Skip to content

g1t/scripts/deploy.mjs

545 lines24,571 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow1#!/usr/bin/env node
2// Deploys g1t to Cloudflare from deploy/stack.jsonc: only what changed since
3// each Worker's live commit, migrations first, then stage by stage.
4// docs/DEPLOYING.md is the guide.
5//
6// node scripts/deploy.mjs plan what would deploy, and why (read-only)
7// node scripts/deploy.mjs deploy migrations, then every changed unit
8// node scripts/deploy.mjs deploy --only web,api just these (if changed; --force: anyway)
9// node scripts/deploy.mjs build --only events build as a deploy would, upload nothing
10// node scripts/deploy.mjs migrate pending D1 migrations only
11// node scripts/deploy.mjs manifest [--check] the resolved manifest, or its problems
12// node scripts/deploy.mjs doctor which units lack their secrets
13// node scripts/deploy.mjs install --only a,b npm ci of just what those units need (CI)
Fast pages, required checks on the branch, self-hosted runners, honest incidents14// node scripts/deploy.mjs build-base build and push the runner's base image (Docker)
15// node scripts/deploy.mjs image build and push the runner's image for this checkout (Docker)
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow16//
17// Flags: --all (every unit, changed or not), --only a,b, --skip a,b,
18// --force, --concurrency N (default 4), --stage core (one stage),
19// --json (plan), --out FILE (plan), --no-migrations, --allow-dirty,
Fast pages, required checks on the branch, self-hosted runners, honest incidents20// --rebuild-image, --rebuild-base, --since REV (Workers with no recorded
21// commit are taken to run REV); for build-base and image, --no-push, and
22// for build-base, --no-cache.
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow23
24import { appendFileSync, mkdirSync, writeFileSync } from "node:fs";
25import { tmpdir } from "node:os";
26import { join } from "node:path";
27
Fast pages, required checks on the branch, self-hosted runners, honest incidents28import { OUT_DIR } from "./build-runner.mjs";
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow29import { ensureWorkerBuild } from "./build-rust-worker.mjs";
30import {
31 annotation,
32 applyMigrations,
33 dockerAvailable,
34 exec,
35 jsonFrom,
36 lastLines,
37 pendingMigrations,
38 readLive,
39 versionFrom,
40 wrangler,
41 wranglerEnv,
42} from "./deploy/cloudflare.mjs";
Fast pages, required checks on the branch, self-hosted runners, honest incidents43import {
44 baseInputs,
45 baseState,
46 baseTag,
47 baseVersions,
48 buildBase,
49 buildRunnerImage,
50 dockerHas,
51 dockerLogin,
52 imageSize,
53 pushImage,
54 readBaseLock,
55 registryHas,
56 removeDeployConfig,
57 runnerRef,
58 writeBaseLock,
59 writeDeployConfig,
60} from "./deploy/image.mjs";
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow61import { decide, git, planJson, pool, table } from "./deploy/plan.mjs";
62import { ROOT, byStage, codeStages, findWranglerConfigs, npmCiArgs, npmWorkspace, pick, problems, resolvedStack } from "./deploy/stack.mjs";
63
Deploying: never roll production back by accident64const USAGE = "usage: node scripts/deploy.mjs plan|deploy|build|migrate|manifest|doctor|install|build-base|image [--all] [--only a,b] [--skip a,b] [--force] [--rollback] [--concurrency N] [--stage S] [--json]";
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow65
66function parseArgs(argv) {
67 const opts = { command: argv[0], only: [], skip: [], concurrency: 4, force: false, all: false, json: false };
68 for (let i = 1; i < argv.length; i++) {
69 const arg = argv[i];
70 const [flag, inline] = arg.split(/=(.*)/s);
71 const value = () => inline ?? argv[++i];
72 if (flag === "--only") opts.only.push(value());
73 else if (flag === "--skip") opts.skip.push(value());
74 else if (flag === "--concurrency") opts.concurrency = Number(value());
75 else if (flag === "--stage") opts.stage = value();
76 else if (flag === "--all") opts.all = true;
77 else if (flag === "--force") opts.force = true;
Deploying: never roll production back by accident78 else if (flag === "--rollback") opts.rollback = true;
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow79 else if (flag === "--json") opts.json = true;
80 else if (flag === "--check") opts.check = true;
81 else if (flag === "--no-migrations") opts.noMigrations = true;
