From d970ee8bd5230f23ab90b610f0de0cda2594d835 Mon Sep 17 00:00:00 2001 From: Nayan Date: Tue, 11 Aug 2026 04:12:58 +0530 Subject: [PATCH] ci: deploy the site via cloudflare workers builds Replaces the GitHub Actions deploy lane with Cloudflare Workers Builds, configured in the Cloudflare dashboard and wired to GitHub by the Cloudflare Workers & Pages app. - delete .github/workflows/web-deploy.yml - drop both wrangler envs: one worker, and the branch picks the command (deploy on main, versions upload everywhere else, so a preview URL is a version of the same worker rather than a second one) - collapse web:deploy:preview into web:deploy, now the manual override - document the lane in CONTRIBUTING.md, since a reader will otherwise go looking for the workflow file that is no longer there The CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID secrets are no longer needed; Workers Builds mints its own token for the build. Watch paths now include packages/editor-tokens, which site-tokens depends on and the old workflow's filter missed. --- .github/workflows/web-deploy.yml | 48 -------------------------------- CONTRIBUTING.md | 12 +++++++- Makefile | 15 +++++----- apps/web/wrangler.jsonc | 19 ++++--------- 4 files changed, 25 insertions(+), 69 deletions(-) delete mode 100644 .github/workflows/web-deploy.yml diff --git a/.github/workflows/web-deploy.yml b/.github/workflows/web-deploy.yml deleted file mode 100644 index 2bfcb12..0000000 --- a/.github/workflows/web-deploy.yml +++ /dev/null @@ -1,48 +0,0 @@ -name: Deploy site - -run-name: "Deploy site · ${{ github.event_name == 'pull_request' && 'preview' || 'production' }}" - -# Ships apps/web to Cloudflare Workers. Production on a push to main, and a -# preview environment for PRs that touch the site. -# -# Path-filtered rather than running on everything: the site depends on -# @airship/site-tokens, so a token change has to redeploy too. -on: - push: - branches: [main] - paths: - - "apps/web/**" - - "packages/site-tokens/**" - - ".github/workflows/web-deploy.yml" - pull_request: - branches: [main] - paths: - - "apps/web/**" - - "packages/site-tokens/**" - workflow_dispatch: - -concurrency: - # Not cancel-in-progress: a half-finished deploy is worse than a redundant one. - group: web-deploy-${{ github.event_name == 'pull_request' && github.ref || 'production' }} - cancel-in-progress: false - -jobs: - deploy: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - - - uses: ./.github/actions/setup-workspace - - # Through turbo so @airship/site-tokens#build runs first — Vite has no - # dist/tokens.css to import without it. - - name: Build - run: pnpm turbo run build --filter=@airship/web - - - uses: cloudflare/wrangler-action@v3 - with: - apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }} - accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} - workingDirectory: apps/web - command: >- - deploy --env ${{ github.event_name == 'pull_request' && 'preview' || 'production' }} diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index ce18e40..e1e0337 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -288,7 +288,17 @@ Every PR into `main` runs: release lane legible, and what makes `dependabot/*` an explicit exception rather than an accident. -`web-deploy.yml` deploys `apps/web` to Cloudflare Workers. +**The site's deploy is not in this repo.** `apps/web` ships through Cloudflare Workers Builds, +configured in the Cloudflare dashboard and wired to GitHub by the *Cloudflare Workers & Pages* +GitHub App — so there is no `web-deploy.yml` to find, and no `CLOUDFLARE_*` secret on the repo. +A push to `main` touching `apps/web/`, `packages/site-tokens/` or `packages/editor-tokens/` +runs `pnpm -w run build:web` and then `wrangler deploy`, updating the `airship-web` worker. Any +other branch runs `wrangler versions upload` instead, which publishes a *version* rather than +promoting it: the app posts that version's preview URL onto the PR, and production is untouched +until the merge. Build logs live in the dashboard, not in the Actions tab. + +This is why `apps/web/wrangler.jsonc` declares no `env` block — one worker, and the branch +decides the command. `make web:deploy` remains as a manual override that authenticates as you. ## Releases diff --git a/Makefile b/Makefile index a73c5b3..12a43aa 100644 --- a/Makefile +++ b/Makefile @@ -183,7 +183,7 @@ preflight\:fix: ## preflight, but autofix first (ultracite fix + regenerate rout ##@ Site (apps/web) .PHONY: web\:dev web\:build web\:preview web\:tokens web\:og web\:routes -.PHONY: web\:deploy web\:deploy\:preview +.PHONY: web\:deploy web\:dev: ## Start apps/web's dev server (see TARGET below) # Through turbo, not `pnpm --filter … dev`: @airship/web#dev depends on @@ -214,17 +214,18 @@ web\:routes: ## Scaffold apps/web's route tree after adding a route (build is au # a new route mid-edit, but build before you commit. @pnpm --filter @airship/web routes -web\:deploy: ## Deploy apps/web to Cloudflare Workers (production) +web\:deploy: ## Deploy apps/web to Cloudflare Workers (break-glass; CI normally does this) + # Cloudflare Workers Builds deploys the site on every push to main, so this + # target is the manual override — a hotfix when the build lane is down or a + # first deploy before the repo is connected. It authenticates as *you* + # (`wrangler login`), not as CI, and there is only one worker to hit: no + # --env, because wrangler.jsonc no longer declares any. $(confirm_shared) @printf "$(BLUE)Deploying apps/web to Cloudflare...$(RESET)\n" @$(MAKE) "web:build" - @pnpm --filter @airship/web exec wrangler deploy --env production + @pnpm --filter @airship/web exec wrangler deploy @printf "$(GREEN)Deployed!$(RESET)\n" -web\:deploy\:preview: ## Deploy apps/web to the Cloudflare preview environment - @$(MAKE) "web:build" - @pnpm --filter @airship/web exec wrangler deploy --env preview - ##@ Overlay (storybook) .PHONY: storybook storybook\:build diff --git a/apps/web/wrangler.jsonc b/apps/web/wrangler.jsonc index a999904..5bd0b9a 100644 --- a/apps/web/wrangler.jsonc +++ b/apps/web/wrangler.jsonc @@ -17,18 +17,11 @@ }, "observability": { "enabled": true - }, - // Both lanes name their target explicitly. Production could ride the - // top-level config instead, but once any env exists wrangler warns on an - // unqualified deploy — and `--env=""` is an awkward thing to thread through a - // GitHub Action's command string. Two named envs keeps both calls symmetric. - // main, compatibility_*, and assets are inherited from above. - "env": { - "production": { - "name": "airship-web" - }, - "preview": { - "name": "airship-web-preview" - } } + // No `env` block, deliberately. Cloudflare Workers Builds deploys this repo + // (see CONTRIBUTING.md § CI), and it runs a bare `wrangler deploy` on main and + // `wrangler versions upload` on every other branch — the preview URL comes from + // a version of this same worker, not a second one. Adding a named env would + // reintroduce the warning on unqualified deploys that the flag-less default + // relies on not hitting. }