Skip to content
288 linesCodeBlameRaw
1# Deploys g1t.sh from main, with g1t's own Actions. What it does is
2# scripts/deploy.mjs, the same tool a person runs; docs/DEPLOYING.md is the
3# guide.
4#
5# check the deploy manifest is consistent, and the tool's tests pass
6# plan what changed since each Worker's live commit, and pending migrations
7# (beside check, not after it: neither waits for the other)
8# migrate pending D1 migrations, before any code, once check and plan pass
9# core, edge, front the units of each stage, in jobs that share a build;
10# a stage starts only when the one before it succeeded
11# smoke sign-in, sign-up and the waitlist still work on g1t.sh
12#
13# Each run that deploys is one production deployment of g1t.sh, made by the
14# jobs that name `environment: production` (one per run, however many jobs):
15# in progress when the first starts, then a success or a failure when the
16# run ends. It shows on the project's Deployments page and as the commit's
17# `deploy / production` check. The plan job reads production's secrets
18# with `deployment: false`, so a dry run or a change that deploys nothing
19# makes no deployment.
20#
21# Needs the repository secret CLOUDFLARE_API_TOKEN (a Production row, with
22# Containers write), the variable CLOUDFLARE_ACCOUNT_ID, and
23# api.cloudflare.com among the project's workflow-only domains for
24# deploy.yml in production (Settings, Guardrails), and
25# registry.cloudflare.com there too, to find, pull and push the runner's
26# image. A job that must build that image (the `runner-image` group) does
27# so with its own Docker Engine, on a larger machine. Optionally, the
28# secret STATUS_DEPLOY_TOKEN (the status Worker's secret of the same name)
29# and status.g1t.sh among the same workflow-only domains, so status.g1t.sh
30# hears each deploy start and finish. See docs/DEPLOYING.md.
31name: Deploy
32
33on:
34 push:
35 branches: [main]
36 workflow_dispatch:
37 inputs:
38 units:
39 description: "Units to deploy whether or not they changed, comma separated (empty: what changed)"
40 type: string
41 default: ""
42 all:
43 description: "Deploy every unit"
44 type: boolean
45 default: false
46 dry_run:
47 description: "Plan only: deploy nothing"
48 type: boolean
49 default: false
50
51# Its token only reads: deploying uses CLOUDFLARE_API_TOKEN, and g1t
52# records the deployments itself.
53permissions:
54 contents: read
55
56# One deploy at a time, and never one cut off halfway: the next waits.
57concurrency:
58 group: deploy-production
59 cancel-in-progress: false
60
61env:
62 CLOUDFLARE_ACCOUNT_ID: ${{ vars.CLOUDFLARE_ACCOUNT_ID }}
63 CARGO_TERM_COLOR: never
64 WRANGLER_SEND_METRICS: "false"
65
66jobs:
67 check:
68 name: Check
69 runs-on: ubuntu-latest
70 timeout-minutes: 20
71 steps:
72 - uses: actions/checkout@v5
73 - name: Install Wrangler
74 run: npm ci --workspaces=false --no-audit --no-fund
75 - name: The manifest matches every wrangler.jsonc
76 run: node scripts/deploy.mjs manifest --check
77 - name: The deploy tool's tests
78 run: npm run test:deploy
79
80 # Runs beside check: nothing deploys until both have succeeded.
81 plan:
82 name: Plan
83 runs-on: ubuntu-latest
84 # Production's secrets, without a deployment: planning deploys nothing.
85 environment:
86 name: production
87 deployment: false
88 timeout-minutes: 15
89 outputs:
90 migrate: ${{ steps.plan.outputs.migrate }}
91 migrate_units: ${{ steps.plan.outputs.migrate_units }}
92 has_core: ${{ steps.plan.outputs.has_core }}
93 core: ${{ steps.plan.outputs.core }}
94 has_edge: ${{ steps.plan.outputs.has_edge }}
95 edge: ${{ steps.plan.outputs.edge }}
96 has_front: ${{ steps.plan.outputs.has_front }}
97 front: ${{ steps.plan.outputs.front }}
98 steps:
99 - uses: actions/checkout@v5
100 with:
101 # Each Worker's live commit is compared with this one.
102 fetch-depth: 0
103 # No npm ci: with CLOUDFLARE_API_TOKEN the plan reads Cloudflare's API
104 # itself (scripts/deploy/cloudflare.mjs), and needs no Wrangler.
