test-env: podman-compose fresh-Debian harness + ssh/rsync deploy shims

Add a test environment that simulates a blank Debian trixie box (systemd
+ sshd container) and routes the project's real 
📦 Linting CSS + JS (biome)…
Checked 71 files in 140ms. No fixes applied.

📦 Building CSS bundles…
🎨 Building CSS bundles…

  ✓ base.min.css (22,317 bytes)
  ✓ admin.min.css (55,602 bytes)
  ✓ form.min.css (41,855 bytes)
  ✓ public.min.css (4,310 bytes)
  ✓ tfe.min.css (9,089 bytes)
  ✓ repertoire.min.css (13,166 bytes)
  ✓ content-page.min.css (3,683 bytes)
  ✓ not-found.min.css (672 bytes)
  ✓ system.min.css (7,408 bytes)
  ✓ file-access.min.css (3,733 bytes)
  ✓ form-base.min.css (19,110 bytes)
  ✓ partage-form.min.css (37,229 bytes)

✅ CSS bundles done — 218,174 bytes total


📦 Building JS bundles…
📦 Building JS bundles…

  ✓ admin.min.js (60,911 bytes)
  ✓ public.min.js (22,022 bytes)
  ✓ form.min.js (41,547 bytes)
  ✓ partage.min.js (42,441 bytes)

✅ JS bundles done


✅ Build complete


              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=461/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=458/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=411/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=411/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=401/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=360/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=325/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=319/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=309/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=302/469)
              0   0%    0.00kB/s    0:00:00 (xfr#0, to-chk=280/469)
            700   0%    0.00kB/s    0:00:00  
         55,602   1%   52.36MB/s    0:00:00 (xfr#1, to-chk=265/469)
         55,602   1%   52.36MB/s    0:00:00 (xfr#1, to-chk=250/469)
        116,513   2%  110.45MB/s    0:00:00 (xfr#2, to-chk=264/469)
        138,830   2%  131.73MB/s    0:00:00 (xfr#3, to-chk=263/469)
        142,513   2%  135.24MB/s    0:00:00 (xfr#4, to-chk=262/469)
        146,246   2%  138.80MB/s    0:00:00 (xfr#5, to-chk=261/469)
        165,356   2%  157.03MB/s    0:00:00 (xfr#6, to-chk=260/469)
        207,211   3%  196.94MB/s    0:00:00 (xfr#7, to-chk=259/469)
        248,758   4%  236.57MB/s    0:00:00 (xfr#8, to-chk=258/469)
        249,430   4%  237.21MB/s    0:00:00 (xfr#9, to-chk=257/469)
        286,659   5%  272.71MB/s    0:00:00 (xfr#10, to-chk=256/469)
        329,100   5%  313.19MB/s    0:00:00 (xfr#11, to-chk=255/469)
        333,410   6%  317.30MB/s    0:00:00 (xfr#12, to-chk=254/469)
        355,432   6%  338.30MB/s    0:00:00 (xfr#13, to-chk=253/469)
        368,598   6%  350.85MB/s    0:00:00 (xfr#14, to-chk=252/469)
        376,006   6%  357.92MB/s    0:00:00 (xfr#15, to-chk=251/469)
        385,095   6%  366.59MB/s    0:00:00 (xfr#16, to-chk=250/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=250/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=235/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=230/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=193/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=192/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=189/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=156/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=156/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=147/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=135/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=134/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=129/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=120/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=93/469) 
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=78/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=77/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=71/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=71/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=64/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=43/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=39/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=34/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=33/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=25/469)
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=8/469) 
        385,095   6%    2.96MB/s    0:00:00 (xfr#16, to-chk=0/469)
📋 Deploying nginx configuration…
xamxam.conf

sent 145 bytes  received 125 bytes  540.00 bytes/sec
total size is 10,012  speedup is 37.08
deploy-server.sh

sent 1,089 bytes  received 107 bytes  797.33 bytes/sec
total size is 8,519  speedup is 7.12 recipes to it
via safe ssh/rsync shims, so setup scripts can be validated without touching
production. Includes provision-server-packages.sh, setup.sh/teardown.sh,
server Dockerfile + helper, and the rendered ssh config.

