name: Backend Deploy

# Deploys the Dockerized Python+Postgres backend to the gowalk host. Installed
# by gowalk-cicd when backend/ or server/ has a compose file, or when a root
# compose file builds one of those directories. Mobile deploy stays in deploy.yml.
on:
  push:
    branches: [main]
    paths:
      - "backend/**"
      - "server/**"
      - "docker-compose.yml"
      - "docker-compose.yaml"
      - "compose.yml"
      - "compose.yaml"
      - ".github/workflows/deploy-backend.yml"
      - ".github/actions/backend-app/**"
      - "!.github/actions/backend-app/.daemux-version"
  workflow_dispatch:
    inputs:
      operation:
        type: choice
        description: Deploy or read scoped identity/network diagnostics without changing the running app
        default: deploy
        options: [deploy, identity-diagnostics, network-diagnostics]
      diagnostic-since:
        type: string
        description: For diagnostics, UTC YYYY-MM-DDTHH:MM:SSZ within the previous 24 hours
        required: false
      diagnostic-provider:
        type: choice
        description: Optional host metadata for network diagnostics; never address-space authorization
        default: none
        options: [none, digitalocean]

permissions:
  contents: read

concurrency:
  group: backend-deploy-${{ github.ref }}-${{ inputs.operation || 'deploy' }}
  cancel-in-progress: true

jobs:
  deploy:
    runs-on: ubuntu-latest
    timeout-minutes: 30
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6

      # Pick the source dir and either its nested compose file or a root one.
      - id: dir
        if: inputs.operation == '' || inputs.operation == 'deploy'
        env:
          BACKEND_LAYOUT_REQUIRED: "true"
        run: node .github/actions/backend-app/layout.cjs

      - name: Deploy backend
        uses: ./.github/actions/backend-app
        with:
          operation: ${{ inputs.operation || 'deploy' }}
          diagnostic-since: ${{ inputs.diagnostic-since }}
          diagnostic-provider: ${{ inputs.diagnostic-provider || 'none' }}
          ssh-key: ${{ secrets.BACKEND_DEPLOY_SSH_KEY }}
          host: ${{ vars.BACKEND_DEPLOY_HOST || '138.197.36.107' }}
          app-name: ${{ vars.BACKEND_APP_NAME || github.event.repository.name }}
          api-domain: ${{ vars.BACKEND_API_DOMAIN }}
          backend-dir: ${{ steps.dir.outputs.path }}
          compose-file: ${{ steps.dir.outputs.compose }}
          health-path: ${{ vars.BACKEND_HEALTH_PATH || '/health' }}
          public-health-url: ${{ vars.BACKEND_PUBLIC_HEALTH_URL }}
          public-base-url: ${{ vars.BACKEND_PUBLIC_BASE_URL }}
          expected-build-sha: ${{ vars.BACKEND_PUBLIC_HEALTH_URL && github.sha || '' }}
          ingress-required: ${{ vars.BACKEND_INGRESS_REQUIRED || 'false' }}
          ingress-token: ${{ secrets.BACKEND_INGRESS_TOKEN }}
          runtime-env: ${{ secrets.BACKEND_RUNTIME_ENV }}
