name: Deploy # Deploy on every push to master (and allow manual runs from the Actions tab). on: push: branches: [master] workflow_dispatch: jobs: deploy: # `docker` runner => node:22-bookworm image WITH the Docker socket available, # so `docker build` / `docker run` control the host's Docker daemon. runs-on: docker steps: - name: Checkout uses: actions/checkout@v4 # The `node:22-bookworm` job image has the Docker socket mounted but not # the docker CLI. Install just the static client binary so `docker ...` # commands can talk to the host's Docker daemon. - name: Install Docker CLI run: | if ! command -v docker >/dev/null 2>&1; then curl -fsSL https://download.docker.com/linux/static/stable/x86_64/docker-27.3.1.tgz \ | tar -xz -C /usr/local/bin --strip-components=1 docker/docker fi docker version # Build the site into an nginx image (see Dockerfile). Tagged with the # commit SHA for traceability, plus :latest for convenience. - name: Build image run: | docker build -t altricade-portfolio:${{ github.sha }} -t altricade-portfolio:latest . # Replace the running container with the freshly built image. # -p 8080:80 publishes the container on host port 8080. # Point Nginx Proxy Manager's proxy host at: :8080 # (Or, if NPM runs in Docker, put this container on NPM's network and # forward to altricade-portfolio:80 instead — see note below.) - name: Deploy container run: | docker rm -f altricade-portfolio 2>/dev/null || true docker run -d \ --name altricade-portfolio \ --restart unless-stopped \ -p 8080:80 \ altricade-portfolio:latest # Free disk on the shared runner by dropping old, untagged images. - name: Prune old images run: docker image prune -f