Skip to content
254 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow1# Deploys g1t.sh from main, with g1t's own Actions. What it does is
2# scripts/deploy.mjs, the same tool a person runs; docs/DEPLOYING.md is the
3# guide.
4#
5# check the deploy manifest is consistent, and the tool's tests pass
6# plan what changed since each Worker's live commit, and pending migrations
7# migrate pending D1 migrations, before any code
8# core, edge, front the units of each stage, in jobs that share a build;
9# a stage starts only when the one before it succeeded
10#
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9711# Each run that deploys is one production deployment of g1t.sh, made by the
12# jobs that name `environment: production` (one per run, however many jobs):
13# in progress when the first starts, then a success or a failure when the
14# run ends. It shows on the project's Deployments page and as the commit's
15# `deploy / production` check. The plan job reads production's secrets
16# with `deployment: false`, so a dry run or a change that deploys nothing
17# makes no deployment.
18#
Merge branch 'main' into actions-toolkit-oidc-artifacts19# Needs the repository secret CLOUDFLARE_API_TOKEN (a Production row, with
20# Containers write), the variable CLOUDFLARE_ACCOUNT_ID, and
21# api.cloudflare.com among the project's workflow-only domains for
22# deploy.yml in production (Settings, Guardrails), and
23# registry.cloudflare.com there too, to find, pull and push the runner's
24# image. A job that must build that image (the `runner-image` group) does
Merge status detection: first-byte speed probe, deploy windows, 4 of 5 with a re-check, check history, reminders25# so with its own Docker Engine, on a larger machine. Optionally, the
26# secret STATUS_DEPLOY_TOKEN (the status Worker's secret of the same name)
27# and status.g1t.sh among the same workflow-only domains, so status.g1t.sh
28# hears each deploy start and finish. See docs/DEPLOYING.md.
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow29name: Deploy
30
31on:
32 push:
33 branches: [main]
34 workflow_dispatch:
35 inputs:
36 units:
37 description: "Units to deploy whether or not they changed, comma separated (empty: what changed)"
38 type: string
39 default: ""
40 all:
41 description: "Deploy every unit"
42 type: boolean
43 default: false
44 dry_run:
45 description: "Plan only: deploy nothing"
46 type: boolean
47 default: false
48
Merge branch 'worktree-agent-a3abfcce648e87dca'49# Its token only reads: deploying uses CLOUDFLARE_API_TOKEN, and g1t
50# records the deployments itself.
51permissions:
52 contents: read
53
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow54# One deploy at a time, and never one cut off halfway: the next waits.
55concurrency:
56 group: deploy-production
57 cancel-in-progress: false
58
59env:
60 CLOUDFLARE_ACCOUNT_ID: ${{ vars.CLOUDFLARE_ACCOUNT_ID }}
61 CARGO_TERM_COLOR: never
62 WRANGLER_SEND_METRICS: "false"
63
64jobs:
65 check:
66 name: Check
67 runs-on: ubuntu-latest
68 timeout-minutes: 20
69 steps:
70 - uses: actions/checkout@v5
71 - name: Install Wrangler
72 run: npm ci --workspaces=false --no-audit --no-fund
73 - name: The manifest matches every wrangler.jsonc
74 run: node scripts/deploy.mjs manifest --check
75 - name: The deploy tool's tests
76 run: npm run test:deploy
77
78 plan:
79 name: Plan
80 needs: check
81 runs-on: ubuntu-latest
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9782 # Production's secrets, without a deployment: planning deploys nothing.
83 environment:
84 name: production
85 deployment: false
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow86 timeout-minutes: 15
87 outputs:
88 migrate: ${{ steps.plan.outputs.migrate }}
89 migrate_units: ${{ steps.plan.outputs.migrate_units }}
90 has_core: ${{ steps.plan.outputs.has_core }}
91 core: ${{ steps.plan.outputs.core }}
92 has_edge: ${{ steps.plan.outputs.has_edge }}
93 edge: ${{ steps.plan.outputs.edge }}
94 has_front: ${{ steps.plan.outputs.has_front }}
95 front: ${{ steps.plan.outputs.front }}
96 steps:
97 - uses: actions/checkout@v5
98 with:
99 # Each Worker's live commit is compared with this one.
100 fetch-depth: 0
101 - name: Install Wrangler
102 run: npm ci --workspaces=false --no-audit --no-fund
103 - name: Plan
104 id: plan
105 env:
106 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
107 UNITS: ${{ inputs.units }}
108 ALL: ${{ inputs.all }}
109 run: |
110 args=()
111 if [ -n "$UNITS" ]; then args+=(--only "$UNITS" --force); fi
112 if [ "$ALL" = "true" ]; then args+=(--all); fi
113 node scripts/deploy.mjs plan "${args[@]}" --github-output
114
115 migrate:
116 name: Migrations
117 needs: plan
118 if: ${{ needs.plan.outputs.migrate == 'true' && inputs.dry_run != true }}
119 runs-on: ubuntu-latest
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97120 environment:
121 name: production
122 url: https://g1t.sh
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow123 timeout-minutes: 20
124 steps:
125 - uses: actions/checkout@v5
126 - name: Install Wrangler
127 run: npm ci --workspaces=false --no-audit --no-fund
128 - name: Apply pending migrations
129 env:
130 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
131 run: node scripts/deploy.mjs migrate --only "${{ needs.plan.outputs.migrate_units }}"
132
133 core:
134 name: core (${{ matrix.group }})
135 needs: [plan, migrate]
Fast pages, required checks on the branch, self-hosted runners, honest incidents136 # Runs when nothing before it failed: a migrate job skipped for having
137 # nothing to apply is not a failure.
138 if: ${{ !failure() && !cancelled() && needs.plan.outputs.has_core == 'true' && inputs.dry_run != true }}
Merge branch 'main' into actions-toolkit-oidc-artifacts139 # Rust builds and the runner's image get 4 vCPUs; everything else the
140 # standard machine.
141 runs-on: ${{ (matrix.rust || matrix.image) && 'g1t-4core' || 'ubuntu-latest' }}
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97142 environment:
143 name: production
144 url: https://g1t.sh
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow145 timeout-minutes: 60
146 strategy:
147 # A deploy cut off halfway is worse than one that finishes: the other
148 # jobs of a stage run on when one fails, and the next stage does not.
149 fail-fast: false
150 max-parallel: 4
151 matrix: ${{ fromJSON(needs.plan.outputs.core) }}
152 steps: &deploy
153 - uses: actions/checkout@v5
154 with:
155 fetch-depth: 0
156 # Rust workers: the wasm target, and worker-build kept between runs
157 # (its version is pinned in scripts/build-rust-worker.mjs).
158 - name: Rust for Workers
159 if: ${{ matrix.rust }}
160 run: rustup target add wasm32-unknown-unknown
161 - name: Cache worker-build
162 if: ${{ matrix.rust }}
163 uses: actions/cache@v4
164 with:
165 path: ~/.cargo/bin/worker-build
166 key: worker-build-${{ runner.os }}-${{ hashFiles('scripts/build-rust-worker.mjs') }}
167 - name: Cache worker-build's tools (wasm-bindgen, esbuild)
168 if: ${{ matrix.rust }}
169 uses: actions/cache@v4
170 with:
171 path: ~/.cache/worker-build
172 key: worker-build-tools-${{ runner.os }}-${{ hashFiles('scripts/build-rust-worker.mjs') }}
173 - name: Cache crates
174 if: ${{ matrix.rust }}
175 uses: actions/cache@v4
176 with:
177 path: ~/.cargo/registry/cache
178 key: cargo-crates-${{ runner.os }}-${{ hashFiles('Cargo.lock') }}
179 restore-keys: cargo-crates-${{ runner.os }}-
Fast pages, required checks on the branch, self-hosted runners, honest incidents180 # The compiled dependencies of this job's units, for wasm32 and the
181 # build scripts and proc macros they run. The workspace's own crates
182 # are compiled again whatever is cached (a checkout's sources are
183 # newer), so an entry is saved only when the dependencies change: a
184 # new Cargo.lock, or a new base image (base.json names its Rust).