82 else if (flag === "--allow-dirty") opts.allowDirty = true;
83 else if (flag === "--rebuild-image") opts.rebuildImage = true;
Fast pages, required checks on the branch, self-hosted runners, honest incidents84 else if (flag === "--rebuild-base") opts.rebuildBase = true;
85 else if (flag === "--no-push") opts.noPush = true;
86 else if (flag === "--no-cache") opts.noCache = true;
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow87 else if (flag === "--out") opts.out = value();
88 else if (flag === "--since") opts.since = value();
89 else if (flag === "--github-output") opts.githubOutput = true;
90 else throw new Error(`unknown flag ${arg}\n${USAGE}`);
91 }
92 if (!Number.isInteger(opts.concurrency) || opts.concurrency < 1) throw new Error("--concurrency is a whole number, 1 or more");
93 return opts;
94}
95
96/** The units a command works on: --only (or all), less --skip, in --stage. */
97function selected(stack, opts) {
98 let units = opts.only.length ? pick(stack, opts.only) : [...stack.units];
99 const skipped = pick(stack, opts.skip);
100 units = units.filter((u) => !skipped.includes(u));
101 if (opts.stage) {
102 if (!codeStages(stack).includes(opts.stage)) throw new Error(`--stage is one of ${codeStages(stack).join(", ")}`);
103 units = units.filter((u) => u.stage === opts.stage);
104 }
105 // Manifest order, whatever order they were named in.
106 return stack.units.filter((u) => units.includes(u));
107}
108
109const log = (...args) => console.error(...args);
110
111/**
112 * The plan for a workflow (.g1t/workflows/deploy.yml): job outputs in
113 * $GITHUB_OUTPUT, and the plan as a table in $GITHUB_STEP_SUMMARY.
114 */
115function writeGithubOutputs(data, p) {
116 const lines = [
117 `commit=${data.commit}`,
118 `migrate=${data.migrations.length > 0}`,
119 `migrate_units=${data.migrations.map((m) => m.unit).join(",")}`,
120 `deploying=${data.units.filter((u) => u.deploy).map((u) => u.unit).join(",")}`,
121 ];
122 for (const [stage, { jobs }] of Object.entries(data.stages)) {
123 // A matrix needs one entry; an empty stage's job is skipped by its `if`.
124 const include = jobs.length ? jobs : [{ group: "none", units: "" }];
125 lines.push(`has_${stage}=${jobs.length > 0}`, `${stage}=${JSON.stringify({ include })}`);
126 }
Deploying: a Plan that cannot read migrations says why127 if (data.migration_errors.length) {
128 // The units, then why for the first: one cause (a token, say) is usually all of them.
129 throw new Error(`Could not read pending migrations: ${data.migration_errors.map((e) => e.unit).join(", ")}
130${data.migration_errors[0].error}`);
131 }
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow132 if (process.env.GITHUB_OUTPUT) appendFileSync(process.env.GITHUB_OUTPUT, `${lines.join("\n")}\n`);
133 else console.log(lines.join("\n"));
134 if (process.env.GITHUB_STEP_SUMMARY) {
135 const rows = p.decisions.map((d) => `| ${d.unit.id} | ${d.unit.stage} | ${d.deploy ? "deploy" : ""} | ${d.since ? d.since.slice(0, 12) : "?"} | ${d.reason.replaceAll("|", "\\|")} |`);
136 const pending = data.migrations.map((m) => `- ${m.database}: ${m.pending.join(", ")}`);
137 appendFileSync(
138 process.env.GITHUB_STEP_SUMMARY,
139 [`## Deploy plan for ${data.commit.slice(0, 12)}`, "", "| unit | stage | action | live | why |", "| --- | --- | --- | --- | --- |", ...rows, "", pending.length ? "### Pending migrations" : "", ...pending, ""].join("\n"),
140 );
141 }
142}
143
144const seconds = (ms) => `${(ms / 1000).toFixed(1)}s`;
145
146/** Reads what each unit runs and what its database is waiting for. */
147async function survey(units, opts) {
148 const live = {};
149 const migrations = {};
150 const tasks = [
151 ...(opts.noLive ? [] : units).map((unit) => async () => {
152 live[unit.id] = await readLive(unit);
153 }),
154 ...(opts.noMigrations ? [] : units.filter((u) => u.d1)).map((unit) => async () => {
155 migrations[unit.id] = await pendingMigrations(unit);
156 }),
157 ];
158 await pool(tasks, Math.max(8, opts.concurrency * 2), (task) => task());
159 return { live, migrations };
160}
161
162async function plan(stack, opts) {
163 const units = selected(stack, opts);
164 const head = git.head();
165 const { live, migrations } = await survey(units, opts);
166 // --since: what a Worker with no recorded commit is taken to run (once,
167 // to adopt Workers deployed before this tool), for example --since HEAD~3.
