Skip to content

Stage - #125

Merged
evereq merged 6 commits into
stagefrom
develop
Oct 23, 2025
Merged

Stage#125
evereq merged 6 commits into
stagefrom
develop

Conversation

@evereq

@evereq evereq commented Oct 23, 2025

Copy link
Copy Markdown
Member

Description

Please include a summary of the changes and the related issues.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my code
  • I have commented on my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings

Previous screenshots

Please add here videos or images of the previous status

Current screenshots

Please add here videos or images of the current (new) status

Comment on lines +13 to +73
runs-on: buildjet-8vcpu-ubuntu-2204

environment: dev
environment: dev

steps:
- name: Checkout
uses: actions/checkout@v4
steps:
- name: Checkout
uses: actions/checkout@v4

- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up QEMU
uses: docker/setup-qemu-action@v3

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./.deploy/api/Dockerfile
load: true
tags: |
ghcr.io/ever-co/ever-rec-api-dev:latest
everco/ever-rec-api-dev:latest
registry.digitalocean.com/ever/ever-rec-api-dev:latest
cache-from: type=registry,ref=everco/ever-rec-api-dev:latest
cache-to: type=inline
build-args: |
NODE_ENV=development
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./.deploy/api/Dockerfile
load: true
tags: |
ghcr.io/ever-co/ever-rec-api-dev:latest
everco/ever-rec-api-dev:latest
registry.digitalocean.com/ever/ever-rec-api-dev:latest
cache-from: type=registry,ref=everco/ever-rec-api-dev:latest
cache-to: type=inline
build-args: |
NODE_ENV=development

- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

- name: Push to Docker Hub Registry
run: |
docker push everco/ever-rec-api-dev:latest
- name: Push to Docker Hub Registry
run: |
docker push everco/ever-rec-api-dev:latest

- name: Install doctl
uses: digitalocean/action-doctl@v2
with:
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}
- name: Install doctl
uses: digitalocean/action-doctl@v2
with:
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}

- name: Log in to DigitalOcean Container Registry with short-lived credentials
run: doctl registry login --expiry-seconds 3600
- name: Log in to DigitalOcean Container Registry with short-lived credentials
run: doctl registry login --expiry-seconds 3600

- name: Push to DigitalOcean Registry
run: |
docker push registry.digitalocean.com/ever/ever-rec-api-dev:latest
- name: Push to DigitalOcean Registry
run: |
docker push registry.digitalocean.com/ever/ever-rec-api-dev:latest

- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GH_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GH_TOKEN }}

- name: Push to Github Registry
run: |
docker push ghcr.io/ever-co/ever-rec-api-dev:latest
- name: Push to Github Registry
run: |
docker push ghcr.io/ever-co/ever-rec-api-dev:latest

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Copilot Autofix

AI 12 months ago

To fix the issue, the workflow should explicitly set the minimum required permissions for the GITHUB_TOKEN used by the workflow. This is done by adding a permissions block to either the root of the workflow or specifically to the job in question. Since the workflow does not interact with repository content in a way that requires write access and only needs to read the repo (e.g., checkout code), the minimal required permission is contents: read.

The best way to fix is to add a top-level permissions block beneath the workflow name and before the jobs definition. This change limits the actions that can be performed with the GITHUB_TOKEN, improving security by following the principle of least privilege. No imports, methods, or additional code changes are needed: only the addition of the permissions YAML block.


Suggested changeset 1
.github/workflows/docker-build-publish-api-dev.yaml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/docker-build-publish-api-dev.yaml b/.github/workflows/docker-build-publish-api-dev.yaml
--- a/.github/workflows/docker-build-publish-api-dev.yaml
+++ b/.github/workflows/docker-build-publish-api-dev.yaml
@@ -1,5 +1,8 @@
 name: Build and Publish API Docker Images Dev
 
+permissions:
+  contents: read
+
 on:
   push:
     branches: [develop]
EOF
@@ -1,5 +1,8 @@
name: Build and Publish API Docker Images Dev

permissions:
contents: read

on:
push:
branches: [develop]
Copilot is powered by AI and may make mistakes. Always verify output.
Unable to commit as this autofix suggestion is now outdated
Comment on lines +13 to +73
runs-on: buildjet-8vcpu-ubuntu-2204

environment: prod
environment: prod

steps:
- name: Checkout
uses: actions/checkout@v4
steps:
- name: Checkout
uses: actions/checkout@v4

- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up QEMU
uses: docker/setup-qemu-action@v3

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./.deploy/api/Dockerfile
load: true
tags: |
ghcr.io/ever-co/ever-rec-api:latest
everco/ever-rec-api:latest
registry.digitalocean.com/ever/ever-rec-api:latest
cache-from: type=registry,ref=everco/ever-rec-api:latest
cache-to: type=inline
build-args: |
NODE_ENV=production
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./.deploy/api/Dockerfile
load: true
tags: |
ghcr.io/ever-co/ever-rec-api:latest
everco/ever-rec-api:latest
registry.digitalocean.com/ever/ever-rec-api:latest
cache-from: type=registry,ref=everco/ever-rec-api:latest
cache-to: type=inline
build-args: |
NODE_ENV=production

- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

- name: Push to Docker Hub Registry
run: |
docker push everco/ever-rec-api:latest
- name: Push to Docker Hub Registry
run: |
docker push everco/ever-rec-api:latest

- name: Install doctl
uses: digitalocean/action-doctl@v2
with:
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}
- name: Install doctl
uses: digitalocean/action-doctl@v2
with:
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}

- name: Log in to DigitalOcean Container Registry with short-lived credentials
run: doctl registry login --expiry-seconds 3600
- name: Log in to DigitalOcean Container Registry with short-lived credentials
run: doctl registry login --expiry-seconds 3600

- name: Push to DigitalOcean Registry
run: |
docker push registry.digitalocean.com/ever/ever-rec-api:latest
- name: Push to DigitalOcean Registry
run: |
docker push registry.digitalocean.com/ever/ever-rec-api:latest

- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GH_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GH_TOKEN }}

- name: Push to Github Registry
run: |
docker push ghcr.io/ever-co/ever-rec-api:latest
- name: Push to Github Registry
run: |
docker push ghcr.io/ever-co/ever-rec-api:latest

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Copilot Autofix

AI 12 months ago

To fix the problem, add a top-level permissions block in .github/workflows/docker-build-publish-api.yaml to restrict the permissions granted to the GITHUB_TOKEN for this workflow. The appropriate permission for code checkout and reading sources is contents: read, which is the minimum recommended. Unless specific workflow steps require additional write permissions to repository resources (such as issues, PRs, or packages), avoid granting them. In this file, no steps require such additional permissions—the authentication to the package registries and Docker Hub uses explicit credentials. Therefore, add:

permissions:
  contents: read

after the workflow name: but before the jobs are defined (typically after line 2).
No imports or new libraries are needed.


Suggested changeset 1
.github/workflows/docker-build-publish-api.yaml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/docker-build-publish-api.yaml b/.github/workflows/docker-build-publish-api.yaml
--- a/.github/workflows/docker-build-publish-api.yaml
+++ b/.github/workflows/docker-build-publish-api.yaml
@@ -1,4 +1,6 @@
 name: Build and Publish API Docker Images Prod
+permissions:
+  contents: read
 
 on:
   push:
EOF
@@ -1,4 +1,6 @@
name: Build and Publish API Docker Images Prod
permissions:
contents: read

on:
push:
Copilot is powered by AI and may make mistakes. Always verify output.
Unable to commit as this autofix suggestion is now outdated
Comment on lines +13 to +81
runs-on: buildjet-8vcpu-ubuntu-2204

environment: dev
environment: dev

steps:
- name: Checkout
uses: actions/checkout@v4
steps:
- name: Checkout
uses: actions/checkout@v4

- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up QEMU
uses: docker/setup-qemu-action@v3

