build(coolify): use SOURCE_COMMIT build arg for deploynotify

Coolify sets SOURCE_COMMIT automatically; consume it as the build arg
feeding the baked commit SHA instead of a manually-passed GIT_SHA.
This commit is contained in:
tiennm99 committed 2026-06-28 22:15:12 +07:00
1 parent cc547136b7
commit 8edd0f8c27
5 files changed
+26 -22

No files matched your search

+4 -5
View File
@@ -23,9 +23,10 @@ ADMIN_IDS=
# Only the twentyq module needs this. Leave blank to disable that command.
GEMINI_API_KEY=
# GIT_SHA is injected at build time by Coolify for the deploynotify owner DM.
# Leave unset for local `docker compose up` — deploynotify just stays silent.
# GIT_SHA=
# SOURCE_COMMIT is injected as a build arg by Coolify (it sets it automatically)
# for the deploynotify owner DM. Leave unset for local `docker compose up` —
# deploynotify just stays silent.
# SOURCE_COMMIT=
# ====================== Leave UNSET on self-host ==================
# These are AWS-only. cmd/server reads secrets directly from the plain env
@@ -33,7 +34,6 @@ GEMINI_API_KEY=
# credentials and bricks startup. Do NOT set any of them:
# TELEGRAM_BOT_TOKEN_PARAMETER_NAME
# TELEGRAM_WEBHOOK_SECRET_PARAMETER_NAME
# CRON_SHARED_SECRET_PARAMETER_NAME
# GEMINI_API_KEY_PARAMETER_NAME
# STOCK_INCOME_EVENTS_API_TOKEN_PARAMETER_NAME
# GOLD_VNAPP_API_KEY_PARAMETER_NAME
@@ -42,6 +42,5 @@ GEMINI_API_KEY=
# KV_PROVIDER — auto-selects mongodb because MONGO_URL is set
# PORT — defaults to 8080 (internal health server)
# TELEGRAM_WEBHOOK_SECRET — long polling has no webhook
# CRON_SHARED_SECRET — unset → /cron route 404s; the in-process scheduler is the trigger
# GOLD_VNAPP_API_KEY — gold module auto-fetches + caches the key to Mongo
# STOCK/COIN/GOLD *_API_URL overrides — modules use their coded default providers
+7 -6
View File
@@ -6,14 +6,15 @@ RUN go mod download
COPY . .
# GIT_SHA is baked into the binary so internal/deploynotify can DM the owner
# once per new version (parity with the Makefile build). Coolify exposes the
# commit SHA as a build arg — pass it with
# --build-arg GIT_SHA=$(git rev-parse --short HEAD)
# SOURCE_COMMIT is baked into the binary so internal/deploynotify can DM the
# owner once per new version (parity with the Makefile build). Coolify exposes
# the commit SHA as the SOURCE_COMMIT build arg automatically — no manual
# wiring needed. For a manual build, pass it with
# --build-arg SOURCE_COMMIT=$(git rev-parse --short HEAD)
# When unset, deploynotify treats the empty SHA as "stay silent".
ARG GIT_SHA=""
ARG SOURCE_COMMIT=""
RUN CGO_ENABLED=0 GOOS=linux go build \
-ldflags="-s -w -X main.gitSHA=${GIT_SHA}" \
-ldflags="-s -w -X main.gitSHA=${SOURCE_COMMIT}" \
-o /out/server \
./cmd/server
+1 -1
View File
@@ -24,7 +24,7 @@ Disable any module by editing `MODULES` in `template.yaml`.
```
cmd/server/ entrypoint (long polling + in-process cron + HTTP health)
cmd/migrate-dynamo-to-mongo/ one-off DynamoDB → MongoDB Atlas data migrator
internal/server/ HTTP routes (/ health, /cron/{name} manual trigger)
internal/server/ HTTP route (/ health only; cron has no HTTP route)
internal/telegram/ Telegram long-polling bot wrapper
internal/cron/ in-process cron scheduler (replaces EventBridge)
internal/modules/ Module framework, registry, dispatchers, modules
+4 -4
View File
@@ -3,9 +3,9 @@ services:
build:
context: .
args:
# Coolify exposes the commit SHA; pass it so deploynotify DMs the owner
# on each new version. Optional — empty SHA just stays silent.
GIT_SHA: ${GIT_SHA:-}
# Coolify sets SOURCE_COMMIT automatically; passed so deploynotify DMs
# the owner on each new version. Optional — empty SHA just stays silent.
SOURCE_COMMIT: ${SOURCE_COMMIT:-}
# Or pin a prebuilt image instead of building:
# image: ghcr.io/tiennm99/miti99bot:latest
restart: unless-stopped
@@ -24,7 +24,7 @@ services:
# The in-process cron scheduler runs by default — no CRON_MODE.
# PORT defaults to 8080 (internal health server) — omit unless overriding.
# Long polling = no TELEGRAM_WEBHOOK_SECRET, no /webhook, no public domain.
# Leave CRON_SHARED_SECRET unset → /cron route is 404 (scheduler is the trigger).
# Cron is in-process only — there is no /cron HTTP route and no secret.
# Do NOT set any *_PARAMETER_NAME vars (those force an SSM/AWS lookup that
# fails with no AWS creds and bricks startup). See .env.example.
# No stock/coin/gold *_API_URL overrides — modules use their coded default
+10 -6
View File
@@ -39,10 +39,13 @@ Copy [`.env.example`](../.env.example) → `.env` (gitignored) and fill in.
| `ADMIN_IDS` | optional | CSV of admin ids (renamed from `ADMIN_USER_IDS`) |
| `GEMINI_API_KEY` | optional | only the `twentyq` module needs it |
**Leave UNSET on self-host:** all six `*_PARAMETER_NAME` vars (they force an
**Leave UNSET on self-host:** all `*_PARAMETER_NAME` vars (they force an
SSM/AWS lookup that fails with no AWS creds and bricks startup), `KV_PROVIDER`,
`PORT`, `TELEGRAM_WEBHOOK_SECRET`, `CRON_SHARED_SECRET`, `GOLD_VNAPP_API_KEY`,
and the `STOCK/COIN/GOLD *_API_URL` overrides (modules use coded defaults).
`PORT`, `TELEGRAM_WEBHOOK_SECRET`, `GOLD_VNAPP_API_KEY`, and the
`STOCK/COIN/GOLD *_API_URL` overrides (modules use coded defaults).
> Cron runs in-process (`internal/cron`) — there is no `/cron` HTTP route and no
> `CRON_SHARED_SECRET`. The scheduler is the sole trigger; nothing inbound.
## 1. MongoDB Atlas (M0)
@@ -85,9 +88,10 @@ and the `STOCK/COIN/GOLD *_API_URL` overrides (modules use coded defaults).
bot token; a second poller gets HTTP 409, and a second in-process scheduler
double-fires crons. Prefer **stop-first redeploys** so two containers never
overlap near a cron time.
5. **Build arg for deploynotify:** pass `GIT_SHA` (Coolify exposes the commit
SHA) so the owner gets the "new version" DM. Without it, `deploynotify`
stays silent (no crash) — but you lose that notification.
5. **Build arg for deploynotify:** Coolify sets `SOURCE_COMMIT` automatically
and the compose build forwards it, so the owner gets the "new version" DM
with no manual wiring. Without it, `deploynotify` stays silent (no crash) —
but you lose that notification.
6. **Health check:** use Coolify's HTTP monitor against `GET /` (returns
`text/plain` `miti99bot ok`). Do **not** use a compose `healthcheck` — the
distroless image has no shell/curl and `cmd/server` has no `-healthcheck`