| 1 | #!/usr/bin/env node |
| 2 | // Deploys g1t to Cloudflare from deploy/stack.jsonc: only what changed since |
| 3 | // each Worker's live commit, migrations first, then stage by stage. |
| 4 | // docs/DEPLOYING.md is the guide. |
| 5 | // |
| 6 | // node scripts/deploy.mjs plan what would deploy, and why (read-only) |
| 7 | // node scripts/deploy.mjs deploy migrations, then every changed unit |
| 8 | // node scripts/deploy.mjs deploy --only web,api just these (if changed; --force: anyway) |
| 9 | // node scripts/deploy.mjs build --only events build as a deploy would, upload nothing |
| 10 | // node scripts/deploy.mjs migrate pending D1 migrations only |
| 11 | // node scripts/deploy.mjs manifest [--check] the resolved manifest, or its problems |
| 12 | // node scripts/deploy.mjs doctor which units lack their secrets |
| 13 | // node scripts/deploy.mjs install --only a,b npm ci of just what those units need (CI) |
| 14 | // node scripts/deploy.mjs build-base build and push the runner's base image (Docker) |
| 15 | // node scripts/deploy.mjs image build and push the runner's image for this checkout (Docker) |
| 16 | // |
| 17 | // Flags: --all (every unit, changed or not), --only a,b, --skip a,b, |
| 18 | // --force, --concurrency N (default 4), --stage core (one stage), |
| 19 | // --json (plan), --out FILE (plan), --no-migrations, --allow-dirty, |
| 20 | // --rebuild-image, --rebuild-base, --since REV (Workers with no recorded |
| 21 | // commit are taken to run REV); for build-base and image, --no-push, and |
| 22 | // for build-base, --no-cache. |
| 23 | |
| 24 | import { appendFileSync, mkdirSync, writeFileSync } from "node:fs"; |
| 25 | import { tmpdir } from "node:os"; |
| 26 | import { join } from "node:path"; |
| 27 | |
| 28 | import { OUT_DIR } from "./build-runner.mjs"; |
| 29 | import { ensureWorkerBuild } from "./build-rust-worker.mjs"; |
| 30 | import { |
| 31 | annotation, |
| 32 | applyMigrations, |
| 33 | dockerAvailable, |
| 34 | exec, |
| 35 | jsonFrom, |
| 36 | lastLines, |
| 37 | pendingMigrations, |
| 38 | readLive, |
| 39 | versionFrom, |
| 40 | wrangler, |
| 41 | wranglerEnv, |
| 42 | } from "./deploy/cloudflare.mjs"; |
| 43 | import { |
| 44 | baseInputs, |
| 45 | baseState, |
| 46 | baseTag, |
| 47 | baseVersions, |
| 48 | buildBase, |
| 49 | buildRunnerImage, |
| 50 | dockerHas, |
| 51 | dockerLogin, |
| 52 | imageSize, |
| 53 | pushImage, |
| 54 | readBaseLock, |
| 55 | registryHas, |
| 56 | removeDeployConfig, |
| 57 | runnerRef, |
| 58 | writeBaseLock, |
| 59 | writeDeployConfig, |
| 60 | } from "./deploy/image.mjs"; |
| 61 | import { decide, git, planJson, pool, table } from "./deploy/plan.mjs"; |
| 62 | import { ROOT, byStage, codeStages, findWranglerConfigs, npmCiArgs, npmWorkspace, pick, problems, resolvedStack } from "./deploy/stack.mjs"; |
| 63 | |
| 64 | const USAGE = "usage: node scripts/deploy.mjs plan|deploy|build|migrate|manifest|doctor|install|build-base|image [--all] [--only a,b] [--skip a,b] [--force] [--concurrency N] [--stage S] [--json]"; |
| 65 | |
| 66 | function parseArgs(argv) { |
| 67 | const opts = { command: argv[0], only: [], skip: [], concurrency: 4, force: false, all: false, json: false }; |
| 68 | for (let i = 1; i < argv.length; i++) { |
| 69 | const arg = argv[i]; |
| 70 | const [flag, inline] = arg.split(/=(.*)/s); |
| 71 | const value = () => inline ?? argv[++i]; |
| 72 | if (flag === "--only") opts.only.push(value()); |
| 73 | else if (flag === "--skip") opts.skip.push(value()); |