168 if (opts.since) {
169 const since = git.resolve(opts.since);
170 for (const unit of units) {
171 const found = live[unit.id];
172 if (found && !found.sha && !found.missing && !found.error) live[unit.id] = { ...found, sha: since, assumed: true };
173 }
174 }
Deploying: never roll production back by accident175 const decisions = decide(units, { live, head, force: opts.force || opts.all, rollback: opts.rollback });
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow176 return { head, units, live, migrations, decisions };
177}
178
179function buildPlan(stack, opts) {
180 const units = selected(stack, opts);
181 return {
182 head: git.head(),
183 units,
184 live: {},
185 migrations: {},
186 decisions: units.map((unit) => ({ unit, deploy: true, reason: "build", since: null, files: [], image: false })),
187 };
188}
189
190function printPlan(stack, { head, decisions, migrations, live }) {
191 console.log(`Deploying ${head.slice(0, 12)} (${git.subject()})\n`);
192 const rows = decisions.map((d) => [
193 d.unit.id,
194 d.unit.stage,
195 d.deploy ? "deploy" : "-",
196 d.since ? d.since.slice(0, 12) + (live[d.unit.id]?.assumed ? "*" : "") : "?",
197 d.unit.d1 ? (migrations[d.unit.id]?.error ? "error" : String(migrations[d.unit.id]?.pending?.length ?? "-")) : "",
198 d.reason + (d.image ? "; image rebuilds" : ""),
199 ]);
200 console.log(table(rows, ["unit", "stage", "action", "live", "migrations", "why"]));
201 if (decisions.some((d) => live[d.unit.id]?.assumed)) console.log("* taken from --since: no commit was recorded for it");
202 const pending = Object.entries(migrations).filter(([, m]) => m.pending?.length);
203 if (pending.length) {
204 console.log("\nPending migrations:");
205 for (const [id, m] of pending) console.log(` ${stack.units.find((u) => u.id === id).d1.database}: ${m.pending.join(", ")}`);
206 }
207 for (const [id, m] of Object.entries(migrations).filter(([, m]) => m.error)) {
208 console.log(`\nCould not list ${id}'s migrations:\n${m.error}`);
209 }
210 const deploying = decisions.filter((d) => d.deploy).map((d) => d.unit);
211 console.log(
212 deploying.length
213 ? `\n${deploying.length} to deploy: ${byStage(stack, deploying).map((g) => `${g.stage} (${g.units.map((u) => u.id).join(", ")})`).join(" -> ")}`
214 : "\nNothing to deploy.",
215 );
216}
217
218/** Output of one unit, prefixed, to the terminal and a log file. */
219function unitLogger(id) {
220 const dir = join(tmpdir(), "g1t-deploy");
221 mkdirSync(dir, { recursive: true });
222 const file = join(dir, `${id}.log`);
223 const lines = [];
224 return {
225 file,
226 line: (text) => {
227 lines.push(text);
228 if (text.trim()) log(`[${id}] ${text}`);
229 },
230 save: () => writeFileSync(file, `${lines.join("\n")}\n`),
231 };
232}
233
Fast pages, required checks on the branch, self-hosted runners, honest incidents234/**
235 * The runner's image for this checkout, by registry reference: already in
236 * the registry (built by an earlier deploy, `deploy.mjs image`, or on
237 * another machine), or built and pushed here, which needs Docker. A dry
238 * run builds it locally and pushes nothing. Returns { ref, note }.
