Skip to content

Phase 0: take ownership of build, CI, and telemetry - #314

Closed
tfedorko-stc wants to merge 13 commits into
msgbyte:masterfrom
STC-Worldwide:feat/fork-ownership
Closed

Phase 0: take ownership of build, CI, and telemetry#314
tfedorko-stc wants to merge 13 commits into
msgbyte:masterfrom
STC-Worldwide:feat/fork-ownership

Conversation

@tfedorko-stc

@tfedorko-stc tfedorko-stc commented Aug 31, 2026

Copy link
Copy Markdown

First step of the fork takeover plan (full review: internal artifact "Tailchat Takeover Review").

What this does

  • STC-owned image build: docker-publish.yml now pushes ghcr.io/stc-worldwide/tailchat using the workflow's own GITHUB_TOKEN — no external secrets, no Docker Hub. Builds on master pushes and v*.*.* tags, amd64, with GHA layer cache.
  • CI teardown: removes the 8 workflows tied to msgbyte infrastructure (Docker Hub, Vercel nightly/test, Deno Deploy, Laf, upstream docs deploy, issue auto-translator, RN APK) plus codemagic.yaml and vercel.json. ci.yaml/admin.yaml now also run on pull requests and use v4 actions; the web build step no longer needs upstream's Perfsee token.
  • Telemetry strip: deletes the unconditional tianji.moonrailgun.com pixel from init.tsx and the umami inject-analytics.js. The admin-configurable tianji hook stays (it only fires when explicitly configured server-side).
  • Dead code removal: client/mobile (RN 0.71 WebView shell, stale since 2023-12, getui/Huawei push) and client/desktop-old (2022). AGENTS.md/.dockerignore updated.
  • Deploy repoint: deploy/stc/docker-compose.yml and the runbook now pin ghcr.io/stc-worldwide/tailchat:1.12.0; root version bumped to 1.12.0. .env.local ignored repo-wide.

After merge (deploy checklist)

  1. Tag v1.12.0 → watch the Docker Publish run (~30–60 min).
  2. Set the GHCR package public (org packages default private), or give the VPS a read:packages PAT.
  3. On the VPS: update compose, docker compose pull && docker compose up -d, smoke-test per runbook.

Not in scope (next phases)

Playwright-in-CI, the $regex search escape, platform upgrades (TS 5 / Tailwind 4 / Node 22 / Mongo 7), and the UI facelift.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added production deployment configuration for STC Worldwide, including Docker Compose, Caddy routing, firewall rules, environment templates, and automated backups.
    • Added deployment documentation covering setup, releases, operations, and backup recovery.
    • Docker images now publish to GitHub Container Registry with version-based tagging.
  • Chores

    • Removed legacy mobile and desktop application projects and their build pipelines.
    • Removed several unused hosting, deployment, translation, and nightly-test workflows.
    • Improved CI pull-request coverage and upgraded build tooling.
    • Added local environment files to ignore rules and pinned the CLI version.
    • Updated the application version to 1.12.0.

tfedorko-stc and others added 13 commits August 29, 2026 10:58
Caddy TLS front (public 80/443) -> internal traefik -> pinned
moonrailgun/tailchat:1.11.12 stack with legacy admin panel.
MinIO credentials parameterized; env template + runbook included.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ocalhost to ::1

Gateway listens IPv4-only; the failing healthcheck made traefik drop
service-core from routing (every route except /admin 404'd).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… rotation)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
STC production deployment for netcup-vps-01
Adds a file_server site block for stc-worldwide.com + www (content at
/opt/landing on the host, source repo STC-Worldwide/stc-worldwide.com)
and mounts /opt/landing read-only into the caddy container.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Serve stc-worldwide.com landing page via Caddy
… 2465, landing page

- vps-nftables.conf: custody copy of the live firewall incl. the 80/443
  input rule and docker0/br-* forward accepts (containers have no
  outbound without them)
- README: firewall, Resend SMTP (netcup blocks 465/587 -> port 2465,
  SMTP_SENDER single-quote form), landing page serving + redeploy
- env example: corrected SMTP examples to the working forms

