This repository was archived by the owner on Jun 3, 2026. It is now read-only.
fix aws issue #126
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Deploy XMem to the PRODUCTION AWS EC2 instance when changes land on main. | |
| # | |
| # ⚠️ IMPORTANT: This should only fire from the promote-to-production workflow | |
| # merging develop → main. Direct pushes to main should be blocked by branch | |
| # protection rules (Settings → Branches → main → Require PR). | |
| # | |
| # Required GitHub repository secrets: | |
| # EC2_HOST Public DNS, Elastic IP, or hostname | |
| # EC2_USER SSH user (e.g. ubuntu, ec2-user, admin) | |
| # EC2_SSH_KEY Private key (same format as your .pem) | |
| # | |
| # Required repository Variable: | |
| # EC2_DEPLOY_PATH Absolute path on the server (e.g. /home/ubuntu/xmem) | |
| name: Deploy to Production | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| concurrency: | |
| group: deploy-ec2-main | |
| cancel-in-progress: false | |
| jobs: | |
| deploy: | |
| runs-on: ubuntu-latest | |
| environment: | |
| name: production | |
| url: ${{ vars.PRODUCTION_URL }} | |
| permissions: | |
| contents: read | |
| deployments: write | |
| steps: | |
| - name: Create deployment | |
| uses: chrnorm/deployment-action@v2 | |
| id: deployment | |
| with: | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| environment: production | |
| - name: Deploy over SSH | |
| uses: appleboy/ssh-action@v1.2.2 | |
| with: | |
| host: ${{ secrets.EC2_HOST }} | |
| username: ${{ secrets.EC2_USER }} | |
| key: ${{ secrets.EC2_SSH_KEY }} | |
| passphrase: ${{ secrets.EC2_SSH_KEY_PASSPHRASE }} | |
| command_timeout: 20m | |
| script: | | |
| set -euo pipefail | |
| cd "${{ secrets.EC2_DEPLOY_PATH }}" | |
| echo "── Pulling latest main ──" | |
| git fetch origin main | |
| git checkout main | |
| git pull origin main | |
| echo "── Restarting XMem service ──" | |
| sudo systemctl restart xmem | |
| echo "── Waiting for health endpoint ──" | |
| for i in $(seq 1 30); do | |
| HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" http://localhost:8000/health || true) | |
| if [ "$HTTP_CODE" = "200" ]; then | |
| echo "Health check passed (attempt $i)" | |
| exit 0 | |
| fi | |
| echo "Health check attempt $i: HTTP $HTTP_CODE — retrying in 10s" | |
| sleep 10 | |
| done | |
| echo "FATAL: Health check never returned 200 after 300s" | |
| exit 1 | |
| - name: Deployment succeeded | |
| if: success() | |
| uses: chrnorm/deployment-status@v2 | |
| with: | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| deployment-id: ${{ steps.deployment.outputs.deployment_id }} | |
| state: success | |
| environment-url: ${{ vars.PRODUCTION_URL }} | |
| - name: Deployment failed | |
| if: failure() | |
| uses: chrnorm/deployment-status@v2 | |
| with: | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| deployment-id: ${{ steps.deployment.outputs.deployment_id }} | |
| state: failure |