Files
lora.vegas/.gitea/workflows/probe.yml
sneak 07af755d1e
Some checks failed
check / check (push) Successful in 8s
Build and Deploy to Cloudflare Pages / build (push) Successful in 8s
probe / r1-wrangler-only (push) Failing after 7s
probe / r2a-upload-proven (push) Successful in 12s
probe / r3a-upload-node20 (push) Successful in 8s
Build and Deploy to Cloudflare Pages / deploy (push) Has been skipped
probe / r2b-download-proven (push) Successful in 2s
probe / r3b-download-node20 (push) Successful in 2s
Move the artifact pair to the exact commits @v3 was resolving to
Round 2 (602fd60) put the build job green:

    check / check                        success   6s
    Build and Deploy .../ build          success  20s   <- green
    Build and Deploy .../ deploy         skipped        <- if: guard
    probe / q1-upload-v3-node16          success   7s
    probe / q2-upload-v3-node20          success  22s
    probe / q3-build-for-roundtrip       success  11s
    probe / q4-deploy-dryrun             failure  43s

Every v3 upload works and the build job is fixed. But q4 -- the deploy-side
rehearsal, which downloads the artifact in the pinned node container and
installs the pinned wrangler, stopping short of the publish call -- failed.
That is a break the deploy job would have hit on main, in a job nobody has
ever been able to run.

q4 bundled two things together, so round 3 splits them:

- r1 runs only the wrangler install and invocation. Worth measuring rather
  than assuming: wrangler 4.120.0 declares engines.node >= 22 and the deploy
  container is node 20, though the pre-issue deploy did run an unpinned
  wrangler on node:20 successfully.
- r2a/r2b run the artifact round trip with no wrangler at all.
- r3a/r3b do the same for the newer node20 artifact builds, so the choice
  between the two pairs is made on measurement.

deploy.yml meanwhile moves to the artifact commits that the mutable `@v3`
references were actually resolving to while this site was deploying, rather
than to the newest thing on the v3 line:

- upload-artifact   -> ff15f030 (v3.2.1)
- download-artifact -> 9bc31d5c (v3.0.2)

That is the conservative reading of what this issue is for: pin what is known
to work, do not take a version bump for free on the way past.
2026-08-09 02:55:51 +00:00

130 lines
5.3 KiB
YAML

# TEMPORARY diagnostic workflow. Deleted before this branch is merged.
#
# The Actions jobs/logs API is not readable by this account, so the only
# available signal is the commit-status API, which reports one entry per
# *job*. This file therefore encodes the diagnosis as job topology: each job
# isolates one hypothesis and surfaces as its own status context.
#
# Round 1 (2d328e7):
#
# p1 bare alpine + checkout failure 3s
# p2 alpine + apk nodejs git tar + checkout success 5s
# p3 p2 + script/bootstrap + script/test + tar success 15s
# p4 p2 + upload-artifact v4 failure 11s
# p5 node:20-alpine + checkout success 8s
# p6 node:20-bookworm-slim + checkout success 11s
#
# -> the pinned alpine image, the prerequisite step and the site build are all
# fine; upload-artifact v4 is what broke the deploy.
#
# Round 2 (602fd60):
#
# build (deploy.yml, upload v3.2.2-node20) success 20s
# q1 upload-artifact v3.2.1 (node16) success 7s
# q2 upload-artifact v3.2.1-n20 (node20) success 22s
# q3 full build + upload v3.2.2-node20 success 11s
# q4 download v3.1.0-node20 + wrangler install failure 43s
#
# -> build is green, every v3 upload works, and the remaining failure is
# somewhere in the deploy-side rehearsal. Round 3 splits q4 into its parts:
# wrangler on its own, the artifact pair that was actually deploying this
# site before this issue, and the newer node20 artifact pair.
name: probe
on:
push:
branches:
- pin-deploy-refs-observable
jobs:
# Isolates the wrangler install and invocation from anything to do with
# artifacts. wrangler 4.120.0 declares engines.node >= 22 while the deploy
# container is node 20, so this needs measuring rather than assuming --
# the pre-issue deploy did run an unpinned wrangler on node:20
# successfully.
r1-wrangler-only:
runs-on: ubuntu-latest
container:
# node 20.20.2-bookworm, 2026-08-09
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
steps:
# wrangler 4.120.0, 2026-08-09
- run: npm install -g wrangler@4.120.0
- run: wrangler --version
# Producer for the pair that `@v3`/`@v3` resolved to before this issue,
# i.e. the code that was actually deploying the site, now pinned.
r2a-upload-proven:
runs-on: ubuntu-latest
container:
# alpine 3.21, 2026-02-28
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
defaults:
run:
shell: sh
steps:
- run: apk add --no-cache nodejs git tar
# actions/checkout v4.2.2, 2026-02-28
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
submodules: recursive
- run: script/bootstrap
- run: script/test
- run: tar -czf site.tar.gz public
# actions/upload-artifact v3.2.1, 2026-08-09
- uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5
with:
name: site-proven
path: site.tar.gz
# Consumer half: the deploy job's artifact handling, with no wrangler, so
# a failure here means the artifact round trip and a pass here means it is
# sound.
r2b-download-proven:
runs-on: ubuntu-latest
needs: r2a-upload-proven
container:
# node 20.20.2-bookworm, 2026-08-09
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
steps:
# actions/download-artifact v3.0.2, 2026-08-09
- uses: actions/download-artifact@9bc31d5ccc31df68ecc42ccf4149144866c47d8a
with:
name: site-proven
- run: tar -xzf site.tar.gz
- run: test -f public/index.html
# The newer node20 artifact pair, kept in the round so the choice between
# the two pairs rests on measurement rather than preference.
r3a-upload-node20:
runs-on: ubuntu-latest
container:
# alpine 3.21, 2026-02-28
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
defaults:
run:
shell: sh
steps:
- run: apk add --no-cache nodejs git tar
# actions/checkout v4.2.2, 2026-02-28
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
- run: tar -czf alt.tar.gz hugo.toml
# actions/upload-artifact v3.2.2-node20, 2026-08-09
- uses: actions/upload-artifact@c6a3b2bd78b3985e4b2f15397fec357f0fd808de
with:
name: alt-node20
path: alt.tar.gz
r3b-download-node20:
runs-on: ubuntu-latest
needs: r3a-upload-node20
container:
# node 20.20.2-bookworm, 2026-08-09
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
steps:
# actions/download-artifact v3.1.0-node20, 2026-08-09
- uses: actions/download-artifact@ad191675b41f6a5b46da9a048cb6893812da158b
with:
name: alt-node20
- run: test -f alt.tar.gz