239 */
240async function runnerImage(unit, { dryRun, docker, rebuildImage, rebuildBase }, out) {
241 let base = baseState(unit);
242 if (!base.current || rebuildBase) {
243 if (!rebuildBase) {
244 throw new Error(
245 `${unit.image.base.context} has changed since ${unit.image.base.lock} was written${base.lock ? "" : " (the base has never been built)"}. Build and push the base, and commit ${unit.image.base.lock}: node scripts/deploy.mjs build-base`,
246 );
247 }
248 if (!docker) throw new Error("--rebuild-base needs Docker.");
249 await newBase(unit, { push: !dryRun, onLine: out.line });
250 base = baseState(unit);
251 }
252 if (!base.pushed && !dryRun) throw new Error(`${unit.image.base.lock} records a base that was never pushed: node scripts/deploy.mjs build-base`);
253 const ref = runnerRef(unit);
254 const tag = ref.split(":").pop();
255 if (!rebuildImage) {
256 if (dryRun && docker && (await dockerHas(ref))) return { ref, note: `image ${tag} already built here` };
257 if (!dryRun) {
258 try {
259 if (await registryHas(ref)) return { ref, note: `image ${tag} already in the registry` };
260 } catch (error) {
261 out.line(`could not ask the registry for ${tag}: ${error.message ?? error}`);
262 }
263 }
264 }
265 if (!docker) {
266 throw new Error(
267 `its image ${tag} is not in the registry, and Docker is not available here. Build and push it from a machine with Docker (node scripts/deploy.mjs image), then run this again.`,
268 );
269 }
270 const started = Date.now();
271 const binary = await exec(process.execPath, [join(ROOT, "scripts/build-runner.mjs")], { onLine: out.line });
272 if (binary.code !== 0) throw new Error(`the runner binary did not build:\n${lastLines(binary.out)}`);
273 if (!dryRun) await dockerLogin({ push: true });
274 await buildRunnerImage(unit, { ref, base: base.ref, binaryDir: OUT_DIR, onLine: out.line });
275 if (!dryRun) await pushImage(ref, { onLine: out.line });
276 return { ref, note: `image ${tag} ${dryRun ? "built" : "built and pushed"} in ${seconds(Date.now() - started)}` };
277}
278
279/** Builds the base (and pushes it unless `push` is false), and writes its lock. */
280async function newBase(unit, { push = true, noCache = false, onLine = log } = {}) {
281 const started = Date.now();
282 const inputs = baseInputs(unit);
283 const tag = baseTag(inputs);
284 const previous = readBaseLock(unit);
285 // Logged in, the base it replaces is pulled as cache.
286 if (push || previous?.pushed) {
287 try {
288 await dockerLogin({ push });
289 } catch (error) {
290 if (push) throw error;
291 onLine(`not logged in to the registry, so no cache from it: ${error.message ?? error}`);
292 }
293 }
294 const ref = await buildBase(unit, { tag, previous: previous?.pushed ? previous.image : null, onLine, noCache });
295 const built = Date.now();
296 const [size, versions] = await Promise.all([imageSize(ref), baseVersions(ref)]);
297 const digest = push ? await pushImage(ref, { onLine }) : null;
298 const lock = { image: ref, digest, pushed: push, inputs, built_at: new Date().toISOString(), size_bytes: size, versions };
299 writeBaseLock(unit, lock);
300 onLine(`base ${tag}: built in ${seconds(built - started)}${push ? `, pushed in ${seconds(Date.now() - built)}` : ""}, ${(size / 1e9).toFixed(2)} GB unpacked`);
301 return lock;
302}
303
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow304/** Builds (and unless `dryRun`, deploys) one unit. */
Fast pages, required checks on the branch, self-hosted runners, honest incidents305async function ship(unit, decision, { head, subject, dirty, dryRun, docker, rebuildImage, rebuildBase }) {
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow306 const started = Date.now();
307 const out = unitLogger(unit.id);
308 const cwd = join(ROOT, unit.path);
309 const result = { unit: unit.id, stage: unit.stage, ok: false, version: null, ms: 0, note: "" };
310 try {
311 if (unit.kind === "react-router" || unit.kind === "astro") {
Deploys print no DEP0190: npm's commands go to the shell as one string312 // One command string: Node warns about arguments passed beside shell: true.
