ci: deploy the site via cloudflare workers builds

Replaces the GitHub Actions deploy lane with Cloudflare Workers Builds,
configured in the Cloudflare dashboard and wired to GitHub by the
Cloudflare Workers & Pages app.

- delete .github/workflows/web-deploy.yml
- drop both wrangler envs: one worker, and the branch picks the command
  (deploy on main, versions upload everywhere else, so a preview URL is a
  version of the same worker rather than a second one)
- collapse web:deploy:preview into web:deploy, now the manual override
- document the lane in CONTRIBUTING.md, since a reader will otherwise go
  looking for the workflow file that is no longer there

The CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID secrets are no longer
needed; Workers Builds mints its own token for the build. Watch paths now
include packages/editor-tokens, which site-tokens depends on and the old
workflow's filter missed.
This commit is contained in:
Nayan
2026-08-11 04:12:58 +05:30
parent c9cf6761cc
commit d970ee8bd5
4 changed files with 25 additions and 69 deletions
-48
View File
@@ -1,48 +0,0 @@
name: Deploy site
run-name: "Deploy site · ${{ github.event_name == 'pull_request' && 'preview' || 'production' }}"
# Ships apps/web to Cloudflare Workers. Production on a push to main, and a
# preview environment for PRs that touch the site.
#
# Path-filtered rather than running on everything: the site depends on
# @airship/site-tokens, so a token change has to redeploy too.
on:
push:
branches: [main]
paths:
- "apps/web/**"
- "packages/site-tokens/**"
- ".github/workflows/web-deploy.yml"
pull_request:
branches: [main]
paths:
- "apps/web/**"
- "packages/site-tokens/**"
workflow_dispatch:
concurrency:
# Not cancel-in-progress: a half-finished deploy is worse than a redundant one.
group: web-deploy-${{ github.event_name == 'pull_request' && github.ref || 'production' }}
cancel-in-progress: false
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-workspace
# Through turbo so @airship/site-tokens#build runs first — Vite has no
# dist/tokens.css to import without it.
- name: Build
run: pnpm turbo run build --filter=@airship/web
- uses: cloudflare/wrangler-action@v3
with:
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
workingDirectory: apps/web
command: >-
deploy --env ${{ github.event_name == 'pull_request' && 'preview' || 'production' }}
+11 -1
View File
@@ -288,7 +288,17 @@ Every PR into `main` runs:
release lane legible, and what makes `dependabot/*` an explicit exception rather than an
accident.
`web-deploy.yml` deploys `apps/web` to Cloudflare Workers.
**The site's deploy is not in this repo.** `apps/web` ships through Cloudflare Workers Builds,
configured in the Cloudflare dashboard and wired to GitHub by the *Cloudflare Workers & Pages*
GitHub App — so there is no `web-deploy.yml` to find, and no `CLOUDFLARE_*` secret on the repo.
A push to `main` touching `apps/web/`, `packages/site-tokens/` or `packages/editor-tokens/`
runs `pnpm -w run build:web` and then `wrangler deploy`, updating the `airship-web` worker. Any
other branch runs `wrangler versions upload` instead, which publishes a *version* rather than
promoting it: the app posts that version's preview URL onto the PR, and production is untouched
until the merge. Build logs live in the dashboard, not in the Actions tab.
This is why `apps/web/wrangler.jsonc` declares no `env` block — one worker, and the branch
decides the command. `make web:deploy` remains as a manual override that authenticates as you.
## Releases
+8 -7
View File
@@ -183,7 +183,7 @@ preflight\:fix: ## preflight, but autofix first (ultracite fix + regenerate rout
##@ Site (apps/web)
.PHONY: web\:dev web\:build web\:preview web\:tokens web\:og web\:routes
.PHONY: web\:deploy web\:deploy\:preview
.PHONY: web\:deploy
web\:dev: ## Start apps/web's dev server (see TARGET below)
# Through turbo, not `pnpm --filter … dev`: @airship/web#dev depends on
@@ -214,17 +214,18 @@ web\:routes: ## Scaffold apps/web's route tree after adding a route (build is au
# a new route mid-edit, but build before you commit.
@pnpm --filter @airship/web routes
web\:deploy: ## Deploy apps/web to Cloudflare Workers (production)
web\:deploy: ## Deploy apps/web to Cloudflare Workers (break-glass; CI normally does this)
# Cloudflare Workers Builds deploys the site on every push to main, so this
# target is the manual override — a hotfix when the build lane is down or a
# first deploy before the repo is connected. It authenticates as *you*
# (`wrangler login`), not as CI, and there is only one worker to hit: no
# --env, because wrangler.jsonc no longer declares any.
$(confirm_shared)
@printf "$(BLUE)Deploying apps/web to Cloudflare...$(RESET)\n"
@$(MAKE) "web:build"
@pnpm --filter @airship/web exec wrangler deploy --env production
@pnpm --filter @airship/web exec wrangler deploy
@printf "$(GREEN)Deployed!$(RESET)\n"
web\:deploy\:preview: ## Deploy apps/web to the Cloudflare preview environment
@$(MAKE) "web:build"
@pnpm --filter @airship/web exec wrangler deploy --env preview
##@ Overlay (storybook)
.PHONY: storybook storybook\:build
+6 -13
View File
@@ -17,18 +17,11 @@
},
"observability": {
"enabled": true
},
// Both lanes name their target explicitly. Production could ride the
// top-level config instead, but once any env exists wrangler warns on an
// unqualified deploy — and `--env=""` is an awkward thing to thread through a
// GitHub Action's command string. Two named envs keeps both calls symmetric.
// main, compatibility_*, and assets are inherited from above.
"env": {
"production": {
"name": "airship-web"
},
"preview": {
"name": "airship-web-preview"
}
}
// No `env` block, deliberately. Cloudflare Workers Builds deploys this repo
// (see CONTRIBUTING.md § CI), and it runs a bare `wrangler deploy` on main and
// `wrangler versions upload` on every other branch — the preview URL comes from
// a version of this same worker, not a second one. Adding a named env would
// reintroduce the warning on unqualified deploys that the flag-less default
// relies on not hitting.
}