name: Build and Deploy to Cloudflare Pages on: push: branches: - main # TEMPORARY: development-only trigger so the build job actually # executes under act_runner before this reaches main. Removed in # the final commit. - pin-deploy-refs-observable jobs: build: runs-on: ubuntu-latest container: # Same digest the Dockerfile pins: one pinned base image and the # same dependency list (script/bootstrap) for both the check build # and the deploy build. The one extra thing this job needs on top # of the Dockerfile is the Actions runner's own prerequisites -- # see the first step. # alpine 3.21, 2026-02-28 image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709 defaults: run: # The default step shell is bash; this image has only busybox # sh, so say so explicitly rather than rely on a fallback. shell: sh steps: # This image is bare busybox+musl. act_runner executes JavaScript # actions (checkout, upload-artifact) with `node` *inside* the job # container and does not inject one, so node has to exist before # the first `uses:` step -- script/bootstrap runs too late. git is # needed for checkout's `submodules: recursive` (without it # checkout degrades to a tarball download that cannot do # submodules). An inline `run:` needs only a shell, so this step # works on the bare image. These apk packages resolve at run time # and are not hash-pinned; that gap is repo-wide (script/bootstrap # has it too) and is tracked in #19. - name: Install runner prerequisites run: apk add --no-cache nodejs git tar - name: Checkout # actions/checkout v4.2.2, 2026-02-28 uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 with: submodules: recursive - name: Install build dependencies run: script/bootstrap - name: Build site run: script/test - name: Archive site run: tar -czf site.tar.gz public - name: Upload artifact # actions/upload-artifact v4.6.2, 2026-08-09 uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 with: name: site path: site.tar.gz deploy: runs-on: ubuntu-latest needs: build # Publishing guard. This job spends CLOUDFLARE_API_TOKEN and creates a # real Cloudflare Pages deployment, so it must never run off main -- # not even if a branch is added to the push trigger above, deliberately # or by accident. Costs one line; the build job stays exercisable from # a branch without this job touching anything external. if: github.ref_name == 'main' container: # node 20.20.2-bookworm, 2026-08-09 image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5 steps: - name: Download artifact # actions/download-artifact v4.3.0, 2026-08-09 uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 with: name: site - name: Extract site run: tar -xzf site.tar.gz - name: Install Wrangler # wrangler 4.120.0, 2026-08-09 run: npm install -g wrangler@4.120.0 - name: Deploy to Cloudflare Pages run: wrangler pages deploy public --project-name=lora-vegas --branch=${{ github.ref_name }} env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}