185 # Otherwise the nearest earlier entry, of any group, is a start.
186 - name: Cache the Cargo target
187 if: ${{ matrix.rust }}
188 uses: actions/cache@v4
189 with:
190 path: |
191 target/release
192 target/wasm32-unknown-unknown/release
193 !target/**/incremental
194 !target/**/*.wasm
195 key: cargo-target-${{ runner.os }}-${{ matrix.group }}-${{ hashFiles('Cargo.lock', 'services/runner/base.json') }}
196 restore-keys: |
197 cargo-target-${{ runner.os }}-${{ matrix.group }}-
198 cargo-target-${{ runner.os }}-
Merge branch 'main' into actions-toolkit-oidc-artifacts199 # The runner's image: its binary, built natively for musl (the base
200 # has musl-gcc; the target is added here), with its Cargo target kept
201 # between runs. The image itself is built and pushed with the job's
202 # own Docker Engine (scripts/deploy/image.mjs).
203 - name: Rust for the runner
204 if: ${{ matrix.image }}
205 run: rustup target add x86_64-unknown-linux-musl
206 - name: Cache the runner's build
207 if: ${{ matrix.image }}
208 uses: actions/cache@v4
209 with:
210 path: |
211 ~/.cargo/registry/cache
212 target/x86_64-unknown-linux-musl/release
213 !target/**/incremental
214 key: runner-musl-${{ runner.os }}-${{ hashFiles('Cargo.lock', 'services/runner/base.json') }}
215 restore-keys: runner-musl-${{ runner.os }}-
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow216 - name: Install
217 run: node scripts/deploy.mjs install --only "${{ matrix.units }}"
218 - name: Deploy ${{ matrix.units }}
219 env:
220 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
Merge status detection: first-byte speed probe, deploy windows, 4 of 5 with a re-check, check history, reminders221 # status.g1t.sh hears the deploy start and finish, so its restarts
222 # are not drafted as incidents. Optional: without it, nothing is sent.
223 STATUS_DEPLOY_TOKEN: ${{ secrets.STATUS_DEPLOY_TOKEN }}
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow224 run: node scripts/deploy.mjs deploy --only "${{ matrix.units }}" --force --no-migrations --concurrency 2
225
226 edge:
227 name: edge (${{ matrix.group }})
228 needs: [plan, migrate, core]
Fast pages, required checks on the branch, self-hosted runners, honest incidents229 if: ${{ !failure() && !cancelled() && needs.plan.outputs.has_edge == 'true' && inputs.dry_run != true }}
Merge branch 'main' into actions-toolkit-oidc-artifacts230 runs-on: ${{ (matrix.rust || matrix.image) && 'g1t-4core' || 'ubuntu-latest' }}
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97231 environment:
232 name: production
233 url: https://g1t.sh
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow234 timeout-minutes: 60
235 strategy:
236 fail-fast: false
237 max-parallel: 4
238 matrix: ${{ fromJSON(needs.plan.outputs.edge) }}
239 steps: *deploy
240
241 front:
242 name: front (${{ matrix.group }})
243 needs: [plan, migrate, core, edge]
Fast pages, required checks on the branch, self-hosted runners, honest incidents244 if: ${{ !failure() && !cancelled() && needs.plan.outputs.has_front == 'true' && inputs.dry_run != true }}
Merge branch 'main' into actions-toolkit-oidc-artifacts245 runs-on: ${{ (matrix.rust || matrix.image) && 'g1t-4core' || 'ubuntu-latest' }}
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97246 environment:
247 name: production
248 url: https://g1t.sh
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow249 timeout-minutes: 60
250 strategy:
251 fail-fast: false
252 max-parallel: 4
253 matrix: ${{ fromJSON(needs.plan.outputs.front) }}
254 steps: *deploy

This file's history is long; its oldest lines are credited to the oldest commit read.