diff --git a/.gitea/workflows/build.yml b/.gitea/workflows/build.yml index 154d406..dfe370e 100644 --- a/.gitea/workflows/build.yml +++ b/.gitea/workflows/build.yml @@ -108,6 +108,25 @@ jobs: run: | docker push "${REGISTRY_HOST}/${PAGE_FETCHER_API_IMAGE}:${IMAGE_TAG}" + # Watchtower's poll is the fallback, not the mechanism: 30s on staging but 300s on + # production, so without this a green run can sit five minutes ahead of the deploy it + # claims to have made. Copied from easyDent, including the soft failure -- an unset + # secret or an unreachable API must degrade to the poll, never fail the build. + - name: Trigger Watchtower redeploy + env: + URL_STAGING: ${{ secrets.WATCHTOWER_URL_STAGING }} + URL_PRODUCTION: ${{ secrets.WATCHTOWER_URL_PRODUCTION }} + TOKEN: ${{ secrets.WATCHTOWER_TOKEN }} + run: | + if [ "${IMAGE_TAG}" = "production" ]; then URL="${URL_PRODUCTION}"; else URL="${URL_STAGING}"; fi + if [ -n "${URL}" ] && [ -n "${TOKEN}" ]; then + echo "Triggering Watchtower at ${URL}" + curl -sf -m 30 -H "Authorization: Bearer ${TOKEN}" "${URL}" && echo " -> redeploy triggered" \ + || echo " -> trigger failed; Watchtower will still pick it up on the next poll" + else + echo "Watchtower push-trigger not configured (WATCHTOWER_* secrets unset); relying on the poll interval." + fi + - name: Reclaim disk space (keep recent build cache) if: always() run: |