Hash-pin every external reference in deploy.yml, verified on a real runner (closes #7) #22
@@ -59,11 +59,12 @@ jobs:
|
||||
# identical to this one but ending in upload-artifact v4 fails,
|
||||
# while the same job without that step passes. So this stays on
|
||||
# the v3 line, pinned, using the node20 build of it rather than
|
||||
# the node16 default. Revisit when the artifact v4 protocol works
|
||||
# here; tracked separately.
|
||||
# here; tracked separately. This is the exact commit the mutable
|
||||
# `@v3` used to resolve to, i.e. the code that was deploying this
|
||||
# site before this issue -- now pinned instead of floating.
|
||||
- name: Upload artifact
|
||||
# actions/upload-artifact v3.2.2-node20, 2026-08-09
|
||||
uses: actions/upload-artifact@c6a3b2bd78b3985e4b2f15397fec357f0fd808de
|
||||
# actions/upload-artifact v3.2.1, 2026-08-09
|
||||
uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5
|
||||
with:
|
||||
name: site
|
||||
path: site.tar.gz
|
||||
@@ -83,9 +84,11 @@ jobs:
|
||||
steps:
|
||||
# Must match the upload-artifact major above -- v4 artifacts and
|
||||
# v3 artifacts are different protocols and do not interoperate.
|
||||
# Like the upload above, this is the exact commit `@v3` used to
|
||||
# resolve to.
|
||||
- name: Download artifact
|
||||
# actions/download-artifact v3.1.0-node20, 2026-08-09
|
||||
uses: actions/download-artifact@ad191675b41f6a5b46da9a048cb6893812da158b
|
||||
# actions/download-artifact v3.0.2, 2026-08-09
|
||||
uses: actions/download-artifact@9bc31d5ccc31df68ecc42ccf4149144866c47d8a
|
||||
with:
|
||||
name: site
|
||||
|
||||
|
||||
@@ -3,11 +3,9 @@
|
||||
# The Actions jobs/logs API is not readable by this account, so the only
|
||||
# available signal is the commit-status API, which reports one entry per
|
||||
# *job*. This file therefore encodes the diagnosis as job topology: each job
|
||||
# below isolates one hypothesis, and each shows up as its own status context,
|
||||
# so one push tests them all.
|
||||
# isolates one hypothesis and surfaces as its own status context.
|
||||
#
|
||||
# Round 1 result (commit 2d328e7), which is what these round 2 jobs follow up
|
||||
# on:
|
||||
# Round 1 (2d328e7):
|
||||
#
|
||||
# p1 bare alpine + checkout failure 3s
|
||||
# p2 alpine + apk nodejs git tar + checkout success 5s
|
||||
@@ -16,10 +14,21 @@
|
||||
# p5 node:20-alpine + checkout success 8s
|
||||
# p6 node:20-bookworm-slim + checkout success 11s
|
||||
#
|
||||
# So the pinned alpine image and the runner-prerequisite step are fine, the
|
||||
# site build inside the Actions container is fine, and the thing that fails is
|
||||
# actions/upload-artifact v4 -- the one step this issue changed protocol on.
|
||||
# Round 2 checks which pinned v3 build works and rehearses the deploy job.
|
||||
# -> the pinned alpine image, the prerequisite step and the site build are all
|
||||
# fine; upload-artifact v4 is what broke the deploy.
|
||||
#
|
||||
# Round 2 (602fd60):
|
||||
#
|
||||
# build (deploy.yml, upload v3.2.2-node20) success 20s
|
||||
# q1 upload-artifact v3.2.1 (node16) success 7s
|
||||
# q2 upload-artifact v3.2.1-n20 (node20) success 22s
|
||||
# q3 full build + upload v3.2.2-node20 success 11s
|
||||
# q4 download v3.1.0-node20 + wrangler install failure 43s
|
||||
#
|
||||
# -> build is green, every v3 upload works, and the remaining failure is
|
||||
# somewhere in the deploy-side rehearsal. Round 3 splits q4 into its parts:
|
||||
# wrangler on its own, the artifact pair that was actually deploying this
|
||||
# site before this issue, and the newer node20 artifact pair.
|
||||
name: probe
|
||||
|
||||
on:
|
||||
@@ -28,50 +37,24 @@ on:
|
||||
- pin-deploy-refs-observable
|
||||
|
||||
jobs:
|
||||
# Fallback A: the exact v3 the workflow used before this issue (node16
|
||||
# runtime), pinned.
|
||||
q1-upload-v3-node16:
|
||||
# Isolates the wrangler install and invocation from anything to do with
|
||||
# artifacts. wrangler 4.120.0 declares engines.node >= 22 while the deploy
|
||||
# container is node 20, so this needs measuring rather than assuming --
|
||||
# the pre-issue deploy did run an unpinned wrangler on node:20
|
||||
# successfully.
|
||||
r1-wrangler-only:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
# alpine 3.21, 2026-02-28
|
||||
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
||||
defaults:
|
||||
run:
|
||||
shell: sh
|
||||
# node 20.20.2-bookworm, 2026-08-09
|
||||
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
|
||||
steps:
|
||||
- run: apk add --no-cache nodejs git tar
|
||||
# actions/checkout v4.2.2, 2026-02-28
|
||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
- run: tar -czf probe-a.tar.gz hugo.toml
|
||||
# actions/upload-artifact v3.2.1, 2026-08-09
|
||||
- uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5
|
||||
with:
|
||||
name: probe-a
|
||||
path: probe-a.tar.gz
|
||||
# wrangler 4.120.0, 2026-08-09
|
||||
- run: npm install -g wrangler@4.120.0
|
||||
- run: wrangler --version
|
||||
|
||||
# Fallback B: same release, node20 runtime.
|
||||
q2-upload-v3-node20:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
# alpine 3.21, 2026-02-28
|
||||
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
||||
defaults:
|
||||
run:
|
||||
shell: sh
|
||||
steps:
|
||||
- run: apk add --no-cache nodejs git tar
|
||||
# actions/checkout v4.2.2, 2026-02-28
|
||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
- run: tar -czf probe-b.tar.gz hugo.toml
|
||||
# actions/upload-artifact v3.2.1-node20, 2026-08-09
|
||||
- uses: actions/upload-artifact@c24449f33cd45d4826c6702db7e49f7cdb9b551d
|
||||
with:
|
||||
name: probe-b
|
||||
path: probe-b.tar.gz
|
||||
|
||||
# Producer half of the round-trip rehearsal: byte-for-byte the build job
|
||||
# from deploy.yml.
|
||||
q3-build-for-roundtrip:
|
||||
# Producer for the pair that `@v3`/`@v3` resolved to before this issue,
|
||||
# i.e. the code that was actually deploying the site, now pinned.
|
||||
r2a-upload-proven:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
# alpine 3.21, 2026-02-28
|
||||
@@ -88,21 +71,53 @@ jobs:
|
||||
- run: script/bootstrap
|
||||
- run: script/test
|
||||
- run: tar -czf site.tar.gz public
|
||||
# actions/upload-artifact v3.2.1, 2026-08-09
|
||||
- uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5
|
||||
with:
|
||||
name: site-proven
|
||||
path: site.tar.gz
|
||||
|
||||
# Consumer half: the deploy job's artifact handling, with no wrangler, so
|
||||
# a failure here means the artifact round trip and a pass here means it is
|
||||
# sound.
|
||||
r2b-download-proven:
|
||||
runs-on: ubuntu-latest
|
||||
needs: r2a-upload-proven
|
||||
container:
|
||||
# node 20.20.2-bookworm, 2026-08-09
|
||||
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
|
||||
steps:
|
||||
# actions/download-artifact v3.0.2, 2026-08-09
|
||||
- uses: actions/download-artifact@9bc31d5ccc31df68ecc42ccf4149144866c47d8a
|
||||
with:
|
||||
name: site-proven
|
||||
- run: tar -xzf site.tar.gz
|
||||
- run: test -f public/index.html
|
||||
|
||||
# The newer node20 artifact pair, kept in the round so the choice between
|
||||
# the two pairs rests on measurement rather than preference.
|
||||
r3a-upload-node20:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
# alpine 3.21, 2026-02-28
|
||||
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
||||
defaults:
|
||||
run:
|
||||
shell: sh
|
||||
steps:
|
||||
- run: apk add --no-cache nodejs git tar
|
||||
# actions/checkout v4.2.2, 2026-02-28
|
||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
- run: tar -czf alt.tar.gz hugo.toml
|
||||
# actions/upload-artifact v3.2.2-node20, 2026-08-09
|
||||
- uses: actions/upload-artifact@c6a3b2bd78b3985e4b2f15397fec357f0fd808de
|
||||
with:
|
||||
name: site
|
||||
path: site.tar.gz
|
||||
name: alt-node20
|
||||
path: alt.tar.gz
|
||||
|
||||
# Consumer half: the deploy job with everything except the publish call.
|
||||
# Same pinned node image, same pinned download action, same pinned
|
||||
# wrangler version -- it just prints wrangler's version instead of running
|
||||
# `wrangler pages deploy`, so it touches nothing external and needs no
|
||||
# token. This is as close to exercising the deploy job as is possible
|
||||
# without actually deploying.
|
||||
q4-deploy-dryrun:
|
||||
r3b-download-node20:
|
||||
runs-on: ubuntu-latest
|
||||
needs: q3-build-for-roundtrip
|
||||
needs: r3a-upload-node20
|
||||
container:
|
||||
# node 20.20.2-bookworm, 2026-08-09
|
||||
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
|
||||
@@ -110,9 +125,5 @@ jobs:
|
||||
# actions/download-artifact v3.1.0-node20, 2026-08-09
|
||||
- uses: actions/download-artifact@ad191675b41f6a5b46da9a048cb6893812da158b
|
||||
with:
|
||||
name: site
|
||||
- run: tar -xzf site.tar.gz
|
||||
- run: test -f public/index.html
|
||||
# wrangler 4.120.0, 2026-08-09
|
||||
- run: npm install -g wrangler@4.120.0
|
||||
- run: wrangler --version
|
||||
name: alt-node20
|
||||
- run: test -f alt.tar.gz
|
||||
|
||||
Reference in New Issue
Block a user