| 74 | else if (flag === "--concurrency") opts.concurrency = Number(value()); |
| 75 | else if (flag === "--stage") opts.stage = value(); |
| 76 | else if (flag === "--all") opts.all = true; |
| 77 | else if (flag === "--force") opts.force = true; |
| 78 | else if (flag === "--json") opts.json = true; |
| 79 | else if (flag === "--check") opts.check = true; |
| 80 | else if (flag === "--no-migrations") opts.noMigrations = true; |
| 81 | else if (flag === "--allow-dirty") opts.allowDirty = true; |
| 82 | else if (flag === "--rebuild-image") opts.rebuildImage = true; |
| 83 | else if (flag === "--rebuild-base") opts.rebuildBase = true; |
| 84 | else if (flag === "--no-push") opts.noPush = true; |
| 85 | else if (flag === "--no-cache") opts.noCache = true; |
| 86 | else if (flag === "--out") opts.out = value(); |
| 87 | else if (flag === "--since") opts.since = value(); |
| 88 | else if (flag === "--github-output") opts.githubOutput = true; |
| 89 | else throw new Error(`unknown flag ${arg}\n${USAGE}`); |
| 90 | } |
| 91 | if (!Number.isInteger(opts.concurrency) || opts.concurrency < 1) throw new Error("--concurrency is a whole number, 1 or more"); |
| 92 | return opts; |
| 93 | } |
| 94 | |
| 95 | /** The units a command works on: --only (or all), less --skip, in --stage. */ |
| 96 | function selected(stack, opts) { |
| 97 | let units = opts.only.length ? pick(stack, opts.only) : [...stack.units]; |
| 98 | const skipped = pick(stack, opts.skip); |
| 99 | units = units.filter((u) => !skipped.includes(u)); |
| 100 | if (opts.stage) { |
| 101 | if (!codeStages(stack).includes(opts.stage)) throw new Error(`--stage is one of ${codeStages(stack).join(", ")}`); |
| 102 | units = units.filter((u) => u.stage === opts.stage); |
| 103 | } |
| 104 | // Manifest order, whatever order they were named in. |
| 105 | return stack.units.filter((u) => units.includes(u)); |
| 106 | } |
| 107 | |
| 108 | const log = (...args) => console.error(...args); |
| 109 | |
| 110 | /** |
| 111 | * The plan for a workflow (.g1t/workflows/deploy.yml): job outputs in |
| 112 | * $GITHUB_OUTPUT, and the plan as a table in $GITHUB_STEP_SUMMARY. |
| 113 | */ |
| 114 | function writeGithubOutputs(data, p) { |
| 115 | const lines = [ |
| 116 | `commit=${data.commit}`, |
| 117 | `migrate=${data.migrations.length > 0}`, |
| 118 | `migrate_units=${data.migrations.map((m) => m.unit).join(",")}`, |
| 119 | `deploying=${data.units.filter((u) => u.deploy).map((u) => u.unit).join(",")}`, |
| 120 | ]; |
| 121 | for (const [stage, { jobs }] of Object.entries(data.stages)) { |
| 122 | // A matrix needs one entry; an empty stage's job is skipped by its `if`. |
| 123 | const include = jobs.length ? jobs : [{ group: "none", units: "" }]; |
| 124 | lines.push(`has_${stage}=${jobs.length > 0}`, `${stage}=${JSON.stringify({ include })}`); |
| 125 | } |
| 126 | if (data.migration_errors.length) throw new Error(`Could not read pending migrations: ${data.migration_errors.map((e) => e.unit).join(", ")}`); |
| 127 | if (process.env.GITHUB_OUTPUT) appendFileSync(process.env.GITHUB_OUTPUT, `${lines.join("\n")}\n`); |
| 128 | else console.log(lines.join("\n")); |
| 129 | if (process.env.GITHUB_STEP_SUMMARY) { |
| 130 | const rows = p.decisions.map((d) => `| ${d.unit.id} | ${d.unit.stage} | ${d.deploy ? "deploy" : ""} | ${d.since ? d.since.slice(0, 12) : "?"} | ${d.reason.replaceAll("|", "\\|")} |`); |
| 131 | const pending = data.migrations.map((m) => `- ${m.database}: ${m.pending.join(", ")}`); |