Validated end-to-end against the box:
- provisioning (apt nginx, php8.4-fpm, composer),
- scripts/setup-server.sh (group/user/dir bootstrap),
- just deploy-code (transfer; surfaced the deploy-code --chown regression).
This commit is contained in:
Pontoporeia
2026-09-18 16:26:49 +02:00
parent 3f352b0d26
commit 64fd92b913
14 changed files with 686 additions and 31 deletions
+50 -31
View File
@@ -114,37 +114,8 @@ deploy: build deploy-code deploy-nginx deploy-deps deploy-migrate
deploy-code:
# Sync application code only (no Composer deps, no migrations, no nginx config).
# nginx + server-side setup are handled by `deploy-nginx` (via deploy).
rsync -vur --progress --delete \
--chown="www-data:xamxam" \
--exclude '/vendor' \
--exclude 'tests' \
--exclude '*.md' \
--exclude '.git*' \
--exclude '.jj' \
--exclude '.claude' \
--exclude '.pi' \
--exclude '.DS_Store' \
--exclude '.env' \
--exclude 'storage/xamxam.db' \
--exclude 'storage/tfe/' \
--exclude 'storage/these/' \
--exclude 'storage/frart/' \
--exclude 'storage/theses' \
--exclude 'storage/covers' \
--exclude 'storage/backup_*' \
--exclude 'storage/cache/*' \
--exclude 'storage/maintenance.flag' \
--exclude 'storage/fixtures' \
--exclude 'storage/docs' \
--exclude 'storage/tmp/' \
--exclude 'storage/documents/' \
--exclude 'storage/theses/' \
--exclude 'storage/triage/' \
--exclude 'storage/backups/' \
--exclude 'storage/logs/' \
--exclude 'var/' \
--exclude 'composer.json' \
--exclude 'composer.lock' \
rsync -az --info=progress2 --delete \
--exclude-from=.rsync-exclude \
app/ xamxam:/var/www/xamxam/
[group('deploy')]
@@ -621,6 +592,54 @@ backup-snapshot:
# Hot backup using SQLite's .backup API (WAL-safe), then gzip.
@DB_PATH=app/storage/xamxam.db BACKUP_DIR=app/storage/backups RETENTION_DAYS=30 bash scripts/backup-sqlite.sh
# ============================================================================
# Test environment (podman compose — fresh Debian box, host-driven via SSH)
# ============================================================================
# Boot a throwaway podman-compose server that simulates a FRESH Debian machine
# with nothing preinstalled (see test-env/README.md). Generates a test SSH key,
# starts the systemd+sshd container, and renders test-env/ssh/config.
[group('test-env')]
test-env-up:
@bash test-env/scripts/setup.sh
# Run any just recipe against the TEST box. Puts the test-env ssh/rsync shims
# on PATH so every `ssh xamxam …` / `rsync … xamxam:/…` in the recipes is routed
# to the podman container instead of production. The host's ~/.ssh/config is
# left untouched. Default recipe: `deploy`.
# just test-env-run # just deploy
# just test-env-run recipe=deploy-nginx
[group('test-env')]
test-env-run recipe='deploy':
@PATH="$(cd test-env && pwd)/bin:$PATH" just {{recipe}}
# Bootstrap the LAMP stack (nginx + php8.4-fpm + composer) on the fresh box.
# Runs the module's package script through the shim so it targets the test box.
[group('test-env')]
test-env-provision:
@PATH="$(cd test-env && pwd)/bin:$PATH" bash test-env/scripts/provision-server-packages.sh
# Run the project's real role/user/dir setup (scripts/setup-server.sh) against
# the test box through the shim, via the module's own deploy-script flow.
[group('test-env')]
test-env-setup-server:
@echo "▶ Running scripts/setup-server.sh on the test box…"
@PATH="$(cd test-env && pwd)/bin:$PATH" bash -c \
'rsync -a scripts/setup-server.sh xamxam:/tmp/setup-server.sh && \
ssh -t xamxam "sudo DEPLOY_USER=deploy bash /tmp/setup-server.sh" && \
ssh xamxam "rm -f /tmp/setup-server.sh"'
# Check the test box is healthy: ssh, then nginx + php-fpm status + nginx -t.
[group('test-env')]
test-env-status:
@PATH="$(cd test-env && pwd)/bin:$PATH" bash -c \
'ssh xamxam "echo reachable as \$(whoami); sudo nginx -t 2>&1 | tail -1; systemctl is-active nginx php8.4-fpm 2>/dev/null || true"'
# Tear down the whole stack (add -- --keys to also drop the test keypair).
[group('test-env')]
test-env-teardown tidy='':
@bash test-env/scripts/teardown.sh {{tidy}}
# ============================================================================
# Utils
# ============================================================================