6767 cancel-in-progress : false
6868
6969 steps :
70+ - name : Check deployment credentials
71+ env :
72+ CLOUDFLARE_API_TOKEN : ${{ secrets.CLOUDFLARE_API_TOKEN }}
73+ CLOUDFLARE_ACCOUNT_ID : ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
74+ run : |
75+ set -euo pipefail
76+ missing=0
77+ for name in CLOUDFLARE_API_TOKEN CLOUDFLARE_ACCOUNT_ID; do
78+ if [ -z "${!name}" ]; then
79+ echo "::error::Missing Actions secret ${name} in $GITHUB_REPOSITORY. See CLOUDFLARE.md; production was not deployed."
80+ missing=1
81+ fi
82+ done
83+ exit "$missing"
84+
7085 - name : Checkout
7186 uses : actions/checkout@v4
7287
@@ -81,37 +96,11 @@ jobs:
8196 name : dist
8297 path : dist
8398
84- # public/_redirects sends the apex root to the company site, which is
85- # a different Pages project. Deploying that redirect before the
86- # target hostname exists would point the bare domain at nothing —
87- # and since the deploy lands before the verification below runs, a
88- # failed check would not undo it. So refuse up front instead.
89- - name : Confirm the redirect target exists
90- run : |
91- set -euo pipefail
92- status="$(curl -sS -o /dev/null -w '%{http_code}' --max-time 10 "$COMPANY_SITE_URL" || true)"
93- if [ "${status:-000}" != "200" ]; then
94- echo "::error::${COMPANY_SITE_URL} answered ${status:-000}. public/_redirects points the apex root there, so it has to be live before this deploys. Attach the hostname to the company site's Pages project first."
95- exit 1
96- fi
97- echo "ok: ${COMPANY_SITE_URL}"
98- env :
99- COMPANY_SITE_URL : https://www.avishaikofun.com/
99+ - name : Install deployment dependencies
100+ run : bun install --frozen-lockfile
100101
101- - name : Deploy to Cloudflare Pages
102- run : bunx wrangler pages deploy dist --project-name=avishai-kofun --branch=main
102+ - name : Deploy and verify Cloudflare Pages
103+ run : bun run deploy:cloudflare:artifact
103104 env :
104105 CLOUDFLARE_API_TOKEN : ${{ secrets.CLOUDFLARE_API_TOKEN }}
105106 CLOUDFLARE_ACCOUNT_ID : ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
106-
107- # A deploy can report success while the host still serves the previous
108- # build, and that silent case is the whole reason this job exists, so
109- # confirm the version is actually live before calling the deploy done.
110- # The propagation is not instant, hence the attempts.
111- - name : Confirm the host serves this build
112- run : |
113- set -euo pipefail
114- version="$(bun scripts/manifest-version.js dist/manifest.xml)"
115- bun scripts/heartbeat.js --attempts=10 --expect-version="$version"
116- env :
117- ADDIN_HOST_URL : https://avishaikofun.com
0 commit comments