313 const built = await exec("npm run build", [], { cwd, onLine: out.line, shell: true, env: wranglerEnv() });
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow314 if (built.code !== 0) throw new Error(`npm run build failed:\n${lastLines(built.out)}`);
315 }
316 const args = ["deploy"];
317 if (dryRun) {
318 args.push("--dry-run", "--outdir", join(tmpdir(), "g1t-deploy", "dist", unit.id));
319 } else {
320 const { message, tag } = annotation(head, subject);
321 args.push("--message", dirty ? message.replace(/^g1t-deploy/, "g1t-deploy-dirty") : message, "--tag", tag);
322 }
323 if (unit.image) {
Fast pages, required checks on the branch, self-hosted runners, honest incidents324 // Wrangler is given the image by reference, so it builds nothing.
325 const image = await runnerImage(unit, { dryRun, docker, rebuildImage, rebuildBase }, out);
326 args.push("--config", writeDeployConfig(unit, image.ref));
327 // Nothing the image is built from changed: the running sandboxes
328 // keep going, and new ones start from the same image.
329 if (!rebuildImage && !rebuildBase && !decision.image) args.push("--containers-rollout", "none");
330 result.note = image.note;
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow331 }
332 const deployed = await wrangler(args, { cwd, onLine: out.line });
333 if (deployed.code !== 0) throw new Error(`wrangler deploy failed:\n${lastLines(deployed.out)}`);
334 result.version = dryRun ? "(dry run)" : versionFrom(deployed.out);
335 result.ok = true;
336 } catch (error) {
337 result.note = String(error.message ?? error);
Fast pages, required checks on the branch, self-hosted runners, honest incidents338 } finally {
339 if (unit.image) removeDeployConfig(unit);
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow340 }
341 result.ms = Date.now() - started;
342 out.save();
343 if (!result.ok) result.note += `\n full log: ${out.file}`;
344 return result;
345}
346
347async function migrate(stack, units, migrations, opts) {
348 const due = units.filter((u) => migrations[u.id]?.pending?.length);
349 const broken = units.filter((u) => migrations[u.id]?.error);
350 if (broken.length) {
351 throw new Error(`Could not read pending migrations for ${broken.map((u) => u.id).join(", ")}; nothing was deployed.`);
352 }
353 if (!due.length) return [];
354 log(`== migrations: ${due.map((u) => `${u.d1.database} (${migrations[u.id].pending.length})`).join(", ")}`);
355 const results = await pool(due, opts.concurrency, async (unit) => {
356 const started = Date.now();
357 const out = unitLogger(`${unit.id}-migrations`);
358 const applied = await applyMigrations(unit, out.line);
359 out.save();
360 return {
361 unit: `${unit.id} (D1 ${unit.d1.database})`,
362 stage: "migrations",
363 ok: applied.code === 0,
364 version: `${migrations[unit.id].pending.length} applied`,
365 ms: Date.now() - started,
366 note: applied.code === 0 ? "" : `${lastLines(applied.out)}\n full log: ${out.file}`,
367 };
368 });
369 return results;
370}
371
372function summary(results) {
373 const rows = results.map((r) => [r.unit, r.stage, r.ok ? "ok" : r.skipped ? "not started" : "FAILED", r.version ?? "", r.ms ? seconds(r.ms) : "", r.note.split("\n")[0]]);
374 console.log(`\n${table(rows, ["unit", "stage", "result", "version", "time", "note"])}`);
375 for (const r of results.filter((r) => !r.ok && !r.skipped)) console.log(`\n${r.unit}: ${r.note}`);
376}
377
378async function deploy(stack, opts, { dryRun = false } = {}) {
379 const started = Date.now();
380 // A build reads nothing from Cloudflare: it builds what it is given.
