diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..c192f9f --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,51 @@ +name: CI + +on: + push: + branches: [main] + pull_request: + +jobs: + check: + runs-on: ubuntu-latest + permissions: + contents: read + deployments: write + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 22 + cache: npm + - run: npm ci + - run: npm test + - run: npm run build + - name: Pages file limits + run: | + node --input-type=module -e " + import { readdirSync, statSync } from 'node:fs' + import { join } from 'node:path' + const files = [] + const walk = (dir) => { + for (const name of readdirSync(dir)) { + const path = join(dir, name) + if (statSync(path).isDirectory()) walk(path) + else files.push(path) + } + } + walk('dist') + const limit = 25 * 1024 * 1024 + const tooBig = files.filter((file) => statSync(file).size > limit) + if (files.length > 20000 || tooBig.length > 0) { + console.error({ files: files.length, tooBig }) + process.exit(1) + } + " + - name: Deploy + if: github.event_name == 'push' || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository) + uses: cloudflare/wrangler-action@v4 + with: + apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }} + accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} + command: pages deploy dist --project-name=detro --branch=${{ github.head_ref || github.ref_name }} + gitHubToken: ${{ secrets.GITHUB_TOKEN }} diff --git a/docs/DEPLOYMENT.md b/docs/DEPLOYMENT.md index 5d791a0..051c95a 100644 --- a/docs/DEPLOYMENT.md +++ b/docs/DEPLOYMENT.md @@ -4,7 +4,7 @@ Checked 2026-10-04. The app is a static site. It does not need a server, a datab Production is live at `https://detro.pages.dev`. The Pages project `detro` is Direct Upload, and it is not connected to Git. The first upload was the local `dist` built from `94e3b40`. -The GitHub Actions upload is the next step. It waits on two secrets: `CLOUDFLARE_API_TOKEN` (permission to edit this Pages project only) and `CLOUDFLARE_ACCOUNT_ID`. Do not print the token and do not commit it. After those secrets exist, add `.github/workflows/ci.yml` as written below and require that check on `main`. Do not connect Pages to Git to get around a missing token. +GitHub Actions runs `.github/workflows/ci.yml`. The job uses `CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID`. Do not print the token and do not commit it. A push to `main` publishes production. A pull request from this repository publishes a preview. Do not connect Pages to Git. ## Procedure @@ -72,7 +72,7 @@ jobs: with: apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }} accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} - command: pages deploy dist --project-name=detro + command: pages deploy dist --project-name=detro --branch=${{ github.head_ref || github.ref_name }} gitHubToken: ${{ secrets.GITHUB_TOKEN }} ```