| 132 | appendFileSync( |
| 133 | process.env.GITHUB_STEP_SUMMARY, |
| 134 | [`## Deploy plan for ${data.commit.slice(0, 12)}`, "", "| unit | stage | action | live | why |", "| --- | --- | --- | --- | --- |", ...rows, "", pending.length ? "### Pending migrations" : "", ...pending, ""].join("\n"), |
| 135 | ); |
| 136 | } |
| 137 | } |
| 138 | |
| 139 | const seconds = (ms) => `${(ms / 1000).toFixed(1)}s`; |
| 140 | |
| 141 | /** Reads what each unit runs and what its database is waiting for. */ |
| 142 | async function survey(units, opts) { |
| 143 | const live = {}; |
| 144 | const migrations = {}; |
| 145 | const tasks = [ |
| 146 | ...(opts.noLive ? [] : units).map((unit) => async () => { |
| 147 | live[unit.id] = await readLive(unit); |
| 148 | }), |
| 149 | ...(opts.noMigrations ? [] : units.filter((u) => u.d1)).map((unit) => async () => { |
| 150 | migrations[unit.id] = await pendingMigrations(unit); |
| 151 | }), |
| 152 | ]; |
| 153 | await pool(tasks, Math.max(8, opts.concurrency * 2), (task) => task()); |
| 154 | return { live, migrations }; |
| 155 | } |
| 156 | |
| 157 | async function plan(stack, opts) { |
| 158 | const units = selected(stack, opts); |
| 159 | const head = git.head(); |
| 160 | const { live, migrations } = await survey(units, opts); |
| 161 | // --since: what a Worker with no recorded commit is taken to run (once, |
| 162 | // to adopt Workers deployed before this tool), for example --since HEAD~3. |
| 163 | if (opts.since) { |
| 164 | const since = git.resolve(opts.since); |
| 165 | for (const unit of units) { |
| 166 | const found = live[unit.id]; |
| 167 | if (found && !found.sha && !found.missing && !found.error) live[unit.id] = { ...found, sha: since, assumed: true }; |
| 168 | } |
| 169 | } |
| 170 | const decisions = decide(units, { live, head, force: opts.force || opts.all }); |
| 171 | return { head, units, live, migrations, decisions }; |
| 172 | } |
| 173 | |
| 174 | function buildPlan(stack, opts) { |
| 175 | const units = selected(stack, opts); |
| 176 | return { |
| 177 | head: git.head(), |
| 178 | units, |
| 179 | live: {}, |
| 180 | migrations: {}, |
| 181 | decisions: units.map((unit) => ({ unit, deploy: true, reason: "build", since: null, files: [], image: false })), |
| 182 | }; |
| 183 | } |
| 184 | |
| 185 | function printPlan(stack, { head, decisions, migrations, live }) { |
| 186 | console.log(`Deploying ${head.slice(0, 12)} (${git.subject()})\n`); |
| 187 | const rows = decisions.map((d) => [ |
| 188 | d.unit.id, |
| 189 | d.unit.stage, |
| 190 | d.deploy ? "deploy" : "-", |
| 191 | d.since ? d.since.slice(0, 12) + (live[d.unit.id]?.assumed ? "*" : "") : "?", |
| 192 | d.unit.d1 ? (migrations[d.unit.id]?.error ? "error" : String(migrations[d.unit.id]?.pending?.length ?? "-")) : "", |
| 193 | d.reason + (d.image ? "; image rebuilds" : ""), |
| 194 | ]); |
| 195 | console.log(table(rows, ["unit", "stage", "action", "live", "migrations", "why"])); |
| 196 | if (decisions.some((d) => live[d.unit.id]?.assumed)) console.log("* taken from --since: no commit was recorded for it"); |
| 197 | const pending = Object.entries(migrations).filter(([, m]) => m.pending?.length); |
| 198 | if (pending.length) { |
| 199 | console.log("\nPending migrations:"); |
| 200 | for (const [id, m] of pending) console.log(` ${stack.units.find((u) => u.id === id).d1.database}: ${m.pending.join(", ")}`); |
| 201 | } |
| 202 | for (const [id, m] of Object.entries(migrations).filter(([, m]) => m.error)) { |