105 - name: Plan
106 id: plan
107 env:
108 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
109 UNITS: ${{ inputs.units }}
110 ALL: ${{ inputs.all }}
111 run: |
112 args=()
113 if [ -n "$UNITS" ]; then args+=(--only "$UNITS" --force); fi
114 if [ "$ALL" = "true" ]; then args+=(--all); fi
115 node scripts/deploy.mjs plan "${args[@]}" --github-output
116
117 migrate:
118 name: Migrations
119 needs: [check, plan]
120 if: ${{ needs.plan.outputs.migrate == 'true' && inputs.dry_run != true }}
121 runs-on: ubuntu-latest
122 environment:
123 name: production
124 url: https://g1t.sh
125 timeout-minutes: 20
126 steps:
127 - uses: actions/checkout@v5
128 - name: Install Wrangler
129 run: npm ci --workspaces=false --no-audit --no-fund
130 - name: Apply pending migrations
131 env:
132 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
133 run: node scripts/deploy.mjs migrate --only "${{ needs.plan.outputs.migrate_units }}"
134
135 core:
136 name: core (${{ matrix.group }})
137 needs: [check, plan, migrate]
138 # Runs when nothing before it failed: a migrate job skipped for having
139 # nothing to apply is not a failure.
140 if: ${{ !failure() && !cancelled() && needs.plan.outputs.has_core == 'true' && inputs.dry_run != true }}
141 # Rust builds and the runner's image get 4 vCPUs; everything else the
142 # standard machine.
143 runs-on: ${{ (matrix.rust || matrix.image) && 'g1t-4core' || 'ubuntu-latest' }}
144 environment:
145 name: production
146 url: https://g1t.sh
147 timeout-minutes: 60
148 strategy:
149 # A deploy cut off halfway is worse than one that finishes: the other
150 # jobs of a stage run on when one fails, and the next stage does not.
151 fail-fast: false
152 max-parallel: 4
153 matrix: ${{ fromJSON(needs.plan.outputs.core) }}
154 steps: &deploy
155 - uses: actions/checkout@v5
156 with:
157 fetch-depth: 0
158 # Rust workers: the wasm target, and worker-build kept between runs
159 # (its version is pinned in scripts/build-rust-worker.mjs).
160 - name: Rust for Workers
161 if: ${{ matrix.rust }}
162 run: rustup target add wasm32-unknown-unknown
163 - name: Cache worker-build
164 if: ${{ matrix.rust }}
165 uses: actions/cache@v4
166 with:
167 path: ~/.cargo/bin/worker-build
168 key: worker-build-${{ runner.os }}-${{ hashFiles('scripts/build-rust-worker.mjs') }}
169 - name: Cache worker-build's tools (wasm-bindgen, esbuild)
170 if: ${{ matrix.rust }}
171 uses: actions/cache@v4
172 with:
173 path: ~/.cache/worker-build
174 key: worker-build-tools-${{ runner.os }}-${{ hashFiles('scripts/build-rust-worker.mjs') }}
175 - name: Cache crates
176 if: ${{ matrix.rust }}
177 uses: actions/cache@v4
178 with:
179 path: ~/.cargo/registry/cache
180 key: cargo-crates-${{ runner.os }}-${{ hashFiles('Cargo.lock') }}
181 restore-keys: cargo-crates-${{ runner.os }}-
182 # The compiled dependencies of this job's units, for wasm32 and the
183 # build scripts and proc macros they run. Cargo calls rustc again for
184 # the workspace's own crates whatever is cached (a checkout's sources
185 # are newer); sccache, below, answers those calls. So an entry is
186 # saved only when the dependencies change: a new Cargo.lock, or a new
187 # base image (base.json names its Rust). Otherwise the nearest earlier
188 # entry, of any group, is a start.
189 - name: Cache the Cargo target
190 if: ${{ matrix.rust }}
191 uses: actions/cache@v4
192 with:
193 path: |
194 target/release
195 target/wasm32-unknown-unknown/release
196 !target/**/incremental
197 !target/**/*.wasm
198 key: cargo-target-${{ runner.os }}-${{ matrix.group }}-${{ hashFiles('Cargo.lock', 'services/runner/base.json') }}
199 restore-keys: |
200 cargo-target-${{ runner.os }}-${{ matrix.group }}-
201 cargo-target-${{ runner.os }}-
202 # The runner's image: its binary, built natively for musl (the base
203 # has musl-gcc; the target is added here), with its Cargo target kept
204 # between runs. The image itself is built and pushed with the job's
205 # own Docker Engine (scripts/deploy/image.mjs).
