From e6e46a14272006db79b90b72228a457a02f558ce Mon Sep 17 00:00:00 2001 From: archipelago Date: Mon, 5 Oct 2026 15:34:41 -0400 Subject: [PATCH] fix: build demo AIUI from the reviewed source revision --- .dockerignore | 8 +++++++- .gitea/workflows/demo-images.yml | 4 ++++ .github/workflows/demo-images.yml | 4 ++++ demo-deploy/README.md | 15 +++++++++++++++ docker-compose.demo.yml | 1 + docs/release-1.9.0-acceptance.md | 21 +++++++++++++++++++++ neode-ui/Dockerfile.web | 15 +++++++++++++-- scripts/build-aiui.sh | 16 ++++++++++++++-- 8 files changed, 79 insertions(+), 5 deletions(-) diff --git a/.dockerignore b/.dockerignore index f323aac2..3db492f2 100644 --- a/.dockerignore +++ b/.dockerignore @@ -4,7 +4,13 @@ # Allow neode-ui (frontend + mock backend + docker configs) !neode-ui/ -# Allow demo assets (AIUI pre-built dist) +!aiui/ +aiui/**/node_modules +aiui/**/dist +aiui/**/.turbo +aiui/**/.build-aiui-last-* + +# Allow curated demo assets !demo/ # Allow the Bitcoin UI + ElectrumX UI mock shells (served from /docker/*) diff --git a/.gitea/workflows/demo-images.yml b/.gitea/workflows/demo-images.yml index ba739508..3ea678e2 100644 --- a/.gitea/workflows/demo-images.yml +++ b/.gitea/workflows/demo-images.yml @@ -17,6 +17,9 @@ on: branches: [main] paths: - 'neode-ui/**' + - 'aiui/**' + - 'scripts/build-aiui.sh' + - '.dockerignore' - 'docker-compose.demo.yml' - '.gitea/workflows/demo-images.yml' workflow_dispatch: @@ -65,6 +68,7 @@ jobs: push: true build-args: | VITE_DEMO=1 + SOURCE_REVISION=${{ github.sha }} tags: | ${{ vars.DEMO_REGISTRY }}/archy-demo-web:demo ${{ vars.DEMO_REGISTRY }}/archy-demo-web:${{ github.sha }} diff --git a/.github/workflows/demo-images.yml b/.github/workflows/demo-images.yml index 9e0f1733..3d6feb61 100644 --- a/.github/workflows/demo-images.yml +++ b/.github/workflows/demo-images.yml @@ -17,6 +17,9 @@ on: branches: [main] paths: - 'neode-ui/**' + - 'aiui/**' + - 'scripts/build-aiui.sh' + - '.dockerignore' - 'docker-compose.demo.yml' - '.github/workflows/demo-images.yml' workflow_dispatch: @@ -65,6 +68,7 @@ jobs: push: true build-args: | VITE_DEMO=1 + SOURCE_REVISION=${{ github.sha }} tags: | ${{ vars.DEMO_REGISTRY }}/archy-demo-web:demo ${{ vars.DEMO_REGISTRY }}/archy-demo-web:${{ github.sha }} diff --git a/demo-deploy/README.md b/demo-deploy/README.md index 3d553f27..48a84db0 100644 --- a/demo-deploy/README.md +++ b/demo-deploy/README.md @@ -31,3 +31,18 @@ redeploy here. No source lives in this repo. - **Wallet/Bitcoin** — signet-flavored; use the in-UI faucet for test sats. - **Files** — real per-session upload/rename/delete, 50 MB quota, wiped on reap. - **Intro** — replays once per calendar day per browser. + +## Building a reviewed demo revision + +The web image builds both the dashboard and AIUI from the checked-out source; +it does not use the historical `demo/aiui` bundle. CI supplies the full commit +as `SOURCE_REVISION`. For a local source build, run: + +```sh +SOURCE_REVISION=$(git rev-parse HEAD) docker compose -f docker-compose.demo.yml build +``` + +AIUI uses its frozen dependency lockfile, type checking and the canonical +`/aiui/` build verifier. Its `BUILD-INFO` identifies that exact source revision. +Prepare and test the images before changing the public demo stack; retain the +previous image IDs for rollback. diff --git a/docker-compose.demo.yml b/docker-compose.demo.yml index bca2b7c3..8299cbbe 100644 --- a/docker-compose.demo.yml +++ b/docker-compose.demo.yml @@ -44,6 +44,7 @@ services: dockerfile: neode-ui/Dockerfile.web args: VITE_DEMO: "1" + SOURCE_REVISION: ${SOURCE_REVISION:?Set SOURCE_REVISION to git rev-parse HEAD} container_name: archy-demo-web ports: - "2100:80" diff --git a/docs/release-1.9.0-acceptance.md b/docs/release-1.9.0-acceptance.md index 3cd6ba1d..042d6963 100644 --- a/docs/release-1.9.0-acceptance.md +++ b/docs/release-1.9.0-acceptance.md @@ -696,3 +696,24 @@ and this qualified helper; an A5 restart can reinstall its older helper. Do not claim final persistence until the new binary is deployed and restart is retested. No certificate verification was disabled for a public