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sync deploy runbook with live VPS state
The RN WebView shell was stale since 2023-12 and tied to getui/Huawei push;
mobile will be a native wrap of the web client instead.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- docker-publish.yml now builds ghcr.io/stc-worldwide/tailchat via GITHUB_TOKEN
  (amd64, gha cache) on master pushes and v*.*.* tags
- drop 8 workflows tied to msgbyte infra (Docker Hub, Vercel, Deno, Laf,
  Codemagic, issue translator) plus codemagic.yaml / vercel.json
- ci.yaml + admin.yaml: run on pull_request, actions v4, plain build (no Perfsee)
- Dockerfile: pin tailchat-cli@1.5.14 instead of @latest

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Drop the unconditional tianji.moonrailgun.com pixel in init.tsx and the
umami inject script (only consumed by the deleted Vercel workflows).
Admin-configured tianji injection (useInjectTianjiScript) is unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- compose + runbook now reference ghcr.io/stc-worldwide/tailchat:1.12.0
- runbook documents the tag-to-release flow and GHCR package visibility
- ignore .env.local repo-wide (was only in one clone's .git/info/exclude)
- bump root version to 1.12.0 for the fork's first release

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@netlify

netlify Bot commented Aug 31, 2026

Copy link
Copy Markdown

👷 Deploy request for tailchat-nightly pending review.

Visit the deploys page to approve it

Name Link
🔨 Latest commit 975121a

@tfedorko-stc

Copy link
Copy Markdown
Author

Opened against the wrong repository by mistake — this belongs on the STC-Worldwide fork. Apologies for the noise.

@coderabbitai

coderabbitai Bot commented Aug 31, 2026

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: effc5e3f-30d2-4f65-8f82-e0c55b9b790e

📥 Commits

Reviewing files that changed from the base of the PR and between d6e3ad1 and 975121a.

