feat(deploy): prisma migration history, /version, galactus standalone deploy
Build and Push Images / Build jorgecuadros-web (push) Successful in 1m49s
Build and Push Images / Build jorgecuadros-api (push) Successful in 2m2s

Closes the gap between "what tag did I deploy" and "what is actually running",
and gives the schema a history that can be reasoned about across releases.

Migrations
- Baseline the existing schema as 0000_init (migrate diff --from-empty). The
  schema had only ever been applied with `prisma db push`, so no history
  existed and schema state was disconnected from app version. Existing
  databases must be baselined once with `migrate resolve --applied 0000_init`;
  the workflows print this remedy on P3005.
- Run `prisma migrate deploy` as a deploy STEP, not the container CMD — as a
  CMD, N replicas would race each other applying the same migration.

Version reporting
- GET /version on the API reports the APP_VERSION / GIT_SHA / BUILD_DATE that
  build.yml already baked into both images but nothing ever read.
- The web footer shows the web build and flags an api/web mismatch. The two
  cannot drift at build time (one matrix run) but can at deploy time.
- Both deploy workflows now fail if the running API does not report the tag
  that was dispatched — a stack naming a tag is not proof of what is running.
- scripts/set-version.mjs stamps every package.json, which had all sat at
  0.1.0 while real releases shipped as v1.x.

Pre-migrate backup
- deploy/scripts/pre-migrate-backup.mjs dumps the database from INSIDE the
  still-running old API container over Portainer's Docker API, so the file
  lands in the volume the Operaciones restore screen reads. A dump taken on
  the CI runner would be unreachable by the only restore path we have.
  Verifies the artefact with `gzip -t` before letting the migration proceed.

galactus
- deploy/galactus/*.compose.yml: standalone-Docker ports of the Swarm stacks.
  Plain compose silently ignores `deploy:`, so restart_policy becomes
  `restart: unless-stopped` — without it nothing returns after a host reboot.
- .gitea/workflows/deploy-galactus.yml drives endpoint 3 with its own secrets.

Fixes
- deploy.yml passed `endpoint_id` and `pull_image` to
  cssnr/portainer-stack-deploy-action, which has no such inputs (they are
  `endpoint` and `pull`). The endpoint was silently never set.

docs/DEPLOY_AND_MIGRATIONS.md documents expand/contract as the rule for schema
changes: Prisma has no down-migrations, so a code rollback never rolls the
schema back, and restoring the replication master from a dump diverges every
replica.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-30 11:41:12 -07:00
co-authored by Claude Opus 5
parent 9ba5d2d09a
commit 4ee7ec71f0
18 changed files with 1677 additions and 8 deletions
+32
View File
@@ -162,6 +162,38 @@ button {
}
}
/* Deployed-build line. Quiet by default — it only needs to be legible when
someone is verifying a release or a rollback. */
.shell-footer {
max-width: var(--shell-max);
margin: 0 auto;
padding: 1rem 1.75rem 1.75rem;
display: flex;
flex-wrap: wrap;
align-items: baseline;
gap: 0.75rem;
font-size: 0.75rem;
color: var(--muted-2);
border-top: 1px solid var(--line);
}
.shell-footer-build {
font-family: var(--font-mono);
font-variant-numeric: tabular-nums;
cursor: help;
}
.shell-footer-warn {
color: var(--negative);
background: var(--negative-tint);
border-radius: var(--radius-sm);
padding: 0.0625rem 0.375rem;
font-weight: 600;
}
@media (max-width: 640px) {
.shell-footer {
padding: 1rem 1rem 1.5rem;
}
}
.eyebrow {
font-family: var(--font-sans);
text-transform: uppercase;
+7 -1
View File
@@ -1,5 +1,6 @@
import type { ReactNode } from "react";
import "./globals.css";
import { readBuildInfoFromEnv } from "@/lib/build-info";
export const metadata = {
title: "Jorge Cuadros & Asociados — Plataforma",
@@ -20,6 +21,9 @@ export default function RootLayout({ children }: { children: ReactNode }) {
process.env.API_ORIGIN ??
process.env.NEXT_PUBLIC_API_ORIGIN ??
"http://localhost:3001";
// Same reason as the API origin: read on the server per request so the built
// image is not pinned to one build identity in its client bundle.
const build = readBuildInfoFromEnv();
return (
<html lang="es">
@@ -27,7 +31,9 @@ export default function RootLayout({ children }: { children: ReactNode }) {
{/* Must run before the app bundle so lib/api.ts sees it at import. */}
<script
dangerouslySetInnerHTML={{
__html: `window.__API_ORIGIN__=${JSON.stringify(apiOrigin)};`,
__html:
`window.__API_ORIGIN__=${JSON.stringify(apiOrigin)};` +
`window.__APP_BUILD__=${JSON.stringify(build)};`,
}}
/>
{/* Text-size preference, applied before first paint so the page never