381 const p = dryRun ? buildPlan(stack, opts) : await plan(stack, opts);
382 if (!dryRun) printPlan(stack, p);
383 const deploying = p.decisions.filter((d) => d.deploy);
384 const touched = deploying.map((d) => d.unit);
385 const head = p.head;
386
387 // A deploy names the commit it came from, so a dirty tree would be
388 // recorded as something it is not.
389 const dirtyFiles = git.dirty();
390 const dirty = deploying.some((d) => dirtyFiles.some((file) => file.startsWith(`${d.unit.path}/`) || d.unit.dependsOn.some((dir) => file.startsWith(`${dir}/`)) || d.unit.inputs.includes(file)));
391 if (dirty && !dryRun && !opts.allowDirty) {
392 throw new Error("Uncommitted changes touch what would deploy. Commit them, or pass --allow-dirty (the deploy then records no commit, and the next plan deploys it again).");
393 }
394
395 const results = [];
396 if (!dryRun && !opts.noMigrations) {
397 const migrated = await migrate(stack, p.units, p.migrations, opts);
398 results.push(...migrated);
399 if (migrated.some((r) => !r.ok)) {
400 summary(results);
401 return false;
402 }
403 }
404 if (!touched.length) {
405 if (results.length) summary(results);
406 return true;
407 }
408
409 if (touched.some((u) => u.kind === "rust-worker")) ensureWorkerBuild();
410 const docker = touched.some((u) => u.image) ? await dockerAvailable() : false;
Fast pages, required checks on the branch, self-hosted runners, honest incidents411 const context = { head, subject: git.subject(), dirty, dryRun, docker, rebuildImage: opts.rebuildImage, rebuildBase: opts.rebuildBase };
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow412
413 let failed = false;
414 for (const { stage, units } of byStage(stack, touched)) {
415 if (failed) {
416 for (const unit of units) results.push({ unit: unit.id, stage, ok: false, skipped: true, ms: 0, note: "an earlier stage failed" });
417 continue;
418 }
419 log(`== ${stage}: ${units.map((u) => u.id).join(", ")}`);
420 const shipped = await pool(units, opts.concurrency, (unit) => ship(unit, deploying.find((d) => d.unit === unit), context));
421 results.push(...shipped);
422 failed = shipped.some((r) => !r.ok);
423 }
424 summary(results);
425 console.log(`\n${failed ? "Failed" : dryRun ? "Built" : "Deployed"} in ${seconds(Date.now() - started)}.`);
426 return !failed;
427}
428
429async function doctor(stack, opts) {
430 const units = selected(stack, opts);
431 const rows = await pool(units, 8, async (unit) => {
432 if (!unit.secrets.length) return [unit.id, "", "", ""];
433 const found = await wrangler(["secret", "list", "--name", unit.worker, "--format", "json"], { cwd: join(ROOT, unit.path) });
434 if (found.code !== 0) return [unit.id, unit.secrets.join(" "), "?", "could not read"];
435 const have = new Set(jsonFrom(found.out).map((s) => s.name));
436 const missing = unit.secrets.filter((name) => !have.has(name));
437 return [unit.id, unit.secrets.join(" "), missing.join(" "), missing.length ? "missing" : "ok"];
438 });
439 console.log(table(rows, ["unit", "secrets", "missing", "result"]));
440 return rows.every((r) => r[3] !== "missing");
441}
442
443async function install(stack, opts) {
444 const units = selected(stack, opts);
445 const args = npmCiArgs(units, npmWorkspace());
446 log(`npm ${args.join(" ")}`);
Deploys print no DEP0190: npm's commands go to the shell as one string447 const done = await exec(`npm ${args.join(" ")}`, [], { cwd: ROOT, shell: true, onLine: (line) => log(line) });
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow448 return done.code === 0;
449}
450
451function manifest(stack, opts) {
452 const found = problems(stack, findWranglerConfigs());
453 if (opts.check) {
454 for (const problem of found) console.log(`- ${problem}`);
455 console.log(found.length ? `\n${found.length} problems in deploy/stack.jsonc.` : "deploy/stack.jsonc is consistent with every wrangler.jsonc.");
