Skip to content

Commit 950ce94

Browse files
committed
fix: verify production deployments and runtime health
1 parent eab7add commit 950ce94

9 files changed

Lines changed: 502 additions & 181 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 19 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,21 @@ jobs:
6767
cancel-in-progress: false
6868

6969
steps:
70+
- name: Check deployment credentials
71+
env:
72+
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
73+
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
74+
run: |
75+
set -euo pipefail
76+
missing=0
77+
for name in CLOUDFLARE_API_TOKEN CLOUDFLARE_ACCOUNT_ID; do
78+
if [ -z "${!name}" ]; then
79+
echo "::error::Missing Actions secret ${name} in $GITHUB_REPOSITORY. See CLOUDFLARE.md; production was not deployed."
80+
missing=1
81+
fi
82+
done
83+
exit "$missing"
84+
7085
- name: Checkout
7186
uses: actions/checkout@v4
7287

@@ -81,37 +96,11 @@ jobs:
8196
name: dist
8297
path: dist
8398

84-
# public/_redirects sends the apex root to the company site, which is
85-
# a different Pages project. Deploying that redirect before the
86-
# target hostname exists would point the bare domain at nothing —
87-
# and since the deploy lands before the verification below runs, a
88-
# failed check would not undo it. So refuse up front instead.
89-
- name: Confirm the redirect target exists
90-
run: |
91-
set -euo pipefail
92-
status="$(curl -sS -o /dev/null -w '%{http_code}' --max-time 10 "$COMPANY_SITE_URL" || true)"
93-
if [ "${status:-000}" != "200" ]; then
94-
echo "::error::${COMPANY_SITE_URL} answered ${status:-000}. public/_redirects points the apex root there, so it has to be live before this deploys. Attach the hostname to the company site's Pages project first."
95-
exit 1
96-
fi
97-
echo "ok: ${COMPANY_SITE_URL}"
98-
env:
99-
COMPANY_SITE_URL: https://www.avishaikofun.com/
99+
- name: Install deployment dependencies
100+
run: bun install --frozen-lockfile
100101

101-
- name: Deploy to Cloudflare Pages
102-
run: bunx wrangler pages deploy dist --project-name=avishai-kofun --branch=main
102+
- name: Deploy and verify Cloudflare Pages
103+
run: bun run deploy:cloudflare:artifact
103104
env:
104105
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
105106
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
106-
107-
# A deploy can report success while the host still serves the previous
108-
# build, and that silent case is the whole reason this job exists, so
109-
# confirm the version is actually live before calling the deploy done.
110-
# The propagation is not instant, hence the attempts.
111-
- name: Confirm the host serves this build
112-
run: |
113-
set -euo pipefail
114-
version="$(bun scripts/manifest-version.js dist/manifest.xml)"
115-
bun scripts/heartbeat.js --attempts=10 --expect-version="$version"
116-
env:
117-
ADDIN_HOST_URL: https://avishaikofun.com

‎CLOUDFLARE.md‎

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,9 @@ repo の **Settings** → **Secrets and variables** → **Actions** に登録し
2121
- `CLOUDFLARE_API_TOKEN`: **Cloudflare Pages — Edit** 権限を持つ API token
2222
- `CLOUDFLARE_ACCOUNT_ID`: Cloudflare account ID
2323

24-
この2つが無いと `deploy` job は失敗します。
24+
この2つが無いと `deploy` job は最初のステップで不足している secret 名を表示して失敗します。チェックやビルドの成功だけでは、本番への反映は確認できません。
25+
26+
2026-09-23 の調査では `CLOUDFLARE_ACCOUNT_ID` のみが登録されており、API token 不足で自動デプロイが停止していました。手元の `wrangler login` による OAuth 認証は GitHub Actions には引き継がれません。CI 用には上記の API token を登録してください。token の値をログやチャットに貼り付ける必要はありません。
2527

2628
### dashboard の Git 連携は使わない
2729

@@ -35,6 +37,10 @@ CI を経由せず手元から上げる場合のみ使います。
3537
bun run deploy:cloudflare
3638
```
3739

40+
手動・CI ともに `scripts/deploy-cloudflare.js` を使い、www の応答を確認してから `main` の本番環境に公開し、公開後に manifest のバージョンと各 URL を検証します。Wrangler は `package.json` と `bun.lock` に固定したバージョンを使います。
41+
42+
検証済みの `dist/` をそのまま公開する場合は `bun run deploy:cloudflare:artifact` を使います。GitHub Actions もこのコマンドでビルド済み artifact を公開します。
43+
3844
## Environment variables
3945

4046
必要に応じて Cloudflare Pages の build variables に設定します。
@@ -54,8 +60,7 @@ bun run deploy:cloudflare
5460
サイトは [hjosugi/avishaikofun-site](https://github.com/hjosugi/avishaikofun-site)
5561
に分離し、別の Pages project(`avishaikofun-site`)から www で配信します。
5662

57-
**順序に注意。** 2026-07-28 時点で `www.avishaikofun.com` は DNS に存在
58-
しません(apex のみ)。apex の `/` は www へ 308 するので、**www を先に
63+
**順序に注意。** apex の `/` は www へ 308 するので、**www を先に
5964
用意しないと、素のドメインが解決しないホストへの行き止まりになります。**
6065

6166
1. 新しい Pages project `avishaikofun-site` に `www.avishaikofun.com` を
@@ -84,3 +89,5 @@ curl -I https://avishaikofun.com/
8489
curl -I https://avishaikofun.com/manifest.xml
8590
bun run heartbeat
8691
```
92+
93+
監視は設定画面と実行用 JavaScript も確認します。JavaScript の URL が HTML の代替ページを返す場合や、www が 404・500 を返す場合も失敗として検出します。

0 commit comments

Comments
 (0)