⛔ Files ignored due to path filters (18)
  • client/desktop-old/build/icon.ico is excluded by !**/*.ico
  • client/desktop-old/yarn.lock is excluded by !**/yarn.lock, !**/*.lock
  • client/mobile/Gemfile.lock is excluded by !**/*.lock
  • client/mobile/android/app/src/main/res/mipmap-hdpi/ic_launcher.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-hdpi/ic_launcher_round.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-mdpi/ic_launcher.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-mdpi/ic_launcher_round.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-xhdpi/ic_launcher.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-xhdpi/ic_launcher_round.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-xxhdpi/ic_launcher.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-xxhdpi/ic_launcher_round.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-xxxhdpi/ic_launcher.png is excluded by !**/*.png
  • client/mobile/android/app/src/main/res/mipmap-xxxhdpi/ic_launcher_round.png is excluded by !**/*.png
  • client/mobile/android/gradle/wrapper/gradle-wrapper.jar is excluded by !**/*.jar
  • client/mobile/ios/Podfile.lock is excluded by !**/*.lock
  • client/mobile/ios/Tailchat.xcodeproj/project.xcworkspace/contents.xcworkspacedata is excluded by !**/*.xcworkspace/contents.xcworkspacedata
  • client/mobile/ios/Tailchat.xcworkspace/contents.xcworkspacedata is excluded by !**/*.xcworkspace/contents.xcworkspacedata
  • client/mobile/yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (116)
  • .dockerignore
  • .github/workflows/admin.yaml
  • .github/workflows/ci.yaml
  • .github/workflows/deploy-deno.yml
  • .github/workflows/deploy-github-app.yml
  • .github/workflows/deploy-laf.yml
  • .github/workflows/deploy-website.yml
  • .github/workflows/docker-publish-canary.yml
  • .github/workflows/docker-publish.yml
  • .github/workflows/rn-build-apk.yml
  • .github/workflows/translator.yaml
  • .github/workflows/vercel-nightly-test.yml
  • .github/workflows/vercel-nightly.yml
  • .gitignore
  • AGENTS.md
  • Dockerfile
  • client/desktop-old/.gitignore
  • client/desktop-old/.npmrc
  • client/desktop-old/build/icon.icns
  • client/desktop-old/forge.config.js
  • client/desktop-old/package.json
  • client/desktop-old/scripts/update.ts
  • client/desktop-old/src/lib/electron-update-notifier.ts
  • client/desktop-old/src/lib/update-electron-app.ts
  • client/desktop-old/src/main/config.ts
  • client/desktop-old/src/main/index.ts
  • client/desktop-old/src/main/menu.ts
  • client/desktop-old/src/main/update.ts
  • client/desktop-old/tsconfig.json
  • client/mobile/.bundle/config
  • client/mobile/.env.example
  • client/mobile/.eslintrc.js
  • client/mobile/.gitignore
  • client/mobile/.node-version
  • client/mobile/.npmrc
  • client/mobile/.prettierrc.js
  • client/mobile/.ruby-version
  • client/mobile/.watchmanconfig
  • client/mobile/Gemfile
  • client/mobile/__tests__/App-test.tsx
  • client/mobile/android/app/build.gradle
  • client/mobile/android/app/debug.keystore
  • client/mobile/android/app/proguard-rules.pro
  • client/mobile/android/app/src/debug/AndroidManifest.xml
  • client/mobile/android/app/src/debug/java/com/msgbyte/tailchat/ReactNativeFlipper.java
  • client/mobile/android/app/src/main/AndroidManifest.xml
  • client/mobile/android/app/src/main/java/com/msgbyte/tailchat/GetuiLogger.java
  • client/mobile/android/app/src/main/java/com/msgbyte/tailchat/GetuiModule.java
  • client/mobile/android/app/src/main/java/com/msgbyte/tailchat/GetuiPackage.java
  • client/mobile/android/app/src/main/java/com/msgbyte/tailchat/MainActivity.java
  • client/mobile/android/app/src/main/java/com/msgbyte/tailchat/MainApplication.java
  • client/mobile/android/app/src/main/java/com/msgbyte/tailchat/PushIntentService.java
  • client/mobile/android/app/src/main/java/com/msgbyte/tailchat/TailchatPushService.java
  • client/mobile/android/app/src/main/res/drawable/rn_edit_text_material.xml
  • client/mobile/android/app/src/main/res/values/strings.xml
  • client/mobile/android/app/src/main/res/values/styles.xml
  • client/mobile/android/app/src/release/java/com/tailchat/ReactNativeFlipper.java
  • client/mobile/android/build.gradle
  • client/mobile/android/gradle.properties
  • client/mobile/android/gradle/wrapper/gradle-wrapper.properties
  • client/mobile/android/gradlew
  • client/mobile/android/gradlew.bat
  • client/mobile/android/settings.gradle
  • client/mobile/app.json
  • client/mobile/babel.config.js
  • client/mobile/index.js
  • client/mobile/ios/.xcode.env
  • client/mobile/ios/Podfile
  • client/mobile/ios/Tailchat.xcodeproj/project.pbxproj
  • client/mobile/ios/Tailchat.xcodeproj/project.xcworkspace/xcshareddata/IDEWorkspaceChecks.plist
  • client/mobile/ios/Tailchat.xcodeproj/xcshareddata/xcschemes/Tailchat.xcscheme
  • client/mobile/ios/Tailchat/AppDelegate.h
  • client/mobile/ios/Tailchat/AppDelegate.mm
  • client/mobile/ios/Tailchat/Images.xcassets/AppIcon.appiconset/Contents.json
  • client/mobile/ios/Tailchat/Images.xcassets/Contents.json
  • client/mobile/ios/Tailchat/Info.plist
  • client/mobile/ios/Tailchat/LaunchScreen.storyboard
  • client/mobile/ios/Tailchat/main.m
  • client/mobile/ios/TailchatTests/Info.plist
  • client/mobile/ios/TailchatTests/TailchatTests.m
  • client/mobile/metro.config.js
  • client/mobile/package.json
  • client/mobile/scripts/notify-links.js
  • client/mobile/src/App.tsx
  • client/mobile/src/AppMain.tsx
  • client/mobile/src/Entry.tsx
  • client/mobile/src/components/ServerCard.tsx
  • client/mobile/src/hooks/useToast.tsx
  • client/mobile/src/lib/i18n/index.ts
  • client/mobile/src/lib/i18n/translations/en.json
  • client/mobile/src/lib/i18n/translations/zh.json
  • client/mobile/src/lib/inject/index.ts
  • client/mobile/src/lib/inject/message-handler.ts
  • client/mobile/src/lib/notifications/getui.ts
  • client/mobile/src/lib/notifications/index.ts
  • client/mobile/src/lib/permissions/index.ts
  • client/mobile/src/lib/socket/index.ts
  • client/mobile/src/lib/utils/index.ts
  • client/mobile/src/lib/utils/storage.ts
  • client/mobile/src/store/server.ts
  • client/mobile/src/store/ui.ts
  • client/mobile/src/theme.ts
  • client/mobile/src/types.ts
  • client/mobile/tsconfig.json
  • client/web/build/inject-analytics.js
  • client/web/src/init.tsx
  • codemagic.yaml
  • deploy/stc/.gitattributes
  • deploy/stc/Caddyfile
  • deploy/stc/README-STC.md
  • deploy/stc/backup.sh
  • deploy/stc/docker-compose.env.example
  • deploy/stc/docker-compose.yml
  • deploy/stc/vps-nftables.conf
  • package.json
  • vercel.json

