diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..32264f9 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,16 @@ +.git +.gitea +node_modules +vendor +.env +.env.* +!.env.example +storage/logs +storage/framework/cache +storage/framework/sessions +storage/framework/views +storage/debugbar +npm-debug.log +Dockerfile +docker-compose.yml +docker-compose.staging.yml diff --git a/.env.staging b/.env.staging new file mode 100644 index 0000000..4f366ca --- /dev/null +++ b/.env.staging @@ -0,0 +1,84 @@ +APP_NAME=Lumen +APP_ENV=staging +APP_KEY=WbPGkYNmXZ6ZQplGlvl0iZ7zyW1b09xa +APP_DEBUG=true +APP_URL=http://127.0.0.1:8090 +APP_TIMEZONE=Asia/Kuala_Lumpur + +# Unique host ports — change these if they collide with other containers on the server. +# Host nginx should proxy the staging domain to 127.0.0.1:${HTTP_PORT} +HTTP_PORT=8090 +MYSQL_PUBLISH_PORT=3308 + +LOG_CHANNEL=stack +LOG_LEVEL=debug +LOG_SLACK_WEBHOOK_URL= + +DB_CONNECTION=mysql +DB_HOST=mysql +DB_PORT=3306 +DB_DATABASE=erahn_xtra +DB_USERNAME=root +DB_PASSWORD=root + +DB_CONNECTION_7=mysql +DB_HOST_7=mysql +DB_PORT_7=3306 +DB_DATABASE_7=master_erahn +DB_USERNAME_7=root +DB_PASSWORD_7=root + +DB_CONNECTION_2=mysql +DB_HOST_2=mysql +DB_PORT_2=3306 +DB_DATABASE_2=erahn_xtra +DB_USERNAME_2=root +DB_PASSWORD_2=root + +DB_CONNECTION_3=mysql +DB_HOST_3=mysql +DB_PORT_3=3306 +DB_DATABASE_3=erahn_baling +DB_USERNAME_3=root +DB_PASSWORD_3=root + +DB_CONNECTION_4=mysql +DB_HOST_4=mysql +DB_PORT_4=3306 +DB_DATABASE_4=arrahn_ld +DB_USERNAME_4=root +DB_PASSWORD_4=root + +DB_CONNECTION_5=mysql +DB_HOST_5=mysql +DB_PORT_5=3306 +DB_DATABASE_5=erahn_segamat +DB_USERNAME_5=root +DB_PASSWORD_5=root + +DB_CONNECTION_7=mysql +DB_HOST_7=mysql +DB_PORT_7=3306 +DB_DATABASE_7=master_erahn +DB_USERNAME_7=root +DB_PASSWORD_7=root + +DB_CONNECTION_6=mysql +DB_HOST_6=mysql +DB_PORT_6=3306 +DB_DATABASE_6=erahn_test +DB_USERNAME_6=root +DB_PASSWORD_6=root + +# DB_CONNECTION_8=mysql +# DB_HOST_8=mysql +# DB_PORT_8=3306 +# DB_DATABASE_8=arrahn_klanas +# DB_USERNAME_8=spider +# DB_PASSWORD_8=G0dz!ll42020 + +TENNANT_MASTER_DB=master_erahn +TENNANT_KAUNTER_DB=kaunter_erahn + +CACHE_DRIVER=file +QUEUE_CONNECTION=sync \ No newline at end of file diff --git a/.gitea/workflows/build.yml b/.gitea/workflows/build.yml new file mode 100644 index 0000000..dc3a55e --- /dev/null +++ b/.gitea/workflows/build.yml @@ -0,0 +1,49 @@ +name: Build Docker Image + +on: + push: + branches: + - staging + tags: + - "v*" + workflow_dispatch: + +jobs: + build-backend: + runs-on: docker + + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Login to Docker registry + run: | + echo "${{ secrets.REGISTRY_PASSWORD }}" | \ + docker login git.koppkb.com \ + -u "${{ secrets.REGISTRY_USERNAME }}" \ + --password-stdin + + - name: Build & push backend image + run: | + set -e + + IMAGE="git.koppkb.com/kopkb/api_arrahn" + TAGS="-t ${IMAGE}:${{ gitea.sha }}" + + if [ "${{ gitea.ref_type }}" = "tag" ] && echo "${{ gitea.ref_name }}" | grep -q '^v'; then + TAGS="${TAGS} -t ${IMAGE}:${{ gitea.ref_name }}" + fi + + if [ "${{ gitea.ref_name }}" = "staging" ]; then + TAGS="${TAGS} -t ${IMAGE}:staging" + fi + + echo "Building and pushing backend: ${TAGS}" + docker buildx build \ + --target staging \ + --platform linux/amd64 \ + --cache-from type=registry,ref=${IMAGE}:buildcache,ignore-error=true \ + --cache-to type=registry,ref=${IMAGE}:buildcache,mode=max \ + -f docker/php/Dockerfile \ + ${TAGS} \ + --push . diff --git a/.gitea/workflows/deploy-staging.yml b/.gitea/workflows/deploy-staging.yml new file mode 100644 index 0000000..8fd6daa --- /dev/null +++ b/.gitea/workflows/deploy-staging.yml @@ -0,0 +1,122 @@ +name: Deploy to Staging + +on: + workflow_dispatch: + inputs: + image_tag: + description: "Docker image tag to deploy (commit SHA, staging, or v*)" + required: true + default: "staging" + type: string + +env: + APP_IMAGE: git.koppkb.com/kopkb/api_arrahn + DEPLOY_DIR: /home/arrahn/Project/api_arrahn + +jobs: + deploy: + runs-on: host + + steps: + - name: Checkout repository + uses: actions/checkout@v4 + with: + ref: ${{ inputs.image_tag }} + + - name: Login to Docker registry + run: | + echo "${{ secrets.REGISTRY_PASSWORD }}" | \ + docker login git.koppkb.com \ + -u "${{ secrets.REGISTRY_USERNAME }}" \ + --password-stdin + + - name: Verify image exists in registry + run: | + set -e + IMAGE_TAG="${{ inputs.image_tag }}" + IMAGE="${APP_IMAGE}:${IMAGE_TAG}" + + echo "Checking if image exists: ${IMAGE}" + if ! docker manifest inspect "${IMAGE}" > /dev/null 2>&1; then + echo "ERROR: Image ${IMAGE} does not exist in registry!" + echo "Run the Build Docker Image workflow first." + exit 1 + fi + echo "✓ ${IMAGE} found" + + - name: Pull Docker image + run: | + set -e + IMAGE_TAG="${{ inputs.image_tag }}" + docker pull "${APP_IMAGE}:${IMAGE_TAG}" + echo "✓ Image pulled successfully" + + - name: Sync compose file and deploy + run: | + set -e + IMAGE_TAG="${{ inputs.image_tag }}" + + mkdir -p "${DEPLOY_DIR}/docker/nginx" "${DEPLOY_DIR}/docker/mysql" + cp docker-compose.staging.yml "${DEPLOY_DIR}/docker-compose.yml" + cp docker/nginx/default.conf "${DEPLOY_DIR}/docker/nginx/default.conf" + cp -R docker/mysql/init "${DEPLOY_DIR}/docker/mysql/" + + if [ ! -f "${DEPLOY_DIR}/.env.staging" ]; then + if [ -f .env.staging ]; then + cp .env.staging "${DEPLOY_DIR}/.env.staging" + echo "Copied .env.staging from repo (first deploy). Edit ${DEPLOY_DIR}/.env.staging on the server if needed." + else + echo "ERROR: ${DEPLOY_DIR}/.env.staging is missing on the server" + exit 1 + fi + fi + + cd "${DEPLOY_DIR}" + + export APP_IMAGE + export IMAGE_TAG + + docker compose --env-file .env.staging -f docker-compose.yml pull app + docker compose --env-file .env.staging -f docker-compose.yml up -d --no-build --remove-orphans + + echo "✓ Deployed IMAGE_TAG=${IMAGE_TAG}" + + - name: Verify deployment + run: | + set -e + cd "${DEPLOY_DIR}" + + echo "Waiting for services to start..." + sleep 10 + + for SERVICE in app web mysql; do + STATUS=$(docker compose --env-file .env.staging -f docker-compose.yml ps --status running --format '{{.Name}}' "$SERVICE" 2>/dev/null || true) + if [ -z "$STATUS" ]; then + echo "ERROR: ${SERVICE} is not running" + docker compose --env-file .env.staging -f docker-compose.yml ps + docker compose --env-file .env.staging -f docker-compose.yml logs --tail=50 "$SERVICE" || true + exit 1 + fi + echo "✓ ${SERVICE} is running (${STATUS})" + done + + HTTP_PORT=$(grep -E '^HTTP_PORT=' .env.staging 2>/dev/null | cut -d= -f2- | tr -d '"' || true) + HTTP_PORT=${HTTP_PORT:-8090} + + check_health() { + NAME=$1 + URL=$2 + for i in 1 2 3 4 5 6; do + if curl -sf "$URL" > /dev/null; then + echo "✓ ${NAME} health check passed (${URL})" + return 0 + fi + echo "Waiting for ${NAME}... attempt ${i}/6" + sleep 5 + done + echo "ERROR: ${NAME} health check failed (${URL})" + docker compose --env-file .env.staging -f docker-compose.yml logs --tail=50 app web || true + return 1 + } + + check_health "api" "http://127.0.0.1:${HTTP_PORT}/health" diff --git a/bootstrap/.gitignore b/bootstrap/.gitignore new file mode 100644 index 0000000..b49a22a --- /dev/null +++ b/bootstrap/.gitignore @@ -0,0 +1 @@ +/cache \ No newline at end of file diff --git a/docker-compose.staging.yml b/docker-compose.staging.yml new file mode 100644 index 0000000..13b6aac --- /dev/null +++ b/docker-compose.staging.yml @@ -0,0 +1,77 @@ +# Staging stack — isolated from local docker-compose.yml (8080 / 3306) +# and from other apps on the server (unique project name + host ports). +# +# Local: +# docker compose --env-file .env.staging -f docker-compose.staging.yml up -d --build +# +# CI (image already in registry): +# APP_IMAGE=git.koppkb.com/KoPKB/api_arrahn IMAGE_TAG= \ +# docker compose --env-file .env.staging -f docker-compose.staging.yml up -d --no-build +# +# Host nginx reverse-proxies the public domain to 127.0.0.1:${HTTP_PORT}. +# See docker/nginx/host-proxy.example.conf +# +# If 8090 or 3308 is already taken, set HTTP_PORT / MYSQL_PUBLISH_PORT in .env.staging. + +name: api_arrahn_staging + +services: + app: + image: ${APP_IMAGE:-api_arrahn}:${IMAGE_TAG:-staging} + build: + context: . + dockerfile: docker/php/Dockerfile + target: staging + container_name: api_arrahn_staging_app + working_dir: /var/www/html + volumes: + - storage_staging:/var/www/html/storage + - ./.env.staging:/var/www/html/.env.staging:ro + env_file: + - .env.staging + environment: + APP_ENV: staging + USE_STAGING_ENV: "true" + extra_hosts: + - "host.docker.internal:host-gateway" + depends_on: + mysql: + condition: service_healthy + restart: unless-stopped + + web: + image: nginx:1.25-alpine + container_name: api_arrahn_staging_web + ports: + - "${HTTP_PORT:-8090}:80" + volumes: + - ./docker/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro + depends_on: + - app + restart: unless-stopped + + mysql: + image: mysql:8.0 + container_name: api_arrahn_staging_mysql + command: --default-authentication-plugin=mysql_native_password + ports: + - "127.0.0.1:${MYSQL_PUBLISH_PORT:-3308}:3306" + environment: + MYSQL_DATABASE: erahn_xtra + MYSQL_USER: xtrauser + MYSQL_PASSWORD: password + MYSQL_ROOT_PASSWORD: root + volumes: + - mysql_staging_data:/var/lib/mysql + - ./docker/mysql/init:/docker-entrypoint-initdb.d:ro + healthcheck: + test: ["CMD", "mysqladmin", "ping", "-h", "127.0.0.1", "-uroot", "-proot"] + interval: 5s + timeout: 5s + retries: 30 + start_period: 20s + restart: unless-stopped + +volumes: + mysql_staging_data: + storage_staging: diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000..2cab859 --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,40 @@ +services: + app: + build: + context: . + dockerfile: docker/php/Dockerfile + target: development + working_dir: /var/www/html + volumes: + - ./:/var/www/html:cached + environment: + APP_ENV: local + APP_DEBUG: "true" + depends_on: + - mysql + + web: + image: nginx:1.25-alpine + ports: + - "8080:80" + volumes: + - ./:/var/www/html:cached + - ./docker/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro + depends_on: + - app + + mysql: + image: mysql:8.0 + command: --default-authentication-plugin=mysql_native_password + ports: + - "3306:3306" + environment: + MYSQL_DATABASE: erahn_xtra + MYSQL_USER: xtrauser + MYSQL_PASSWORD: password + MYSQL_ROOT_PASSWORD: root + volumes: + - mysql_data:/var/lib/mysql + +volumes: + mysql_data: diff --git a/docker/mysql/init/01-create-databases.sql b/docker/mysql/init/01-create-databases.sql new file mode 100644 index 0000000..9b47955 --- /dev/null +++ b/docker/mysql/init/01-create-databases.sql @@ -0,0 +1,7 @@ +CREATE DATABASE IF NOT EXISTS master_erahn; +CREATE DATABASE IF NOT EXISTS kaunter_erahn; + +GRANT ALL PRIVILEGES ON master_erahn.* TO 'xtrauser'@'%'; +GRANT ALL PRIVILEGES ON kaunter_erahn.* TO 'xtrauser'@'%'; +GRANT ALL PRIVILEGES ON erahn_xtra.* TO 'xtrauser'@'%'; +FLUSH PRIVILEGES; diff --git a/docker/nginx/default.conf b/docker/nginx/default.conf new file mode 100644 index 0000000..223a96c --- /dev/null +++ b/docker/nginx/default.conf @@ -0,0 +1,36 @@ +server { + listen 80; + server_name _; + + root /var/www/html/public; + index index.php index.html; + + charset utf-8; + client_max_body_size 50M; + + location / { + try_files $uri $uri/ @php; + } + + location @php { + include fastcgi_params; + fastcgi_param SCRIPT_FILENAME /var/www/html/public/index.php; + fastcgi_param PATH_INFO $fastcgi_path_info; + fastcgi_pass app:9000; + fastcgi_index index.php; + fastcgi_read_timeout 120s; + } + + location ~ \.php$ { + include fastcgi_params; + fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; + fastcgi_param PATH_INFO $fastcgi_path_info; + fastcgi_pass app:9000; + fastcgi_index index.php; + fastcgi_read_timeout 120s; + } + + location ~ /\.(?!well-known).* { + deny all; + } +} diff --git a/docker/php/Dockerfile b/docker/php/Dockerfile new file mode 100644 index 0000000..172df1c --- /dev/null +++ b/docker/php/Dockerfile @@ -0,0 +1,51 @@ +FROM php:7.4-fpm AS base + +WORKDIR /var/www/html + +RUN apt-get update \ + && apt-get install -y --no-install-recommends \ + git \ + pkg-config \ + unzip \ + libonig-dev \ + libzip-dev \ + libpng-dev \ + libjpeg62-turbo-dev \ + libfreetype6-dev \ + && docker-php-ext-configure gd --with-freetype --with-jpeg \ + && docker-php-ext-install -j"$(nproc)" \ + pdo_mysql \ + mbstring \ + bcmath \ + zip \ + exif \ + gd \ + && rm -rf /var/lib/apt/lists/* + +COPY --from=composer:2 /usr/bin/composer /usr/local/bin/composer + +COPY docker/php/php.ini /usr/local/etc/php/conf.d/app.ini +COPY docker/php/zz-clear-env.conf /usr/local/etc/php-fpm.d/zz-clear-env.conf +COPY docker/php/entrypoint.sh /usr/local/bin/app-entrypoint.sh + +RUN chmod +x /usr/local/bin/app-entrypoint.sh \ + && usermod -u 1000 www-data && groupmod -g 1000 www-data + +ENTRYPOINT ["app-entrypoint.sh"] +CMD ["php-fpm"] + +FROM base AS staging + +COPY --chown=www-data:www-data . /var/www/html + +RUN composer install --no-interaction --prefer-dist --no-dev --optimize-autoloader \ + && mkdir -p \ + storage/logs \ + storage/framework/cache/data \ + storage/framework/views \ + storage/framework/sessions \ + storage/app/public \ + bootstrap/cache \ + && chown -R www-data:www-data storage bootstrap/cache vendor + +FROM base AS development diff --git a/docker/php/entrypoint.sh b/docker/php/entrypoint.sh new file mode 100644 index 0000000..a9951a7 --- /dev/null +++ b/docker/php/entrypoint.sh @@ -0,0 +1,30 @@ +#!/bin/sh +set -e + +cd /var/www/html + +if [ "${USE_STAGING_ENV:-false}" = "true" ] && [ -f .env.staging ]; then + cp .env.staging .env +fi + +if [ -f composer.json ]; then + if [ -f vendor/autoload.php ] && [ "${USE_STAGING_ENV:-false}" = "true" ]; then + : # vendor is baked into the staging image + elif [ "${USE_STAGING_ENV:-false}" = "true" ]; then + composer install --no-interaction --prefer-dist --no-dev --optimize-autoloader + else + composer install --no-interaction --prefer-dist + fi +fi + +mkdir -p \ + storage/logs \ + storage/framework/cache/data \ + storage/framework/views \ + storage/framework/sessions \ + storage/app/public \ + bootstrap/cache + +chown -R www-data:www-data storage bootstrap/cache + +exec docker-php-entrypoint "$@" diff --git a/docker/php/php.ini b/docker/php/php.ini new file mode 100644 index 0000000..3e9df60 --- /dev/null +++ b/docker/php/php.ini @@ -0,0 +1,4 @@ +memory_limit=512M +upload_max_filesize=50M +post_max_size=50M +max_execution_time=120 diff --git a/docker/php/zz-clear-env.conf b/docker/php/zz-clear-env.conf new file mode 100644 index 0000000..edbfb22 --- /dev/null +++ b/docker/php/zz-clear-env.conf @@ -0,0 +1,3 @@ +[www] +; Pass container env vars (from compose env_file) through to PHP workers. +clear_env = no diff --git a/routes/web.php b/routes/web.php index 8d76ddb..a239c1d 100644 --- a/routes/web.php +++ b/routes/web.php @@ -21,6 +21,10 @@ use App\Http\Controllers\TransactionOnlineTrailController; use App\Http\Controllers\Reports\RingkasanHarianController; use App\Transaction; +$router->get('/health', function () { + return response()->json(['status' => 'ok']); +}); + $router->group(['namespace' => '\Rap2hpoutre\LaravelLogViewer'], function() use ($router) { $router->get('logs', 'LogViewerController@index'); }); diff --git a/storage/.gitignore b/storage/.gitignore new file mode 100644 index 0000000..ca5c069 --- /dev/null +++ b/storage/.gitignore @@ -0,0 +1,2 @@ +/debugbar +/framework/sessions \ No newline at end of file