# Deployment

This repo (`dijitul/Parrot-Supplies`, private) is the source of truth for the
live store at **https://parrot-supplies.co.uk** (server `178.62.113.207`, app at
`/var/www/html`, Apache + PHP 8.2).

## How to ship a change

1. Edit files locally in this working copy.
2. Commit and push to `main`:
   ```bash
   git add -A
   git commit -m "your message"
   git push
   ```
   The push **deploys automatically** — the `Deploy to production` workflow
   fires on every push to `main` and the change is live within a minute.

You can also still run the workflow by hand from the repo's **Actions** tab
→ **Deploy to production** → **Run workflow** — useful for re-syncing the
server or clearing caches without making a new commit.

## What the deploy does

The `Deploy to production` workflow (`.github/workflows/deploy.yml`) SSHes into
the server and runs, as `www-data`:

```
git fetch --prune origin
git reset --hard origin/main      # server is forced to match origin/main exactly
php artisan optimize:clear        # clears config/route/view/cache (incl. full-page cache)
```

### Important consequences

- **`git reset --hard` means the server is an exact mirror of `origin/main`.**
  Do **not** hand-edit files directly on the live server anymore — the next
  deploy will overwrite them. All changes go through this repo.
- **Dependencies/assets are NOT rebuilt on deploy, and migrations are NOT run**
  (the "pull + clear cache" model). If you change `composer.json`,
  `package.json`, front-end assets that need a Vite build, or add a migration,
  run the matching step on the server manually (`composer install` /
  `npm ci && npm run build` / `php artisan migrate`) or ask for the workflow to
  be extended to handle it.
- `public/themes/shop/default/build/assets/app-custom.css` is the exception: it
  is hand-maintained and tracked in git, so storefront CSS edits there go live
  with a normal deploy.
- Secrets live only in the server's `/var/www/html/.env` (git-ignored) — never
  commit `.env`.

## Auth / keys (already configured)

- **GitHub Actions → server:** SSH key in repo secrets (`DEPLOY_HOST`,
  `DEPLOY_USER`, `DEPLOY_SSH_KEY`); public half in the server's
  `/root/.ssh/authorized_keys`.
- **Server → GitHub (pull):** read-only deploy key on this repo; private half at
  `/var/www/.ssh/parrot_deploy` (owned by `www-data`), wired via the repo's
  `core.sshCommand`.
