diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 76d7cf7..f24f7b3 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -9,14 +9,34 @@ jobs: build: runs-on: ubuntu-latest container: - # Same digest the Dockerfile pins: one pinned base image and one - # dependency list (script/bootstrap) for both the check build and - # the deploy build. + # Same digest the Dockerfile pins: one pinned base image and the + # same dependency list (script/bootstrap) for both the check build + # and the deploy build. The one extra thing this job needs on top + # of the Dockerfile is the Actions runner's own prerequisites -- + # see the first step. # alpine 3.21, 2026-02-28 image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709 + defaults: + run: + # The default step shell is bash; this image has only busybox + # sh, so say so explicitly rather than rely on a fallback. + shell: sh steps: - # actions/checkout v4.2.2, 2026-08-09 + # This image is bare busybox+musl. act_runner executes JavaScript + # actions (checkout, upload-artifact) with `node` *inside* the job + # container and does not inject one, so node has to exist before + # the first `uses:` step -- script/bootstrap runs too late. git is + # needed for checkout's `submodules: recursive` (without it + # checkout degrades to a tarball download that cannot do + # submodules). An inline `run:` needs only a shell, so this step + # works on the bare image. These apk packages resolve at run time + # and are not hash-pinned; that gap is repo-wide (script/bootstrap + # has it too) and is tracked in #19. + - name: Install runner prerequisites + run: apk add --no-cache nodejs git tar + - name: Checkout + # actions/checkout v4.2.2, 2026-02-28 uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 with: submodules: recursive @@ -30,8 +50,8 @@ jobs: - name: Archive site run: tar -czf site.tar.gz public - # actions/upload-artifact v4.6.2, 2026-08-09 - name: Upload artifact + # actions/upload-artifact v4.6.2, 2026-08-09 uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 with: name: site @@ -44,8 +64,8 @@ jobs: # node 20.20.2-bookworm, 2026-08-09 image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5 steps: - # actions/download-artifact v4.3.0, 2026-08-09 - name: Download artifact + # actions/download-artifact v4.3.0, 2026-08-09 uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 with: name: site @@ -53,8 +73,8 @@ jobs: - name: Extract site run: tar -xzf site.tar.gz - # wrangler 4.120.0, 2026-08-09 - name: Install Wrangler + # wrangler 4.120.0, 2026-08-09 run: npm install -g wrangler@4.120.0 - name: Deploy to Cloudflare Pages diff --git a/TODO.md b/TODO.md index 163f0cf..7b81a32 100644 --- a/TODO.md +++ b/TODO.md @@ -31,9 +31,11 @@ Update `README.md` accordingly. (`upload`/`download-artifact` moved v3 to v4), and the wrangler install is pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is gone: the build job now runs on the same pinned `alpine` digest the - `Dockerfile` uses, with `script/bootstrap` then `script/test`. Also dropped - the dead `feat/initial-site` push trigger and reindented the file to 4-space - YAML to match `check.yml` + `Dockerfile` uses, with a pre-checkout `apk add nodejs git tar` step (the + Actions runner needs `node` inside the job container to execute JavaScript + actions), an explicit `shell: sh` default, then `script/bootstrap` and + `script/test`. Also dropped the dead `feat/initial-site` push trigger and + reindented the file to 4-space YAML to match `check.yml` - 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/` entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus `.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running