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./.deploy/portal/Dockerfile
load: true
tags: |
ghcr.io/ever-co/ever-rec-portal-dev:latest
everco/ever-rec-portal-dev:latest
registry.digitalocean.com/ever/ever-rec-portal-dev:latest
cache-from: type=registry,ref=everco/ever-rec-portal-dev:latest
cache-to: type=inline
build-args: |
NEXT_PUBLIC_EXTENSION_NAME=${{ secrets.NEXT_PUBLIC_EXTENSION_NAME }}
NEXT_PUBLIC_EXTENSION_ID=${{ secrets.NEXT_PUBLIC_EXTENSION_ID }}
NEXT_PUBLIC_GOOGLE_CLIENT_ID=${{ secrets.NEXT_PUBLIC_GOOGLE_CLIENT_ID }}
NEXT_PUBLIC_EXTENTION_REDIRECT_URL=${{ secrets.NEXT_PUBLIC_EXTENTION_REDIRECT_URL }}
NEXT_PUBLIC_REBRANDLY_API_KEY=${{ secrets.NEXT_PUBLIC_REBRANDLY_API_KEY }}
NEXT_PUBLIC_API_BASE_URL=${{ secrets.NEXT_PUBLIC_API_BASE_URL }}
NEXT_PUBLIC_WEBSITE_URL=${{ secrets.NEXT_PUBLIC_WEBSITE_URL }}
NEXT_PUBLIC_STATIC_FILES_URL=${{ secrets.NEXT_PUBLIC_STATIC_FILES_URL }}
NEXT_PUBLIC_SENTRY_DSN=${{ secrets.NEXT_PUBLIC_SENTRY_DSN }}
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./.deploy/portal/Dockerfile
load: true
tags: |
ghcr.io/ever-co/ever-rec-portal-dev:latest
everco/ever-rec-portal-dev:latest
registry.digitalocean.com/ever/ever-rec-portal-dev:latest
cache-from: type=registry,ref=everco/ever-rec-portal-dev:latest
cache-to: type=inline
build-args: |
NEXT_PUBLIC_EXTENSION_NAME=${{ secrets.DEV_NEXT_PUBLIC_EXTENSION_NAME }}
NEXT_PUBLIC_EXTENSION_ID=${{ secrets.DEV_NEXT_PUBLIC_EXTENSION_ID }}
NEXT_PUBLIC_GOOGLE_CLIENT_ID=${{ secrets.DEV_NEXT_PUBLIC_GOOGLE_CLIENT_ID }}
NEXT_PUBLIC_EXTENSION_REDIRECT_URL=${{ secrets.DEV_NEXT_PUBLIC_EXTENSION_REDIRECT_URL }}
NEXT_PUBLIC_REBRANDLY_API_KEY=${{ secrets.DEV_NEXT_PUBLIC_REBRANDLY_API_KEY }}
NEXT_PUBLIC_API_BASE_URL=${{ secrets.DEV_NEXT_PUBLIC_API_BASE_URL }}
NEXT_PUBLIC_WEBSITE_URL=${{ secrets.DEV_NEXT_PUBLIC_WEBSITE_URL }}
NEXT_PUBLIC_STATIC_FILES_URL=${{ secrets.DEV_NEXT_PUBLIC_STATIC_FILES_URL }}
NEXT_PUBLIC_SENTRY_DSN=${{ secrets.DEV_NEXT_PUBLIC_SENTRY_DSN }}

- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

- name: Push to Docker Hub Registry
run: |
docker push everco/ever-rec-portal-dev:latest
- name: Push to Docker Hub Registry
run: |
docker push everco/ever-rec-portal-dev:latest

- name: Install doctl
uses: digitalocean/action-doctl@v2
with:
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}
- name: Install doctl
uses: digitalocean/action-doctl@v2
with:
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}

- name: Log in to DigitalOcean Container Registry with short-lived credentials
run: doctl registry login --expiry-seconds 3600
- name: Log in to DigitalOcean Container Registry with short-lived credentials
run: doctl registry login --expiry-seconds 3600

- name: Push to DigitalOcean Registry
run: |
docker push registry.digitalocean.com/ever/ever-rec-portal-dev:latest
- name: Push to DigitalOcean Registry
run: |
docker push registry.digitalocean.com/ever/ever-rec-portal-dev:latest

- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GH_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GH_TOKEN }}

- name: Push to Github Registry
run: |
docker push ghcr.io/ever-co/ever-rec-portal-dev:latest
- name: Push to Github Registry
run: |
docker push ghcr.io/ever-co/ever-rec-portal-dev:latest

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Copilot Autofix

AI 12 months ago

The best way to fix this issue is to add a permissions block at the root of the workflow YAML file (.github/workflows/docker-build-publish-portal-dev.yaml). This block must declare the least privilege required for the workflow to operate successfully. Since the workflow's steps primarily interact with external services using secrets and do not write to the repository, contents: read is sufficient. Add this block immediately after the name and before on.

