Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| CI: every pull request into main builds and tests everything | 1 | # Tests every pull request into main, so main can always be deployed. The |
| 2 | # "Default branch" ruleset requires this workflow ("CI") to pass before a | |
| 3 | # pull request merges; people may still push to main directly, agents | |
| 4 | # may not. Deploy (deploy.yml) ships what lands on main. | |
| 5 | # | |
| 6 | # rust every crate's tests, natively | |
| 7 | # typescript type checks and tests of the apps and TS services, the | |
| 8 | # deploy and ops scripts, and the deploy manifest | |
| 9 | # build the site, sudo and the docs build as they deploy | |
| 10 | name: CI | |
| 11 | ||
| 12 | on: | |
| 13 | pull_request: | |
| 14 | branches: [main] | |
| 15 | workflow_dispatch: | |
| 16 | ||
| 17 | concurrency: | |
| 18 | group: ci-${{ github.ref }} | |
| 19 | cancel-in-progress: true | |
| 20 | ||
| 21 | env: | |
| 22 | CARGO_TERM_COLOR: never | |
| 23 | WRANGLER_SEND_METRICS: "false" | |
| 24 | ||
| 25 | jobs: | |
| 26 | rust: | |
| 27 | name: Rust | |
| 28 | runs-on: g1t-4core | |
| 29 | timeout-minutes: 45 | |
| 30 | steps: | |
| 31 | - uses: actions/checkout@v5 | |
| 32 | - name: Cache crates | |
| 33 | uses: actions/cache@v4 | |
| 34 | with: | |
| 35 | path: ~/.cargo/registry/cache | |
| 36 | key: cargo-crates-${{ runner.os }}-${{ hashFiles('Cargo.lock') }} | |
| 37 | restore-keys: cargo-crates-${{ runner.os }}- | |
| 38 | - name: Cache the test build | |
| 39 | uses: actions/cache@v4 | |
| 40 | with: | |
| 41 | path: | | |
| 42 | target/debug | |
| 43 | !target/debug/incremental | |
| 44 | key: cargo-test-${{ runner.os }}-${{ hashFiles('Cargo.lock', 'services/runner/base.json') }} | |
| 45 | restore-keys: cargo-test-${{ runner.os }}- | |
| 46 | - name: Tests | |
| 47 | run: cargo test --workspace --locked --quiet | |
| 48 | ||
| 49 | typescript: | |
| 50 | name: TypeScript | |
| 51 | runs-on: ubuntu-latest | |
| 52 | timeout-minutes: 30 | |
| 53 | steps: | |
| 54 | - uses: actions/checkout@v5 | |
| 55 | - name: Install | |
| 56 | run: npm ci --no-audit --no-fund | |
| 57 | - name: Type checks | |
| 58 | run: npm run typecheck | |
| 59 | - name: Tests | |
| 60 | run: npm test --workspaces --if-present | |
| 61 | - name: The deploy tool's tests | |
| 62 | run: npm run test:deploy | |
| 63 | - name: The ops scripts' tests | |
| 64 | run: npm run test:ops | |
| 65 | - name: The manifest matches every wrangler.jsonc | |
| 66 | run: node scripts/deploy.mjs manifest --check | |
| 67 | ||
| 68 | build: | |
| 69 | name: Build | |
| 70 | runs-on: ubuntu-latest | |
| 71 | timeout-minutes: 30 | |
| 72 | steps: | |
| 73 | - uses: actions/checkout@v5 | |
| 74 | - name: Install | |
| 75 | run: npm ci --no-audit --no-fund | |
| 76 | - name: The site, sudo and the docs | |
| 77 | run: node scripts/deploy.mjs build --only web,sudo,docs |