Rollback manual — tidak ada fitur auto-rollback di workflow:
# Di server target
cd /var/www/konco
git log --oneline -10
git reset --hard <commit-hash-yang-stable>
php artisan optimize:clear
# Restart PHP-FPM bila perluLakukan serupa untuk dazo-whitelist-api di /var/www/konco-api.
Langkah berikutnya
- Detail workflow file? Lihat CI/CD.
- Engineer baru wajib baca Auth & Security — RSA handshake rentan putus saat deploy bila key tidak sinkron.