  • Modify .github/workflows/docker-build-publish-portal-dev.yaml
  • Insert:
    permissions:
      contents: read
    right after the name: field (ideally before the on: block).
  • No additional imports, methods, or definitions are needed.

Suggested changeset 1
.github/workflows/docker-build-publish-portal-dev.yaml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/docker-build-publish-portal-dev.yaml b/.github/workflows/docker-build-publish-portal-dev.yaml
--- a/.github/workflows/docker-build-publish-portal-dev.yaml
+++ b/.github/workflows/docker-build-publish-portal-dev.yaml
@@ -1,4 +1,6 @@
 name: Build and Publish Portal Docker Images Dev
+permissions:
+  contents: read
 
 on:
   push:
EOF
@@ -1,4 +1,6 @@
name: Build and Publish Portal Docker Images Dev
permissions:
contents: read

on:
push:
Copilot is powered by AI and may make mistakes. Always verify output.
Unable to commit as this autofix suggestion is now outdated
Comment on lines +13 to +81
runs-on: buildjet-8vcpu-ubuntu-2204

environment: prod
environment: prod

steps:
- name: Checkout
uses: actions/checkout@v4
steps:
- name: Checkout
uses: actions/checkout@v4

- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up QEMU
uses: docker/setup-qemu-action@v3

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./.deploy/portal/Dockerfile
load: true
tags: |
ghcr.io/ever-co/ever-rec-portal:latest
everco/ever-rec-portal:latest
registry.digitalocean.com/ever/ever-rec-portal:latest
cache-from: type=registry,ref=everco/ever-rec-portal:latest
cache-to: type=inline
build-args: |
NEXT_PUBLIC_EXTENSION_NAME=${{ secrets.NEXT_PUBLIC_EXTENSION_NAME }}
NEXT_PUBLIC_EXTENSION_ID=${{ secrets.NEXT_PUBLIC_EXTENSION_ID }}
NEXT_PUBLIC_GOOGLE_CLIENT_ID=${{ secrets.NEXT_PUBLIC_GOOGLE_CLIENT_ID }}
NEXT_PUBLIC_EXTENTION_REDIRECT_URL=${{ secrets.NEXT_PUBLIC_EXTENTION_REDIRECT_URL }}
NEXT_PUBLIC_REBRANDLY_API_KEY=${{ secrets.NEXT_PUBLIC_REBRANDLY_API_KEY }}
NEXT_PUBLIC_API_BASE_URL=${{ secrets.NEXT_PUBLIC_API_BASE_URL }}
NEXT_PUBLIC_WEBSITE_URL=${{ secrets.NEXT_PUBLIC_WEBSITE_URL }}
NEXT_PUBLIC_STATIC_FILES_URL=${{ secrets.NEXT_PUBLIC_STATIC_FILES_URL }}
NEXT_PUBLIC_SENTRY_DSN=${{ secrets.NEXT_PUBLIC_SENTRY_DSN }}
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: ./.deploy/portal/Dockerfile
load: true
tags: |
ghcr.io/ever-co/ever-rec-portal:latest
everco/ever-rec-portal:latest
registry.digitalocean.com/ever/ever-rec-portal:latest
cache-from: type=registry,ref=everco/ever-rec-portal:latest
cache-to: type=inline
build-args: |
NEXT_PUBLIC_EXTENSION_NAME=${{ secrets.NEXT_PUBLIC_EXTENSION_NAME }}
NEXT_PUBLIC_EXTENSION_ID=${{ secrets.NEXT_PUBLIC_EXTENSION_ID }}
NEXT_PUBLIC_GOOGLE_CLIENT_ID=${{ secrets.NEXT_PUBLIC_GOOGLE_CLIENT_ID }}
NEXT_PUBLIC_EXTENSION_REDIRECT_URL=${{ secrets.NEXT_PUBLIC_EXTENSION_REDIRECT_URL }}
NEXT_PUBLIC_REBRANDLY_API_KEY=${{ secrets.NEXT_PUBLIC_REBRANDLY_API_KEY }}
NEXT_PUBLIC_API_BASE_URL=${{ secrets.NEXT_PUBLIC_API_BASE_URL }}
NEXT_PUBLIC_WEBSITE_URL=${{ secrets.NEXT_PUBLIC_WEBSITE_URL }}
NEXT_PUBLIC_STATIC_FILES_URL=${{ secrets.NEXT_PUBLIC_STATIC_FILES_URL }}
NEXT_PUBLIC_SENTRY_DSN=${{ secrets.NEXT_PUBLIC_SENTRY_DSN }}

- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Login to DockerHub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

- name: Push to Docker Hub Registry
run: |
docker push everco/ever-rec-portal:latest
- name: Push to Docker Hub Registry
run: |
docker push everco/ever-rec-portal:latest

- name: Install doctl
uses: digitalocean/action-doctl@v2
with:
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}
- name: Install doctl
uses: digitalocean/action-doctl@v2
with:
token: ${{ secrets.DIGITALOCEAN_ACCESS_TOKEN }}

- name: Log in to DigitalOcean Container Registry with short-lived credentials
run: doctl registry login --expiry-seconds 3600
- name: Log in to DigitalOcean Container Registry with short-lived credentials
run: doctl registry login --expiry-seconds 3600

- name: Push to DigitalOcean Registry
run: |
docker push registry.digitalocean.com/ever/ever-rec-portal:latest
- name: Push to DigitalOcean Registry
run: |
docker push registry.digitalocean.com/ever/ever-rec-portal:latest

- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GH_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GH_TOKEN }}

- name: Push to Github Registry
run: |
docker push ghcr.io/ever-co/ever-rec-portal:latest
- name: Push to Github Registry
run: |
docker push ghcr.io/ever-co/ever-rec-portal:latest

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Copilot Autofix

AI 12 months ago

To fix the problem, add a permissions: block to the workflow, either at the workflow (root) level—applying to all jobs—or at the individual job level—customizing permissions per job. Since the workflow pushes images (requiring only contents: read for basic checkout/build actions and possibly some permission for packages if publishing to the GitHub Container Registry), but does not appear to need write access to repository content or issues/pull-requests, the least-privilege approach is to set contents: read at the minimum. If in the future you use steps that require more permissions, you can expand the permissions block.

How to fix:

  • Add a permissions key right below the name field at the root of the workflow YAML file (recommended for one-job workflows), set to contents: read.
  • This fix will restrict the GITHUB_TOKEN to read-only for repository contents and will prevent write operations unless explicitly expanded.
  • No new imports or dependencies are required; it's a configuration change only.

File/region to change:

  • Edit .github/workflows/docker-build-publish-portal.yaml
  • Insert the following block after the name: property.

Suggested changeset 1
.github/workflows/docker-build-publish-portal.yaml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/docker-build-publish-portal.yaml b/.github/workflows/docker-build-publish-portal.yaml
--- a/.github/workflows/docker-build-publish-portal.yaml
+++ b/.github/workflows/docker-build-publish-portal.yaml
@@ -1,4 +1,6 @@
 name: Build and Publish Portal Docker Images Prod
+permissions:
+  contents: read
 
 on:
   push:
EOF
@@ -1,4 +1,6 @@
name: Build and Publish Portal Docker Images Prod
permissions:
contents: read

on:
push:
Copilot is powered by AI and may make mistakes. Always verify output.
Unable to commit as this autofix suggestion is now outdated
@evereq
evereq merged commit 52bf211 into stage Oct 23, 2025
12 of 13 checks passed

@greptile-apps greptile-apps Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Greptile Overview

Greptile Summary

This PR consolidates infrastructure improvements and bug fixes across deployment configurations. The changes migrate from Traefik to nginx ingress controller, fix critical typos in deployment automation, and add the REC_JWT_SECRET environment variable.