📝 Walkthrough

Walkthrough

The change removes legacy desktop and mobile clients, updates CI and GHCR publishing, removes several deployment workflows, disables client telemetry, pins the CLI version, and adds a complete STC production deployment with Compose, Caddy, backups, documentation, and nftables rules.

Changes

CI and release publishing

Layer / File(s) Summary
Workflow validation updates
.github/workflows/admin.yaml, .github/workflows/ci.yaml
Admin and client workflows now run on matching pull requests. GitHub Actions and pnpm actions use newer major versions. The client build uses pnpm build without PERFSEE_TOKEN.
GHCR image publishing
.github/workflows/docker-publish.yml, Dockerfile, package.json
Image publishing moves to GHCR for master pushes and version tags. Builds target linux/amd64, use GitHub authentication and caching, and pass the ref name as the version. The package version is 1.12.0, and tailchat-cli is pinned to 1.5.14.
Retired web publishing path
.github/workflows/vercel-nightly.yml, vercel.json
The nightly Vercel workflow is removed. The Vercel SPA fallback rewrite is removed.

Legacy client cleanup

Layer / File(s) Summary
Repository client scope
.dockerignore, AGENTS.md
The repository map removes the legacy mobile and desktop directories. Docker no longer excludes these paths from its build context.
Legacy desktop removal
client/desktop-old/scripts/update.ts
The legacy desktop update packaging and GitHub Pages deployment script is removed.
React Native project removal
client/mobile/...
The React Native entry point, configuration, native Android and iOS projects, tests, translations, types, stores, notifications, permissions, WebView integration, and utilities are removed.
Web telemetry cleanup
client/web/src/init.tsx
Production telemetry submission is removed from global configuration loading. Error handling remains.
Local environment protection
.gitignore
.env.local is now ignored as a machine-specific environment file.

STC deployment

Layer / File(s) Summary
Deployment configuration
deploy/stc/docker-compose.env.example
The example environment file defines service connections, public URLs, secrets, SMTP, MinIO, upload limits, Prometheus, and admin credentials.
Container topology
deploy/stc/docker-compose.yml
The Compose stack adds Tailchat application services, MongoDB, Redis, MinIO, Traefik, and Caddy on an internal network. Caddy publishes the public HTTP and HTTPS ports.
Host firewall and line endings
deploy/stc/.gitattributes, deploy/stc/vps-nftables.conf
The deployment enforces LF line endings and adds a re-applicable nftables policy for web, Docker, SSH, ICMP, Tailscale, and MSS handling.
Deployment operations
deploy/stc/Caddyfile, deploy/stc/backup.sh, deploy/stc/README-STC.md
The deployment adds Caddy routing, nightly MongoDB and MinIO backups, retention cleanup, and operational documentation.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant Caddy
  participant Traefik
  participant Tailchat
  participant MongoDB
  participant Redis

  Client->>Caddy: Send HTTPS request
  Caddy->>Traefik: Proxy request to internal port 80
  Traefik->>Tailchat: Route by request path
  Tailchat->>MongoDB: Read or write application data
  Tailchat->>Redis: Use Redis transporter
Loading
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant