-
Notifications
You must be signed in to change notification settings - Fork 0
89 lines (76 loc) · 3.01 KB
/
Copy pathdeploy.yml
File metadata and controls
89 lines (76 loc) · 3.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
name: Deploy to Cloudflare Pages
# Production deploy. Runs after a push to main (or on demand).
#
# The Cloudflare Pages project `terraphim-ai` is deployed exclusively through
# this workflow. There is no separate CDN/Git integration to keep in sync, so a
# green run here means the published site matches main.
on:
push:
branches:
- main
workflow_dispatch:
permissions:
contents: read
deployments: write
concurrency:
group: cloudflare-pages-production
cancel-in-progress: false
env:
ZOLA_VERSION: "0.22.1"
CF_PROJECT: terraphim-ai
OP_API_TOKEN: op://TerraphimPlatform/terraphim-md-book-cloudflare/workers-api-token
OP_ACCOUNT_ID: op://TerraphimPlatform/terraphim-md-book-cloudflare/account_id
jobs:
build-and-deploy:
name: Build and Deploy
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Install Zola ${{ env.ZOLA_VERSION }}
run: |
curl --fail --location --silent --show-error \
"https://github.com/getzola/zola/releases/download/v${ZOLA_VERSION}/zola-v${ZOLA_VERSION}-x86_64-unknown-linux-gnu.tar.gz" \
| tar xz
sudo mv zola /usr/local/bin
zola --version
- name: Build site
run: zola build
- name: Load secrets from 1Password
id: op-load-secrets
uses: 1password/load-secrets-action@v2
with:
export-env: true
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_SERVICE_ACCOUNT_TOKEN }}
CLOUDFLARE_API_TOKEN: ${{ env.OP_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ env.OP_ACCOUNT_ID }}
- name: Deploy to Cloudflare Pages
id: deploy
uses: cloudflare/wrangler-action@v3
with:
apiToken: ${{ env.CLOUDFLARE_API_TOKEN }}
accountId: ${{ env.CLOUDFLARE_ACCOUNT_ID }}
command: pages deploy public --project-name=${{ env.CF_PROJECT }} --branch=main
- name: Verify the deployed site serves the committed version
env:
DEPLOY_URL: ${{ steps.deploy.outputs.deployment-url }}
run: |
expected=$(grep -oP '^release_version\s*=\s*"\K[^"]+' config.toml)
url="${DEPLOY_URL:-https://${CF_PROJECT}.pages.dev}"
echo "Expecting release_version ${expected} at ${url}"
attempt=1
while [ "${attempt}" -le 5 ]; do
body=$(curl --fail --location --silent --show-error --max-time 30 "${url}/" || true)
if printf '%s' "${body}" | grep -q "${expected}"; then
echo "Deployment served release ${expected} on attempt ${attempt}"
exit 0
fi
echo "Attempt ${attempt}: ${expected} not found yet, retrying"
attempt=$((attempt + 1))
sleep 15
done
# Surface the site content for debugging before failing.
curl --fail --location --silent --show-error --max-time 30 "${url}/" | head -c 2000 || true
echo "::error::Deployed site does not advertise release ${expected}"
exit 1