| 203 | console.log(`\nCould not list ${id}'s migrations:\n${m.error}`); |
| 204 | } |
| 205 | const deploying = decisions.filter((d) => d.deploy).map((d) => d.unit); |
| 206 | console.log( |
| 207 | deploying.length |
| 208 | ? `\n${deploying.length} to deploy: ${byStage(stack, deploying).map((g) => `${g.stage} (${g.units.map((u) => u.id).join(", ")})`).join(" -> ")}` |
| 209 | : "\nNothing to deploy.", |
| 210 | ); |
| 211 | } |
| 212 | |
| 213 | /** Output of one unit, prefixed, to the terminal and a log file. */ |
| 214 | function unitLogger(id) { |
| 215 | const dir = join(tmpdir(), "g1t-deploy"); |
| 216 | mkdirSync(dir, { recursive: true }); |
| 217 | const file = join(dir, `${id}.log`); |
| 218 | const lines = []; |
| 219 | return { |
| 220 | file, |
| 221 | line: (text) => { |
| 222 | lines.push(text); |
| 223 | if (text.trim()) log(`[${id}] ${text}`); |
| 224 | }, |
| 225 | save: () => writeFileSync(file, `${lines.join("\n")}\n`), |
| 226 | }; |
| 227 | } |
| 228 | |
| 229 | /** |
| 230 | * The runner's image for this checkout, by registry reference: already in |
| 231 | * the registry (built by an earlier deploy, `deploy.mjs image`, or on |
| 232 | * another machine), or built and pushed here, which needs Docker. A dry |
| 233 | * run builds it locally and pushes nothing. Returns { ref, note }. |
| 234 | */ |
| 235 | async function runnerImage(unit, { dryRun, docker, rebuildImage, rebuildBase }, out) { |
| 236 | let base = baseState(unit); |
| 237 | if (!base.current || rebuildBase) { |
| 238 | if (!rebuildBase) { |
| 239 | throw new Error( |
| 240 | `${unit.image.base.context} has changed since ${unit.image.base.lock} was written${base.lock ? "" : " (the base has never been built)"}. Build and push the base, and commit ${unit.image.base.lock}: node scripts/deploy.mjs build-base`, |
| 241 | ); |
| 242 | } |
| 243 | if (!docker) throw new Error("--rebuild-base needs Docker."); |
| 244 | await newBase(unit, { push: !dryRun, onLine: out.line }); |
| 245 | base = baseState(unit); |
| 246 | } |
| 247 | if (!base.pushed && !dryRun) throw new Error(`${unit.image.base.lock} records a base that was never pushed: node scripts/deploy.mjs build-base`); |
| 248 | const ref = runnerRef(unit); |
| 249 | const tag = ref.split(":").pop(); |
| 250 | if (!rebuildImage) { |
| 251 | if (dryRun && docker && (await dockerHas(ref))) return { ref, note: `image ${tag} already built here` }; |
| 252 | if (!dryRun) { |
| 253 | try { |
| 254 | if (await registryHas(ref)) return { ref, note: `image ${tag} already in the registry` }; |
| 255 | } catch (error) { |
| 256 | out.line(`could not ask the registry for ${tag}: ${error.message ?? error}`); |
| 257 | } |
| 258 | } |
| 259 | } |
| 260 | if (!docker) { |
| 261 | throw new Error( |
| 262 | `its image ${tag} is not in the registry, and Docker is not available here. Build and push it from a machine with Docker (node scripts/deploy.mjs image), then run this again.`, |
| 263 | ); |
| 264 | } |
| 265 | const started = Date.now(); |
| 266 | const binary = await exec(process.execPath, [join(ROOT, "scripts/build-runner.mjs")], { onLine: out.line }); |
| 267 | if (binary.code !== 0) throw new Error(`the runner binary did not build:\n${lastLines(binary.out)}`); |
| 268 | if (!dryRun) await dockerLogin({ push: true }); |
| 269 | await buildRunnerImage(unit, { ref, base: base.ref, binaryDir: OUT_DIR, onLine: out.line }); |
| 270 | if (!dryRun) await pushImage(ref, { onLine: out.line }); |