application or upstream. Raw-IP/unknown-SNI negative routing probes alone bypass hostname matching. + +### NPM final source qualification and demo packaging + +Backend source e0b2181a: all1,681 isolated tests pass (zero failures, four +explicit ignores). Corrected nested-layout NPM integration also passes real +local ACME issuance/renewal,40 cross-certificate TLS requests, WSS, ACLs, +restart, failed-bind rollback and host enable/delete propagation. Real public +Let’s Encrypt staging issuance plus forced renewal pass on migrated Shorty; +production certificate files and NPM container identity/start time are unchanged. +Evidence: `/tmp/archy-190-npm-guard-final-backend-tests.log`, +`/tmp/archy-190-npm-multicert-nested-acme.log`, +`/tmp/archy-190-shorty-migrated-staging-acme.log`. +Optimized build and final deployment/restart acceptance are still pending. + +Demo image preparation found the web Dockerfile copied historical prebuilt AIUI. +It now builds the current source with the canonical script and frozen lockfile, +with explicit source revision for archive/container builds. Both CI workflows +track AIUI changes and pass the checkout revision. Actual image qualification +and public demo deployment remain pending. The demo/release VPS currently has +under1GiB free disk; capacity must be resolved before image/artifact publication. +No running container, volume, release or repository was deleted. diff --git a/neode-ui/Dockerfile.web b/neode-ui/Dockerfile.web index ff00b812..044526cf 100644 --- a/neode-ui/Dockerfile.web +++ b/neode-ui/Dockerfile.web @@ -1,3 +1,14 @@ +FROM node:22-alpine AS aiui-builder +RUN apk add --no-cache bash git coreutils findutils && corepack enable +WORKDIR /source +COPY aiui/ ./aiui/ +COPY scripts/build-aiui.sh ./scripts/build-aiui.sh +ARG SOURCE_REVISION +ARG VITE_DEMO=1 +RUN test -n "$SOURCE_REVISION" && \ + if [ "$VITE_DEMO" = "1" ] || [ "$VITE_DEMO" = "true" ]; then export VITE_DEMO_CONTENT=true; fi && \ + ARCHY_SOURCE_REVISION="$SOURCE_REVISION" bash scripts/build-aiui.sh + FROM node:22-alpine AS builder WORKDIR /app @@ -49,8 +60,8 @@ FROM nginx:alpine # Copy built files to nginx COPY --from=builder /app/dist /usr/share/nginx/html -# Copy AIUI pre-built dist -COPY demo/aiui/ /usr/share/nginx/html/aiui/ +# Build AIUI from the same source revision as the dashboard. +COPY --from=aiui-builder /source/aiui/packages/app/dist/ /usr/share/nginx/html/aiui/ # Copy nginx config template and entrypoint COPY neode-ui/docker/nginx-demo.conf /etc/nginx/nginx.conf.template diff --git a/scripts/build-aiui.sh b/scripts/build-aiui.sh index 67a74a76..5b9a92a6 100755 --- a/scripts/build-aiui.sh +++ b/scripts/build-aiui.sh @@ -45,6 +45,18 @@ AIUI_APP_DIR="$AIUI_ROOT/packages/app" AIUI_DIST="$AIUI_APP_DIR/dist" AIUI_MOUNT_PATH="/aiui/" +# Source archives/container contexts omit .git. Require their caller to supply +# the exact checkout revision; normal node builds always use the real checkout. +if git -C "$PROJECT_DIR" rev-parse --verify HEAD >/dev/null 2>&1; then + SOURCE_REVISION="$(git -C "$PROJECT_DIR" rev-parse HEAD)" +else + SOURCE_REVISION="${ARCHY_SOURCE_REVISION:-}" +fi +if [[ ! "$SOURCE_REVISION" =~ ^[0-9a-f]{40}$ ]]; then + echo "FATAL: a full source commit is required (ARCHY_SOURCE_REVISION for archives)." >&2 + exit 1 +fi + timestamp() { echo "[$(date +%H:%M:%S)]"; } # ── require_base_path ────────────────────────────────────────────────── @@ -113,7 +125,7 @@ verify_dist() { # Attribute this build to THIS repo's own current commit (D-19: no # second-repo pin file — this repo's own commit IS the answer now). local commit_sha - commit_sha="$(git -C "$PROJECT_DIR" rev-parse HEAD)" + commit_sha="$SOURCE_REVISION" { echo "commit=$commit_sha" echo "built_at=$(date -u +%Y-%m-%dT%H:%M:%SZ)" @@ -178,4 +190,4 @@ echo "$(timestamp) Building AIUI (vue-tsc --noEmit && vite build)..." echo "$(timestamp) Verifying dist..." verify_dist -echo "$(timestamp) AIUI build OK — $AIUI_DIST attributable to $(git -C "$PROJECT_DIR" rev-parse --short HEAD)" +echo "$(timestamp) AIUI build OK — $AIUI_DIST attributable to ${SOURCE_REVISION:0:8}"