456 return !found.length;
457 }
458 const out = stack.units.map(({ config, ...unit }) => ({
459 ...unit,
460 queues: { produces: (config?.queues?.producers ?? []).map((q) => q.queue), consumes: (config?.queues?.consumers ?? []).map((q) => q.queue) },
461 kv: (config?.kv_namespaces ?? []).map((kv) => stack.resources.kv?.[kv.id] ?? kv.id),
462 r2: (config?.r2_buckets ?? []).map((b) => b.bucket_name),
463 vectorize: (config?.vectorize ?? []).map((v) => v.index_name),
464 dispatch_namespaces: (config?.dispatch_namespaces ?? []).map((d) => d.namespace),
465 routes: (config?.routes ?? []).map((r) => r.pattern),
466 }));
467 if (opts.json) console.log(JSON.stringify({ stages: stack.stages, units: out }, null, 2));
468 else
469 console.log(
470 table(
471 out.map((u) => [u.id, u.stage, u.kind, u.worker, u.d1?.database ?? "", u.dependsOn.join(" ")]),
472 ["unit", "stage", "kind", "worker", "d1", "built from (besides its folder)"],
473 ),
474 );
475 return true;
476}
477
Fast pages, required checks on the branch, self-hosted runners, honest incidents478/** The unit with a Containers image (the runner), or the one named. */
479function imageUnit(stack, opts) {
480 const units = (opts.only.length ? pick(stack, opts.only) : stack.units).filter((u) => u.image?.base);
481 if (units.length !== 1) throw new Error("Name the unit with a Containers image: --only runner");
482 return units[0];
483}
484
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow485async function main() {
486 const opts = parseArgs(process.argv.slice(2));
487 const stack = resolvedStack();
488 switch (opts.command) {
489 case "plan": {
490 const p = await plan(stack, opts);
491 const data = planJson(stack, p.decisions, p.migrations, p.head);
492 if (opts.out) writeFileSync(opts.out, `${JSON.stringify(data)}\n`);
493 if (opts.githubOutput) writeGithubOutputs(data, p);
494 if (opts.json) console.log(JSON.stringify(data, null, 2));
495 else if (!opts.githubOutput || process.env.GITHUB_OUTPUT) printPlan(stack, p);
496 return true;
497 }
498 case "deploy":
499 return deploy(stack, opts);
500 case "build":
501 return deploy(stack, { ...opts, force: true }, { dryRun: true });
502 case "migrate": {
503 const units = selected(stack, opts);
504 const { migrations } = await survey(units.filter((u) => u.d1), { ...opts, noMigrations: false, noLive: true });
505 const results = await migrate(stack, units, migrations, opts);
506 if (results.length) summary(results);
507 else console.log("No migrations to apply.");
508 return results.every((r) => r.ok);
509 }
510 case "manifest":
511 return manifest(stack, opts);
512 case "doctor":
513 return doctor(stack, opts);
514 case "install":
515 return install(stack, opts);
Fast pages, required checks on the branch, self-hosted runners, honest incidents516 case "build-base": {
517 const unit = imageUnit(stack, opts);
518 if (!(await dockerAvailable())) throw new Error("build-base needs Docker.");
519 const lock = await newBase(unit, { push: !opts.noPush, noCache: opts.noCache });
520 console.log(JSON.stringify(lock, null, 2));
521 if (lock.pushed) console.log(`\nCommit ${unit.image.base.lock}: the next deploy builds the runner's image on this base.`);
522 return true;
523 }
524 case "image": {
525 const unit = imageUnit(stack, opts);
526 const out = unitLogger(`${unit.id}-image`);
527 const docker = await dockerAvailable();
528 const image = await runnerImage(unit, { dryRun: Boolean(opts.noPush), docker, rebuildImage: opts.rebuildImage, rebuildBase: opts.rebuildBase }, out);
529 out.save();
530 console.log(`${image.ref}\n${image.note}`);
531 return true;
532 }
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow533 default:
534 console.error(USAGE);
535 return false;
536 }
537}
538
539main().then(
540 (ok) => process.exit(ok ? 0 : 1),
541 (error) => {
542 console.error(`\n${error.message ?? error}`);
543 process.exit(1);
544 },
545);