#!/bin/sh # Push this working tree to the NAS and restart it. # # The NAS only accepts password auth, so one ssh master connection is opened # up front and every later step rides on it: you type the password once, not # five times. (macOS's bundled rsync 2.6.9 cannot carry a password through # -e at all — hence tar over ssh.) # # ./deploy/push.sh [user@host] [port] # # The password is never stored here — ssh asks for it on your terminal. To # stop being asked at all, run `ssh-copy-id -p 2222 ericwyuan@192.168.50.64` # once; after that this script runs unattended. # # Never touches .env, .venv or the database on the far side. set -e HOST="${1:-ericwyuan@192.168.50.64}" PORT="${2:-2222}" # Needed for the sudo restart below. Prompted for rather than stored, and only # used over the already-authenticated ssh master connection. PASS="${NAS_PASSWORD:-}" REPO="$(cd "$(dirname "$0")/.." && pwd)" CTL="$(mktemp -u /tmp/garmin-deploy-XXXXXX)" sh_() { ssh -S "$CTL" -o BatchMode=yes "$HOST" "$@"; } cleanup() { ssh -S "$CTL" -O exit "$HOST" 2>/dev/null || true; } trap cleanup EXIT echo "==> connecting to $HOST:$PORT (password prompt follows, once)" ssh -M -S "$CTL" -fN -p "$PORT" -o ControlPersist=300 "$HOST" if [ -z "$PASS" ]; then # Same password as the ssh login; asked for separately because ssh consumed # the first one itself and sudo on the far side needs it on stdin. printf 'sudo password for %s (needed to restart the root-owned service): ' "$HOST" >&2 stty -echo 2>/dev/null; read PASS; stty echo 2>/dev/null; echo >&2 fi # The app dir has moved before; find it rather than assume it. APP=$(sh_ 'for d in ~/apps/garmin-health-lab /volume1/web/garmin-health-lab; do [ -d "$d/backend" ] && { echo "$d"; break; }; done') [ -n "$APP" ] || { echo "cannot find the app dir on $HOST" >&2; exit 1; } echo "==> app dir: $APP" # STATIC_DIR is ./static relative to backend/, which is where start.sh cds to. STATIC="$APP/backend/static" # `cmd && VAR=x` would trip `set -e` when cmd fails, so spell it out. if sh_ "[ -f '$APP/static/index.html' ]" 2>/dev/null; then STATIC="$APP/static" fi echo "==> static dir: $STATIC" # macOS bsdtar writes com.apple.provenance xattrs and ._ resource forks that # the NAS's tar cannot read; it warns once per file and copies nothing useful. TAR="tar czf - --no-xattrs" export COPYFILE_DISABLE=1 echo "==> backend" $TAR --exclude .venv --exclude .env --exclude __pycache__ \ --exclude '*.db' --exclude tests --exclude .pytest_cache \ -C "$REPO/backend" . | sh_ "tar xzf - -C '$APP/backend'" echo "==> static (cleared first, so stale JS chunks do not pile up)" if [ ! -f "$REPO/client/build/index.html" ]; then echo "client/build is missing — run 'npm run build' first" >&2 exit 1 fi sh_ "rm -rf '$STATIC' && mkdir -p '$STATIC'" $TAR -C "$REPO/client/build" . | sh_ "tar xzf - -C '$STATIC'" # The service is started at boot as root (DSM Task Scheduler -> S99garmin.sh), # so logs/error.log and logs/access.log are root-owned. Restarting as # ericwyuan therefore fails instantly — gunicorn cannot open its own error log # — and this went unnoticed for a whole deploy: stop.sh could not kill a root # process either, so the OLD master kept serving :8124, start.sh's health # check saw a 200 and reported "started", and the new code was never loaded. # Hence sudo, matching how the service actually runs. SUDO="echo '$PASS' | sudo -S" echo "==> restart (sudo: the service runs as root, started at boot)" BEFORE=$(sh_ "pgrep -f '$APP/backend/.venv/bin/gunicorn' | tr '\n' ',' " || true) sh_ "cd '$APP' && $SUDO sh deploy/stop.sh >/dev/null 2>&1; sleep 3; $SUDO sh deploy/start.sh" \ || { echo "restart failed" >&2; exit 1; } echo "==> health" sh_ "curl -sf -m 5 -o /dev/null -w 'local api: %{http_code}\n' \ http://127.0.0.1:8124/api/health/status" || echo "local api: unreachable" # A 200 alone proves nothing: it is exactly what a surviving old master # returns. The master pid must have changed for the new code to be loaded. AFTER=$(sh_ "pgrep -f '$APP/backend/.venv/bin/gunicorn' | tr '\n' ',' " || true) if [ -n "$BEFORE" ] && [ "$BEFORE" = "$AFTER" ]; then echo "the gunicorn pids did not change ($AFTER) - the old process is still" >&2 echo "serving and your changes are NOT live. Check $APP/logs/error.log." >&2 exit 1 fi echo "==> gunicorn restarted: $BEFORE -> $AFTER" echo "done. The public URL takes a few seconds longer (frp reconnecting)."