From 01992ca46e697598512438d6118150e7644812ce Mon Sep 17 00:00:00 2001 From: CodeDotJS Date: Sun, 4 Oct 2026 09:43:15 +0530 Subject: [PATCH 1/2] docs(deploy): require a branch and a pull request --- .cursor/rules/00-product.mdc | 2 +- .cursor/rules/60-deployment.mdc | 28 +++++++++++++++++----------- AGENTS.md | 2 +- docs/DEPLOYMENT.md | 14 ++++++++++++-- 4 files changed, 31 insertions(+), 15 deletions(-) diff --git a/.cursor/rules/00-product.mdc b/.cursor/rules/00-product.mdc index a4af2e0..2a7c644 100644 --- a/.cursor/rules/00-product.mdc +++ b/.cursor/rules/00-product.mdc @@ -19,6 +19,6 @@ Follow `docs/DMRC_API.md` for upstream calls. Follow `docs/DECISIONS.md` for def Files that stay on this machine and out of git are listed in the local-files rule. Do not delete them, and do not add them to a commit. -Do not deploy until the user approves it. Follow the deployment rule and `docs/DEPLOYMENT.md`. +Ship through a branch and a pull request. Follow the deployment rule. Do not push straight to `main`. Commits use `type(scope): description`. `type` is `feat`, `fix`, `docs`, `test`, `refactor`, or `chore`. `scope` is the area that changed, such as `plan`, `map`, `city`, `offline`, `deploy`, `data`, or `docs`. The description is the change itself, in lowercase, with no period. One commit is one change. Do not use a label that does not name the work. diff --git a/.cursor/rules/60-deployment.mdc b/.cursor/rules/60-deployment.mdc index 89ab164..db0476f 100644 --- a/.cursor/rules/60-deployment.mdc +++ b/.cursor/rules/60-deployment.mdc @@ -1,20 +1,26 @@ --- -description: When and how to deploy DETRO. Do not deploy until the user approves. +description: Branch, preview, and production deploy for DETRO alwaysApply: true --- # Deployment -Do not create the Cloudflare project, do not add the workflow, do not set secrets, and do not upload a build until the user explicitly approves a deploy. +Every change goes through a branch and a pull request. Do not commit or push directly to `main`. -When they approve, follow `docs/DEPLOYMENT.md` from the top and stop at the first failed check. Report the check and the URL. Do not continue past a failure. +1. Branch from `main`. +2. Commit on that branch. `type(scope): description`. One commit is one change. +3. Push the branch and open a pull request in this repository. +4. Wait for `CI / check`. It runs `npm ci`, `npm test`, and `npm run build`, rejects `dist` above 20,000 files or any file over 25 MiB, then uploads a preview. `npm run smoke` is not in the job. +5. Open the preview at `https://.detro.pages.dev`. A slash in the branch name becomes a hyphen. Confirm `/`, `/map`, `/city`, and `/help` load. If the check fails, stop and report the check and the URL. +6. Merge into `main` only after that check is green. Branch protection requires `CI / check`. +7. The merge publishes production at `https://detro.pages.dev`. -The Pages project `detro` already exists and is Direct Upload. Do not create a second project and do not connect it to Git. +The Pages project `detro` already exists and is Direct Upload. Do not create a second project, do not connect Pages to Git, and do not upload with Wrangler from this machine. -- Production is Cloudflare Pages only. Project name `detro`. Public URL `https://detro.pages.dev`. -- GitHub Actions runs `npm ci`, `npm test`, and `npm run build`, then Wrangler uploads `dist`. Pages does not also build from Git. -- A pull request from this repository uploads a preview. A push to `main` uploads production. `npm run smoke` is not part of the job. -- Fail the job if `dist` has more than 20,000 files or any file over 25 MiB. -- Do not deploy `data/en/routes/`, `data/en/fares/`, `data/en/first-last/`, `data/hi/`, `scripts/`, `detro.archives/`, `curls/`, or `prompt.md`. -- No Vercel project, Pages Functions, Workers, R2, KV, D1, analytics, or a paid add-on. -- `CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID` are GitHub Actions secrets. Never commit them or print them. +Production is Cloudflare Pages only. No Vercel project, Pages Functions, Workers, R2, KV, D1, analytics, or a paid add-on. + +Do not deploy `data/en/routes/`, `data/en/fares/`, `data/en/first-last/`, `data/hi/`, `scripts/`, `detro.archives/`, `curls/`, or `prompt.md`. + +`CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID` are GitHub Actions secrets. Never commit them or print them. + +The first-time setup is already done. It is recorded in `docs/DEPLOYMENT.md`. Do not repeat it. diff --git a/AGENTS.md b/AGENTS.md index f017a6e..5279f2a 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -38,7 +38,7 @@ Routes are calculated from station order. A packed journey supplies the fare, pl - Do not add a Hindi language control. Hindi strings in `src/i18n/copy.ts` exist so the types compile. - Do not load fonts from a CDN. Vendored font files are allowed. - Do not claim live arrivals, live lifts, or official affiliation. -- Do not deploy, and do not add analytics, ads, or a paid service, until the user approves it. Follow `docs/DEPLOYMENT.md`. +- Ship through a branch and a pull request. Follow `docs/DEPLOYMENT.md`. Do not push straight to `main`. Do not add analytics, ads, or a paid service. ## Local files diff --git a/docs/DEPLOYMENT.md b/docs/DEPLOYMENT.md index 051c95a..0598bc9 100644 --- a/docs/DEPLOYMENT.md +++ b/docs/DEPLOYMENT.md @@ -4,7 +4,17 @@ Checked 2026-10-04. The app is a static site. It does not need a server, a datab Production is live at `https://detro.pages.dev`. The Pages project `detro` is Direct Upload, and it is not connected to Git. The first upload was the local `dist` built from `94e3b40`. -GitHub Actions runs `.github/workflows/ci.yml`. The job uses `CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID`. Do not print the token and do not commit it. A push to `main` publishes production. A pull request from this repository publishes a preview. Do not connect Pages to Git. +Every later change uses a branch and a pull request. Do not commit or push directly to `main`. + +1. Branch from `main` and commit there. +2. Open a pull request. `CI / check` tests the build, enforces the file limits, and uploads a preview at `https://.detro.pages.dev`. A slash in the branch name becomes a hyphen. +3. Confirm `/`, `/map`, `/city`, and `/help` on that preview. +4. Merge only after `CI / check` is green. Branch protection requires that check. +5. The merge publishes production at `https://detro.pages.dev`. + +Do not upload with Wrangler from a laptop, and do not connect Pages to Git. The secrets `CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID` stay in GitHub. Do not print the token and do not commit it. + +The numbered procedure below is the first-time setup. It is already done. Do not repeat it. ## Procedure @@ -76,7 +86,7 @@ jobs: gitHubToken: ${{ secrets.GITHUB_TOKEN }} ``` -A push to `main` publishes production. Any other branch from this repository publishes a preview at `https://.detro.pages.dev`. A pull request from a fork does not receive the secrets, so the deploy step must not run for it. `npm run smoke` is not in this job. +A push to `main` publishes production. A pull request from this repository publishes a preview at `https://.detro.pages.dev`. A slash in the branch name becomes a hyphen. A pull request from a fork does not receive the secrets, so the deploy step must not run for it. `npm run smoke` is not in this job. Production traffic goes to Cloudflare Pages. Pages does not meter static bandwidth and does not bill overage. GitHub Actions runs the tests and uploads the built site. Vercel is not part of this pipeline. From 582dc2ccb8408fd65aa9af7fb2d818e7c46a9f92 Mon Sep 17 00:00:00 2001 From: CodeDotJS Date: Sun, 4 Oct 2026 09:45:02 +0530 Subject: [PATCH 2/2] docs(deploy): name the required job check --- .cursor/rules/60-deployment.mdc | 4 ++-- docs/DEPLOYMENT.md | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.cursor/rules/60-deployment.mdc b/.cursor/rules/60-deployment.mdc index db0476f..49e0362 100644 --- a/.cursor/rules/60-deployment.mdc +++ b/.cursor/rules/60-deployment.mdc @@ -10,9 +10,9 @@ Every change goes through a branch and a pull request. Do not commit or push dir 1. Branch from `main`. 2. Commit on that branch. `type(scope): description`. One commit is one change. 3. Push the branch and open a pull request in this repository. -4. Wait for `CI / check`. It runs `npm ci`, `npm test`, and `npm run build`, rejects `dist` above 20,000 files or any file over 25 MiB, then uploads a preview. `npm run smoke` is not in the job. +4. Wait for the `check` job in the CI workflow. It runs `npm ci`, `npm test`, and `npm run build`, rejects `dist` above 20,000 files or any file over 25 MiB, then uploads a preview. `npm run smoke` is not in the job. 5. Open the preview at `https://.detro.pages.dev`. A slash in the branch name becomes a hyphen. Confirm `/`, `/map`, `/city`, and `/help` load. If the check fails, stop and report the check and the URL. -6. Merge into `main` only after that check is green. Branch protection requires `CI / check`. +6. Merge into `main` only after that job is green. Branch protection requires the `check` job. 7. The merge publishes production at `https://detro.pages.dev`. The Pages project `detro` already exists and is Direct Upload. Do not create a second project, do not connect Pages to Git, and do not upload with Wrangler from this machine. diff --git a/docs/DEPLOYMENT.md b/docs/DEPLOYMENT.md index 0598bc9..d98b8c8 100644 --- a/docs/DEPLOYMENT.md +++ b/docs/DEPLOYMENT.md @@ -7,9 +7,9 @@ Production is live at `https://detro.pages.dev`. The Pages project `detro` is Di Every later change uses a branch and a pull request. Do not commit or push directly to `main`. 1. Branch from `main` and commit there. -2. Open a pull request. `CI / check` tests the build, enforces the file limits, and uploads a preview at `https://.detro.pages.dev`. A slash in the branch name becomes a hyphen. +2. Open a pull request. The `check` job in the CI workflow tests the build, enforces the file limits, and uploads a preview at `https://.detro.pages.dev`. A slash in the branch name becomes a hyphen. 3. Confirm `/`, `/map`, `/city`, and `/help` on that preview. -4. Merge only after `CI / check` is green. Branch protection requires that check. +4. Merge only after the `check` job is green. Branch protection requires that job. 5. The merge publishes production at `https://detro.pages.dev`. Do not upload with Wrangler from a laptop, and do not connect Pages to Git. The secrets `CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID` stay in GitHub. Do not print the token and do not commit it.