| 271 | return { ref, note: `image ${tag} ${dryRun ? "built" : "built and pushed"} in ${seconds(Date.now() - started)}` }; |
| 272 | } |
| 273 | |
| 274 | /** Builds the base (and pushes it unless `push` is false), and writes its lock. */ |
| 275 | async function newBase(unit, { push = true, noCache = false, onLine = log } = {}) { |
| 276 | const started = Date.now(); |
| 277 | const inputs = baseInputs(unit); |
| 278 | const tag = baseTag(inputs); |
| 279 | const previous = readBaseLock(unit); |
| 280 | // Logged in, the base it replaces is pulled as cache. |
| 281 | if (push || previous?.pushed) { |
| 282 | try { |
| 283 | await dockerLogin({ push }); |
| 284 | } catch (error) { |
| 285 | if (push) throw error; |
| 286 | onLine(`not logged in to the registry, so no cache from it: ${error.message ?? error}`); |
| 287 | } |
| 288 | } |
| 289 | const ref = await buildBase(unit, { tag, previous: previous?.pushed ? previous.image : null, onLine, noCache }); |
| 290 | const built = Date.now(); |
| 291 | const [size, versions] = await Promise.all([imageSize(ref), baseVersions(ref)]); |
| 292 | const digest = push ? await pushImage(ref, { onLine }) : null; |
| 293 | const lock = { image: ref, digest, pushed: push, inputs, built_at: new Date().toISOString(), size_bytes: size, versions }; |
| 294 | writeBaseLock(unit, lock); |
| 295 | onLine(`base ${tag}: built in ${seconds(built - started)}${push ? `, pushed in ${seconds(Date.now() - built)}` : ""}, ${(size / 1e9).toFixed(2)} GB unpacked`); |
| 296 | return lock; |
| 297 | } |
| 298 | |
| 299 | /** Builds (and unless `dryRun`, deploys) one unit. */ |
| 300 | async function ship(unit, decision, { head, subject, dirty, dryRun, docker, rebuildImage, rebuildBase }) { |
| 301 | const started = Date.now(); |
| 302 | const out = unitLogger(unit.id); |
| 303 | const cwd = join(ROOT, unit.path); |
| 304 | const result = { unit: unit.id, stage: unit.stage, ok: false, version: null, ms: 0, note: "" }; |
| 305 | try { |
| 306 | if (unit.kind === "react-router" || unit.kind === "astro") { |
| 307 | const built = await exec("npm", ["run", "build"], { cwd, onLine: out.line, shell: true, env: wranglerEnv() }); |
| 308 | if (built.code !== 0) throw new Error(`npm run build failed:\n${lastLines(built.out)}`); |
| 309 | } |
| 310 | const args = ["deploy"]; |
| 311 | if (dryRun) { |
| 312 | args.push("--dry-run", "--outdir", join(tmpdir(), "g1t-deploy", "dist", unit.id)); |
| 313 | } else { |
| 314 | const { message, tag } = annotation(head, subject); |
| 315 | args.push("--message", dirty ? message.replace(/^g1t-deploy/, "g1t-deploy-dirty") : message, "--tag", tag); |
| 316 | } |
| 317 | if (unit.image) { |
| 318 | // Wrangler is given the image by reference, so it builds nothing. |
| 319 | const image = await runnerImage(unit, { dryRun, docker, rebuildImage, rebuildBase }, out); |
| 320 | args.push("--config", writeDeployConfig(unit, image.ref)); |
| 321 | // Nothing the image is built from changed: the running sandboxes |
| 322 | // keep going, and new ones start from the same image. |
| 323 | if (!rebuildImage && !rebuildBase && !decision.image) args.push("--containers-rollout", "none"); |
| 324 | result.note = image.note; |
| 325 | } |
| 326 | const deployed = await wrangler(args, { cwd, onLine: out.line }); |
| 327 | if (deployed.code !== 0) throw new Error(`wrangler deploy failed:\n${lastLines(deployed.out)}`); |
| 328 | result.version = dryRun ? "(dry run)" : versionFrom(deployed.out); |
| 329 | result.ok = true; |
| 330 | } catch (error) { |
| 331 | result.note = String(error.message ?? error); |
| 332 | } finally { |
| 333 | if (unit.image) removeDeployConfig(unit); |
| 334 | } |
| 335 | result.ms = Date.now() - started; |
| 336 | out.save(); |
| 337 | if (!result.ok) result.note += `\n full log: ${out.file}`; |
| 338 | return result; |
| 339 | } |
| 340 | |
| 341 | async function migrate(stack, units, migrations, opts) { |
| 342 | const due = units.filter((u) => migrations[u.id]?.pending?.length); |
| 343 | const broken = units.filter((u) => migrations[u.id]?.error); |
| 344 | if (broken.length) { |
| 345 | throw new Error(`Could not read pending migrations for ${broken.map((u) => u.id).join(", ")}; nothing was deployed.`); |
| 346 | } |
| 347 | if (!due.length) return []; |
| 348 | log(`== migrations: ${due.map((u) => `${u.d1.database} (${migrations[u.id].pending.length})`).join(", ")}`); |
| 349 | const results = await pool(due, opts.concurrency, async (unit) => { |
| 350 | const started = Date.now(); |
| 351 | const out = unitLogger(`${unit.id}-migrations`); |
| 352 | const applied = await applyMigrations(unit, out.line); |
| 353 | out.save(); |
| 354 | return { |
| 355 | unit: `${unit.id} (D1 ${unit.d1.database})`, |
| 356 | stage: "migrations", |
| 357 | ok: applied.code === 0, |
| 358 | version: `${migrations[unit.id].pending.length} applied`, |
| 359 | ms: Date.now() - started, |
| 360 | note: applied.code === 0 ? "" : `${lastLines(applied.out)}\n full log: ${out.file}`, |
| 361 | }; |
| 362 | }); |
| 363 | return results; |
| 364 | } |
| 365 | |
| 366 | function summary(results) { |
| 367 | const rows = results.map((r) => [r.unit, r.stage, r.ok ? "ok" : r.skipped ? "not started" : "FAILED", r.version ?? "", r.ms ? seconds(r.ms) : "", r.note.split("\n")[0]]); |
| 368 | console.log(`\n${table(rows, ["unit", "stage", "result", "version", "time", "note"])}`); |
| 369 | for (const r of results.filter((r) => !r.ok && !r.skipped)) console.log(`\n${r.unit}: ${r.note}`); |
| 370 | } |
| 371 | |
| 372 | async function deploy(stack, opts, { dryRun = false } = {}) { |
| 373 | const started = Date.now(); |
| 374 | // A build reads nothing from Cloudflare: it builds what it is given. |
| 375 | const p = dryRun ? buildPlan(stack, opts) : await plan(stack, opts); |
| 376 | if (!dryRun) printPlan(stack, p); |
| 377 | const deploying = p.decisions.filter((d) => d.deploy); |
| 378 | const touched = deploying.map((d) => d.unit); |
| 379 | const head = p.head; |
| 380 | |
| 381 | // A deploy names the commit it came from, so a dirty tree would be |
| 382 | // recorded as something it is not. |
| 383 | const dirtyFiles = git.dirty(); |
| 384 | const dirty = deploying.some((d) => dirtyFiles.some((file) => file.startsWith(`${d.unit.path}/`) || d.unit.dependsOn.some((dir) => file.startsWith(`${dir}/`)) || d.unit.inputs.includes(file))); |
| 385 | if (dirty && !dryRun && !opts.allowDirty) { |
| 386 | throw new Error("Uncommitted changes touch what would deploy. Commit them, or pass --allow-dirty (the deploy then records no commit, and the next plan deploys it again)."); |
| 387 | } |
| 388 | |
| 389 | const results = []; |
| 390 | if (!dryRun && !opts.noMigrations) { |
| 391 | const migrated = await migrate(stack, p.units, p.migrations, opts); |
| 392 | results.push(...migrated); |
| 393 | if (migrated.some((r) => !r.ok)) { |
| 394 | summary(results); |
| 395 | return false; |
| 396 | } |
| 397 | } |
| 398 | if (!touched.length) { |
| 399 | if (results.length) summary(results); |
| 400 | return true; |
| 401 | } |
| 402 | |
| 403 | if (touched.some((u) => u.kind === "rust-worker")) ensureWorkerBuild(); |
| 404 | const docker = touched.some((u) => u.image) ? await dockerAvailable() : false; |
| 405 | const context = { head, subject: git.subject(), dirty, dryRun, docker, rebuildImage: opts.rebuildImage, rebuildBase: opts.rebuildBase }; |
| 406 | |
| 407 | let failed = false; |
| 408 | for (const { stage, units } of byStage(stack, touched)) { |
| 409 | if (failed) { |
| 410 | for (const unit of units) results.push({ unit: unit.id, stage, ok: false, skipped: true, ms: 0, note: "an earlier stage failed" }); |
| 411 | continue; |
| 412 | } |
| 413 | log(`== ${stage}: ${units.map((u) => u.id).join(", ")}`); |
| 414 | const shipped = await pool(units, opts.concurrency, (unit) => ship(unit, deploying.find((d) => d.unit === unit), context)); |
| 415 | results.push(...shipped); |
| 416 | failed = shipped.some((r) => !r.ok); |
| 417 | } |
| 418 | summary(results); |
| 419 | console.log(`\n${failed ? "Failed" : dryRun ? "Built" : "Deployed"} in ${seconds(Date.now() - started)}.`); |
| 420 | return !failed; |
| 421 | } |
| 422 | |
| 423 | async function doctor(stack, opts) { |
| 424 | const units = selected(stack, opts); |
| 425 | const rows = await pool(units, 8, async (unit) => { |
| 426 | if (!unit.secrets.length) return [unit.id, "", "", ""]; |
| 427 | const found = await wrangler(["secret", "list", "--name", unit.worker, "--format", "json"], { cwd: join(ROOT, unit.path) }); |
| 428 | if (found.code !== 0) return [unit.id, unit.secrets.join(" "), "?", "could not read"]; |
| 429 | const have = new Set(jsonFrom(found.out).map((s) => s.name)); |
| 430 | const missing = unit.secrets.filter((name) => !have.has(name)); |
| 431 | return [unit.id, unit.secrets.join(" "), missing.join(" "), missing.length ? "missing" : "ok"]; |
| 432 | }); |
| 433 | console.log(table(rows, ["unit", "secrets", "missing", "result"])); |
| 434 | return rows.every((r) => r[3] !== "missing"); |
| 435 | } |
| 436 | |
| 437 | async function install(stack, opts) { |
| 438 | const units = selected(stack, opts); |
| 439 | const args = npmCiArgs(units, npmWorkspace()); |
| 440 | log(`npm ${args.join(" ")}`); |
| 441 | const done = await exec("npm", args, { cwd: ROOT, shell: true, onLine: (line) => log(line) }); |
| 442 | return done.code === 0; |
| 443 | } |
| 444 | |
| 445 | function manifest(stack, opts) { |
| 446 | const found = problems(stack, findWranglerConfigs()); |
| 447 | if (opts.check) { |
| 448 | for (const problem of found) console.log(`- ${problem}`); |
| 449 | console.log(found.length ? `\n${found.length} problems in deploy/stack.jsonc.` : "deploy/stack.jsonc is consistent with every wrangler.jsonc."); |
| 450 | return !found.length; |
| 451 | } |
| 452 | const out = stack.units.map(({ config, ...unit }) => ({ |
| 453 | ...unit, |
| 454 | queues: { produces: (config?.queues?.producers ?? []).map((q) => q.queue), consumes: (config?.queues?.consumers ?? []).map((q) => q.queue) }, |
| 455 | kv: (config?.kv_namespaces ?? []).map((kv) => stack.resources.kv?.[kv.id] ?? kv.id), |
| 456 | r2: (config?.r2_buckets ?? []).map((b) => b.bucket_name), |
| 457 | vectorize: (config?.vectorize ?? []).map((v) => v.index_name), |
| 458 | dispatch_namespaces: (config?.dispatch_namespaces ?? []).map((d) => d.namespace), |
| 459 | routes: (config?.routes ?? []).map((r) => r.pattern), |
| 460 | })); |
| 461 | if (opts.json) console.log(JSON.stringify({ stages: stack.stages, units: out }, null, 2)); |
| 462 | else |
| 463 | console.log( |
| 464 | table( |
| 465 | out.map((u) => [u.id, u.stage, u.kind, u.worker, u.d1?.database ?? "", u.dependsOn.join(" ")]), |
| 466 | ["unit", "stage", "kind", "worker", "d1", "built from (besides its folder)"], |
| 467 | ), |
| 468 | ); |
| 469 | return true; |
| 470 | } |
| 471 | |
| 472 | /** The unit with a Containers image (the runner), or the one named. */ |
| 473 | function imageUnit(stack, opts) { |
| 474 | const units = (opts.only.length ? pick(stack, opts.only) : stack.units).filter((u) => u.image?.base); |
| 475 | if (units.length !== 1) throw new Error("Name the unit with a Containers image: --only runner"); |
| 476 | return units[0]; |
| 477 | } |
| 478 | |
| 479 | async function main() { |
| 480 | const opts = parseArgs(process.argv.slice(2)); |
| 481 | const stack = resolvedStack(); |
| 482 | switch (opts.command) { |
| 483 | case "plan": { |
| 484 | const p = await plan(stack, opts); |
| 485 | const data = planJson(stack, p.decisions, p.migrations, p.head); |
| 486 | if (opts.out) writeFileSync(opts.out, `${JSON.stringify(data)}\n`); |
| 487 | if (opts.githubOutput) writeGithubOutputs(data, p); |
| 488 | if (opts.json) console.log(JSON.stringify(data, null, 2)); |
| 489 | else if (!opts.githubOutput || process.env.GITHUB_OUTPUT) printPlan(stack, p); |
| 490 | return true; |
| 491 | } |
| 492 | case "deploy": |
| 493 | return deploy(stack, opts); |
| 494 | case "build": |
| 495 | return deploy(stack, { ...opts, force: true }, { dryRun: true }); |
| 496 | case "migrate": { |
| 497 | const units = selected(stack, opts); |
| 498 | const { migrations } = await survey(units.filter((u) => u.d1), { ...opts, noMigrations: false, noLive: true }); |
| 499 | const results = await migrate(stack, units, migrations, opts); |
| 500 | if (results.length) summary(results); |
| 501 | else console.log("No migrations to apply."); |
| 502 | return results.every((r) => r.ok); |
| 503 | } |
| 504 | case "manifest": |
| 505 | return manifest(stack, opts); |
| 506 | case "doctor": |
| 507 | return doctor(stack, opts); |
| 508 | case "install": |
| 509 | return install(stack, opts); |
| 510 | case "build-base": { |
| 511 | const unit = imageUnit(stack, opts); |
| 512 | if (!(await dockerAvailable())) throw new Error("build-base needs Docker."); |
| 513 | const lock = await newBase(unit, { push: !opts.noPush, noCache: opts.noCache }); |
| 514 | console.log(JSON.stringify(lock, null, 2)); |
| 515 | if (lock.pushed) console.log(`\nCommit ${unit.image.base.lock}: the next deploy builds the runner's image on this base.`); |
| 516 | return true; |
| 517 | } |
| 518 | case "image": { |
| 519 | const unit = imageUnit(stack, opts); |
| 520 | const out = unitLogger(`${unit.id}-image`); |
| 521 | const docker = await dockerAvailable(); |
| 522 | const image = await runnerImage(unit, { dryRun: Boolean(opts.noPush), docker, rebuildImage: opts.rebuildImage, rebuildBase: opts.rebuildBase }, out); |
| 523 | out.save(); |
| 524 | console.log(`${image.ref}\n${image.note}`); |
| 525 | return true; |
| 526 | } |
| 527 | default: |
| 528 | console.error(USAGE); |
| 529 | return false; |
| 530 | } |
| 531 | } |
| 532 | |
| 533 | main().then( |
| 534 | (ok) => process.exit(ok ? 0 : 1), |
| 535 | (error) => { |
| 536 | console.error(`\n${error.message ?? error}`); |
| 537 | process.exit(1); |
| 538 | }, |
| 539 | ); |