diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index f24f7b3..3967d2e 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -1,83 +1,52 @@ name: Build and Deploy to Cloudflare Pages on: - push: - branches: - - main + push: + branches: + - feat/initial-site + - main jobs: - build: - runs-on: ubuntu-latest - container: - # Same digest the Dockerfile pins: one pinned base image and the - # same dependency list (script/bootstrap) for both the check build - # and the deploy build. The one extra thing this job needs on top - # of the Dockerfile is the Actions runner's own prerequisites -- - # see the first step. - # alpine 3.21, 2026-02-28 - image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709 - defaults: - run: - # The default step shell is bash; this image has only busybox - # sh, so say so explicitly rather than rely on a fallback. - shell: sh - steps: - # This image is bare busybox+musl. act_runner executes JavaScript - # actions (checkout, upload-artifact) with `node` *inside* the job - # container and does not inject one, so node has to exist before - # the first `uses:` step -- script/bootstrap runs too late. git is - # needed for checkout's `submodules: recursive` (without it - # checkout degrades to a tarball download that cannot do - # submodules). An inline `run:` needs only a shell, so this step - # works on the bare image. These apk packages resolve at run time - # and are not hash-pinned; that gap is repo-wide (script/bootstrap - # has it too) and is tracked in #19. - - name: Install runner prerequisites - run: apk add --no-cache nodejs git tar + build: + runs-on: ubuntu-latest + container: + image: klakegg/hugo:ext-alpine + steps: + - name: Checkout + uses: actions/checkout@v4 + with: + submodules: recursive - - name: Checkout - # actions/checkout v4.2.2, 2026-02-28 - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 - with: - submodules: recursive + - name: Build site + run: hugo --minify - - name: Install build dependencies - run: script/bootstrap + - name: Archive site + run: tar -czf site.tar.gz public - - name: Build site - run: script/test + - name: Upload artifact + uses: actions/upload-artifact@v3 + with: + name: site + path: site.tar.gz - - name: Archive site - run: tar -czf site.tar.gz public + deploy: + runs-on: ubuntu-latest + needs: build + container: + image: node:20 + steps: + - name: Download artifact + uses: actions/download-artifact@v3 + with: + name: site - - name: Upload artifact - # actions/upload-artifact v4.6.2, 2026-08-09 - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 - with: - name: site - path: site.tar.gz + - name: Extract site + run: tar -xzf site.tar.gz - deploy: - runs-on: ubuntu-latest - needs: build - container: - # node 20.20.2-bookworm, 2026-08-09 - image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5 - steps: - - name: Download artifact - # actions/download-artifact v4.3.0, 2026-08-09 - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 - with: - name: site + - name: Install Wrangler + run: npm install -g wrangler - - name: Extract site - run: tar -xzf site.tar.gz - - - name: Install Wrangler - # wrangler 4.120.0, 2026-08-09 - run: npm install -g wrangler@4.120.0 - - - name: Deploy to Cloudflare Pages - run: wrangler pages deploy public --project-name=lora-vegas --branch=${{ github.ref_name }} - env: - CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} + - name: Deploy to Cloudflare Pages + run: wrangler pages deploy public --project-name=lora-vegas --branch=${{ github.ref_name }} + env: + CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} diff --git a/TODO.md b/TODO.md index 7b81a32..c8a581c 100644 --- a/TODO.md +++ b/TODO.md @@ -14,8 +14,7 @@ pre-1.0 No git tags. The site is live and now has the scripts-to-rule-them-all scaffold (`Makefile`, `script/`, `Dockerfile`, `check.yml`); still missing `LICENSE` and -policy files. Every external reference in the repo is now pinned by -cryptographic hash (or, for the wrangler CLI install, an exact version). +policy files. # Next Step @@ -25,17 +24,6 @@ Update `README.md` accordingly. # Completed Steps -- 2026-08-09: hash-pinned every external reference in - `.gitea/workflows/deploy.yml` (closes #7): both job container images are - pinned by digest, all three `uses:` are pinned by 40-hex commit SHA - (`upload`/`download-artifact` moved v3 to v4), and the wrangler install is - pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is - gone: the build job now runs on the same pinned `alpine` digest the - `Dockerfile` uses, with a pre-checkout `apk add nodejs git tar` step (the - Actions runner needs `node` inside the job container to execute JavaScript - actions), an explicit `shell: sh` default, then `script/bootstrap` and - `script/test`. Also dropped the dead `feat/initial-site` push trigger and - reindented the file to 4-space YAML to match `check.yml` - 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/` entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus `.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running @@ -52,6 +40,9 @@ Update `README.md` accordingly. # Future Steps +- Pin the images and actions in `deploy.yml` by sha256 + (`klakegg/hugo:ext-alpine`, `node:20`, `actions/checkout`, + `upload`/`download-artifact` are all unpinned) - Rework README.md into the standard sections: Description, Getting Started, Rationale, Design, TODO, License, Author (currently About, Contributing, Technical Details, License)