ci(deploy): switch to libretech/runner-image:v1 and consolidate

The deploy workflow is now a single job that builds, pushes, and
deploys in one runner. Tag computation moved to docker/metadata-action,
the per-deploy .env perl rewrite is gone (host pins LIBRENOTES_IMAGE
once; main pushes update :main rolling, releases pin to :vX.Y.Z by
manual edit), and both jobs run in our bespoke runner image whose
runner user already has socket access via group membership.

ci.yml moves to the same image so go/make/node are all available
without per-step apt installs.

Drops compose.prod.yaml (unused, redundant with compose.netcup.yaml).
This commit is contained in:
2026-04-29 12:44:39 +02:00
parent f4230c05b7
commit c580e30097
6 changed files with 74 additions and 148 deletions
+5 -3
View File
@@ -1,9 +1,11 @@
# Server-side .env for netcup deploy. Copy to /srv/librenotes/.env on the host.
# Used by: docker compose -f compose.yaml -f compose.netcup.yaml up -d
# Image to pull. Main pushes update :main; tag pushes pin to immutable
# tags such as :v0.1.0. The deploy workflow rewrites this line on tag
# pushes; rollback is `perl -i -pe 's|...|=...:vX.Y.Z|' .env && up -d`.
# Image to pull. The default `:main` rolls forward — main pushes
# rebuild and push the same tag, so `compose pull` picks up the new
# digest without rewriting this file. To pin a release (or roll back),
# edit this line to an immutable tag such as :v0.1.0 and re-run
# `docker compose -f compose.yaml -f compose.netcup.yaml pull && up -d`.
LIBRENOTES_IMAGE=git.librete.ch/public/librenotes:main
# Public origin (caddy reverse-proxies to librenotes:8080)