Major Changes:

  • Migrated Kubernetes ingress from Traefik to nginx ingress controller in both dev and prod manifests
  • Fixed critical typo: NEXT_PUBLIC_EXTENTION_REDIRECT_URL → NEXT_PUBLIC_EXTENSION_REDIRECT_URL across Dockerfile, workflows, and env samples
  • Fixed deployment command typo: ever-rec-poral-* → ever-rec-portal-* in deploy workflows
  • Added REC_JWT_SECRET environment variable to both dev and prod API deployments
  • Added TLS secret generation step to deployment workflows
  • Prefixed dev environment secrets with DEV_ prefix for better separation
  • Changed production container registry from GitHub to DigitalOcean registry
  • Standardized YAML formatting across all workflow files

Infrastructure Impact:
The ingress controller migration requires nginx ingress controller to be installed in the Kubernetes cluster. The TLS secrets are now generated dynamically during deployment from GitHub secrets.

Confidence Score: 4/5

  • Safe to merge with one minor workflow naming issue
  • The changes are well-structured infrastructure improvements with proper typo fixes. Only issue is the incorrect workflow name in deploy-do-prod.yml (says "Dev" instead of "Prod"), which is cosmetic but should be fixed for clarity. All other changes are solid improvements.
  • .github/workflows/deploy-do-prod.yml needs workflow name correction

Important Files Changed

File Analysis

Filename Score Overview
.github/workflows/deploy-do-prod.yml 4/5 Fixed typo in deployment command, added TLS secret generation, added REC_JWT_SECRET env var. Has incorrect workflow name (says "Dev" instead of "Prod").
.github/workflows/deploy-do-dev.yml 5/5 Fixed typo in deployment command (ever-rec-poral-dev → ever-rec-portal-dev), added TLS secret generation, added REC_JWT_SECRET environment variable.
.deploy/k8s/k8s-manifest.dev.yaml 5/5 Migrated from Traefik to nginx ingress controller, improved YAML formatting, removed standalone Middleware resource, added REC_JWT_SECRET env var.
.deploy/k8s/k8s-manifest.prod.yaml 5/5 Migrated from Traefik to nginx ingress controller, improved YAML formatting, changed container images to DigitalOcean registry, added REC_JWT_SECRET env var.
.deploy/portal/Dockerfile 5/5 Fixed typo: NEXT_PUBLIC_EXTENTION_REDIRECT_URL → NEXT_PUBLIC_EXTENSION_REDIRECT_URL throughout the Dockerfile.

Sequence Diagram

sequenceDiagram
    participant GH as GitHub Actions
    participant DockerHub as Docker Hub
    participant DO as DigitalOcean Registry
    participant GHCR as GitHub Container Registry
    participant K8s as Kubernetes Cluster
    participant Nginx as Nginx Ingress
    participant App as Applications

    Note over GH: On push to develop/main
    GH->>GH: Build Docker Images
    GH->>DockerHub: Push images
    GH->>DO: Push images
    GH->>GHCR: Push images
    
    Note over GH: Deploy workflow triggered
    GH->>K8s: Generate TLS Secrets
    Note right of K8s: Decode base64 certs<br/>Create k8s secrets
    GH->>K8s: Apply manifests with envsubst
    Note right of K8s: Inject REC_JWT_SECRET<br/>and Firebase config
    GH->>K8s: Rollout restart deployments
    K8s->>DO: Pull latest images
    K8s->>App: Deploy API & Portal
    
    Note over Nginx,App: Ingress Configuration
    Nginx->>App: Route traffic with TLS
    Note right of Nginx: Uses nginx controller<br/>(migrated from Traefik)
Loading

Additional Comments (1)

  1. .github/workflows/deploy-do-prod.yml, line 1 (link)

    syntax: workflow name says "Dev" but this is production

10 files reviewed, 1 comment

Edit Code Review Agent Settings | Greptile

This branch was previously deployed

2 inactive deployments
prod — 9938deb1 Deployed Oct 23, 2025 by evereq via deploy-demo #3
dev — 9938deb1 Deployed Oct 23, 2025 by evereq via deploy-demo #15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants