name: Build and Deploy to Cloudflare Pages on: push: branches: - main # TEMPORARY: development-only trigger so the build job actually # executes under act_runner before this reaches main. Removed in # the final commit. - pin-deploy-refs-observable jobs: build: runs-on: ubuntu-latest container: # Same digest the Dockerfile pins: one pinned base image and the # same dependency list (script/bootstrap) for both the check build # and the deploy build. The one extra thing this job needs on top # of the Dockerfile is the Actions runner's own prerequisites -- # see the first step. # alpine 3.21, 2026-02-28 image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709 defaults: run: # The default step shell is bash; this image has only busybox # sh, so say so explicitly rather than rely on a fallback. shell: sh steps: # This image is bare busybox+musl. act_runner executes JavaScript # actions (checkout, upload-artifact) with `node` *inside* the job # container and does not inject one, so node has to exist before # the first `uses:` step -- script/bootstrap runs too late. git is # needed for checkout's `submodules: recursive` (without it # checkout degrades to a tarball download that cannot do # submodules). An inline `run:` needs only a shell, so this step # works on the bare image. These apk packages resolve at run time # and are not hash-pinned; that gap is repo-wide (script/bootstrap # has it too) and is tracked in #19. - name: Install runner prerequisites run: apk add --no-cache nodejs git tar - name: Checkout # actions/checkout v4.2.2, 2026-02-28 uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 with: submodules: recursive - name: Install build dependencies run: script/bootstrap - name: Build site run: script/test - name: Archive site run: tar -czf site.tar.gz public # v4 does not work on this Gitea Actions instance -- it is what # broke the deploy in run 25. Measured on this branch: a job # identical to this one but ending in upload-artifact v4 fails, # while the same job without that step passes. So this stays on # the v3 line, pinned, using the node20 build of it rather than # the node16 default. Revisit when the artifact v4 protocol works # here; tracked separately. - name: Upload artifact # actions/upload-artifact v3.2.2-node20, 2026-08-09 uses: actions/upload-artifact@c6a3b2bd78b3985e4b2f15397fec357f0fd808de with: name: site path: site.tar.gz deploy: runs-on: ubuntu-latest needs: build # Publishing guard. This job spends CLOUDFLARE_API_TOKEN and creates a # real Cloudflare Pages deployment, so it must never run off main -- # not even if a branch is added to the push trigger above, deliberately # or by accident. Costs one line; the build job stays exercisable from # a branch without this job touching anything external. if: github.ref_name == 'main' container: # node 20.20.2-bookworm, 2026-08-09 image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5 steps: # Must match the upload-artifact major above -- v4 artifacts and # v3 artifacts are different protocols and do not interoperate. - name: Download artifact # actions/download-artifact v3.1.0-node20, 2026-08-09 uses: actions/download-artifact@ad191675b41f6a5b46da9a048cb6893812da158b with: name: site - name: Extract site run: tar -xzf site.tar.gz - name: Install Wrangler # wrangler 4.120.0, 2026-08-09 run: npm install -g wrangler@4.120.0 - name: Deploy to Cloudflare Pages run: wrangler pages deploy public --project-name=lora-vegas --branch=${{ github.ref_name }} env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}