mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-01 14:59:19 +08:00
856fe0ffb6
* fix(docker): upgrade bun to 1.3.14 to unbreak the Next 16.3.0 server
Bun 1.3.13 cannot load Next 16.3.0's compiled server runtime. The app container
runs the Next server under Bun (`oven/bun:1.3.13-slim`, `bun apps/sim/bootstrap.js`),
so every app-page render threw and `/api/health` returned 500:
⨯ Error: Failed to load external module
next/dist/compiled/next-server/app-page-turbo.runtime.prod.js:
TypeError: Expected CommonJS module to have a function wrapper.
If you weren't messing around with Bun's internals, this is a bug in Bun
Isolated to Bun, not Next, by loading that exact module in the real images:
Next 16.2.12 + Bun 1.3.13 -> loads (why staging was fine before)
Next 16.3.0 + Bun 1.3.13 -> CJS wrapper error
Next 16.3.0 + Bun 1.3.14 -> loads
Bun 1.3.14 is the current stable and already fixes it, so this bumps every pin
rather than reverting the framework upgrade, which would only defer the same
latent Bun bug to the next attempt.
Why no gate caught it: local dev machines and this bump's own verification run
Bun 1.3.14, while the container and CI pinned 1.3.13 — and CI only *builds* the
image, it never boots one and probes `/api/health`. A container smoke test in CI
would have caught this before merge; that is worth adding separately.
* fix(docker): align the remaining bun pins with 1.3.14
Two pins were missed in the first pass because the search was scoped to
docker/, package.json and .github/workflows/:
- .devcontainer/Dockerfile still built on oven/bun:1.3.13-alpine
- PI_BUN_VERSION in apps/sim/scripts/pi-sandbox-packages.ts was still 1.3.13,
despite being documented as mirroring the root packageManager field, so Pi
sandbox images would have kept installing the Bun release that cannot load
the Next 16.3.0 server runtime.
Fixed surgically rather than with a repo-wide replace: "1.3.13" also appears
inside SVG path data in apps/sim/components/icons.tsx and
apps/docs/components/icons.tsx, which a blind sed would have corrupted.
87 lines
3.5 KiB
YAML
87 lines
3.5 KiB
YAML
name: Database Migrations
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
environment:
|
|
description: Target environment (production, staging, or dev)
|
|
required: true
|
|
type: string
|
|
workflow_dispatch:
|
|
inputs:
|
|
environment:
|
|
description: Target environment
|
|
required: true
|
|
type: choice
|
|
options:
|
|
- production
|
|
- staging
|
|
- dev
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
migrate:
|
|
name: Apply Database Migrations
|
|
runs-on: ${{ (vars.CI_PROVIDER == '' || vars.CI_PROVIDER == 'blacksmith') && 'blacksmith-4vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
|
timeout-minutes: 45
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
|
|
|
|
- name: Setup Bun
|
|
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
|
|
with:
|
|
bun-version: 1.3.14
|
|
|
|
- name: Cache Bun dependencies
|
|
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5
|
|
with:
|
|
path: |
|
|
~/.bun/install/cache
|
|
node_modules
|
|
**/node_modules
|
|
key: ${{ runner.os }}-bun-${{ hashFiles('**/bun.lock') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-bun-
|
|
|
|
- name: Install dependencies
|
|
run: bun install --frozen-lockfile --ignore-scripts
|
|
|
|
# The expression maps the explicit environment input to exactly one repo
|
|
# secret, so the job never holds another environment's database URL. An
|
|
# unknown environment resolves to empty and the guard below fails the job.
|
|
# MIGRATION_DATABASE_URL is the optional direct (non-pooled) DSN preferred
|
|
# by migrate.ts; when the secret is unset it resolves to empty and the
|
|
# script falls back to DATABASE_URL.
|
|
- name: Apply database schema changes
|
|
working-directory: ./packages/db
|
|
env:
|
|
DATABASE_URL: ${{ inputs.environment == 'production' && secrets.DATABASE_URL || inputs.environment == 'staging' && secrets.STAGING_DATABASE_URL || inputs.environment == 'dev' && secrets.DEV_DATABASE_URL || '' }}
|
|
MIGRATION_DATABASE_URL: ${{ inputs.environment == 'production' && secrets.MIGRATION_DATABASE_URL || inputs.environment == 'staging' && secrets.STAGING_MIGRATION_DATABASE_URL || '' }}
|
|
ENVIRONMENT: ${{ inputs.environment }}
|
|
run: |
|
|
if [ -z "$DATABASE_URL" ]; then
|
|
echo "ERROR: no database URL secret resolved for environment '${ENVIRONMENT}'" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [ "${ENVIRONMENT}" = "dev" ]; then
|
|
echo "Dev environment — pushing schema directly (db:push)"
|
|
# drizzle-kit push needs a TTY to resolve ambiguous renames (--force only
|
|
# covers data-loss). In CI it throws "Interactive prompts require a TTY
|
|
# terminal" but still exits 0, so the job goes green without applying the
|
|
# change. tee keeps the output live in the log; we then fail on drizzle's
|
|
# own TTY error. A genuine non-zero exit already fails via `set -e`.
|
|
bun run db:push --force < /dev/null 2>&1 | tee /tmp/db-push.log
|
|
if grep -q "Interactive prompts require a TTY terminal" /tmp/db-push.log; then
|
|
echo "ERROR: db:push needs an interactive rename decision; land it as a versioned migration instead of relying on push." >&2
|
|
exit 1
|
|
fi
|
|
else
|
|
echo "Applying versioned migrations (db:migrate)"
|
|
bun run ./scripts/migrate.ts
|
|
fi
|