206 - name: Rust for the runner
207 if: ${{ matrix.image }}
208 run: rustup target add x86_64-unknown-linux-musl
209 - name: Cache the runner's build
210 if: ${{ matrix.image }}
211 uses: actions/cache@v4
212 with:
213 path: |
214 ~/.cargo/registry/cache
215 target/x86_64-unknown-linux-musl/release
216 !target/**/incremental
217 key: runner-musl-${{ runner.os }}-${{ hashFiles('Cargo.lock', 'services/runner/base.json') }}
218 restore-keys: runner-musl-${{ runner.os }}-
219 # Every rustc call that makes a library (the workspace's crates,
220 # which Cargo compiles again on every checkout, and any dependency
221 # not restored above) is looked up by its inputs in the repository's
222 # Actions cache: unchanged crates come back from it instead of being
223 # compiled. A Worker's own crate (a cdylib) and the runner's binary
224 # are still compiled. worker-build runs Cargo, so its wasm32 builds
225 # go through it too; wasm-bindgen and wasm-opt are not rustc.
226 # Pinned by version and sha256 in scripts/sccache.sh; without the
227 # cache, the job builds as before.
228 - name: sccache
229 if: ${{ matrix.rust || matrix.image }}
230 run: bash scripts/sccache.sh install
231 - name: Install
232 run: node scripts/deploy.mjs install --only "${{ matrix.units }}"
233 - name: Deploy ${{ matrix.units }}
234 env:
235 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
236 # status.g1t.sh hears the deploy start and finish, so its restarts
237 # are not drafted as incidents. Optional: without it, nothing is sent.
238 STATUS_DEPLOY_TOKEN: ${{ secrets.STATUS_DEPLOY_TOKEN }}
239 run: node scripts/deploy.mjs deploy --only "${{ matrix.units }}" --force --no-migrations --concurrency 2
240 # Hits and misses, on the log and in the run's summary.
241 - name: sccache's hits and misses
242 if: ${{ always() && (matrix.rust || matrix.image) }}
243 run: bash scripts/sccache.sh stats
244
245 edge:
246 name: edge (${{ matrix.group }})
247 needs: [check, plan, migrate, core]
248 if: ${{ !failure() && !cancelled() && needs.plan.outputs.has_edge == 'true' && inputs.dry_run != true }}
249 runs-on: ${{ (matrix.rust || matrix.image) && 'g1t-4core' || 'ubuntu-latest' }}
250 environment:
251 name: production
252 url: https://g1t.sh
253 timeout-minutes: 60
254 strategy:
255 fail-fast: false
256 max-parallel: 4
257 matrix: ${{ fromJSON(needs.plan.outputs.edge) }}
258 steps: *deploy
259
260 front:
261 name: front (${{ matrix.group }})
262 needs: [check, plan, migrate, core, edge]
263 if: ${{ !failure() && !cancelled() && needs.plan.outputs.has_front == 'true' && inputs.dry_run != true }}
264 runs-on: ${{ (matrix.rust || matrix.image) && 'g1t-4core' || 'ubuntu-latest' }}
265 environment:
266 name: production
267 url: https://g1t.sh
268 timeout-minutes: 60
269 strategy:
270 fail-fast: false
271 max-parallel: 4
272 matrix: ${{ fromJSON(needs.plan.outputs.front) }}
273 steps: *deploy
274
275 # Once everything has deployed: the ways in for someone new still work.
276 # The pages a visitor lands on load, and the waitlist form reaches
277 # identity, sent an address it refuses before keeping anything, so the
278 # real waitlist is never touched. scripts/ops/smoke.mjs.
279 smoke:
280 name: Smoke
281 needs: [check, plan, core, edge, front]
282 if: ${{ !failure() && !cancelled() && inputs.dry_run != true && (needs.plan.outputs.has_core == 'true' || needs.plan.outputs.has_edge == 'true' || needs.plan.outputs.has_front == 'true') }}
283 runs-on: ubuntu-latest
284 timeout-minutes: 5
285 steps:
286 - uses: actions/checkout@v5
287 - name: Sign-in, sign-up and the waitlist work
288 run: node scripts/ops/smoke.mjs