diff --git a/.forgejo/workflows/deploy.yml b/.forgejo/workflows/deploy.yml index 6ad3a548..d6f34f38 100644 --- a/.forgejo/workflows/deploy.yml +++ b/.forgejo/workflows/deploy.yml @@ -1,20 +1,25 @@ -name: Build and publish static site +name: Publish static bundles on: push: + branches: [main] workflow_dispatch: concurrency: - group: site-${{ github.ref }} + group: publish-main cancel-in-progress: true jobs: - build: + publish: runs-on: docker container: image: node:24-bookworm timeout-minutes: 30 env: + AWS_ACCESS_KEY_ID: ${{ secrets.GARAGE_SITES_ACCESS_KEY_ID }} + AWS_SECRET_ACCESS_KEY: ${{ secrets.GARAGE_SITES_SECRET_ACCESS_KEY }} + AWS_DEFAULT_REGION: garage-sites + GARAGE_S3_ENDPOINT: https://s3-sites.bcgen.ie NODE_OPTIONS: --max-old-space-size=768 PUBLIC_ANALYTICS_DASHBOARD_URL: ${{ secrets.PUBLIC_ANALYTICS_DASHBOARD_URL }} PUBLIC_CONTACT_FORM_ENDPOINT: ${{ secrets.PUBLIC_CONTACT_FORM_ENDPOINT }} @@ -25,16 +30,19 @@ jobs: steps: - uses: actions/checkout@v4 - - name: Install validation tools + - name: Install build and S3 tools run: | + set -eu apt-get update -qq - apt-get install -y -q python3 - - - name: Install dependencies - run: npm ci --no-audit --no-fund + apt-get install -y -q ca-certificates python3-venv + python3 -m venv /opt/awscli + /opt/awscli/bin/pip install --quiet awscli - name: Build and validate Astro output - run: npm run check + run: | + set -eu + npm ci --no-audit --no-fund + npm run check - name: Split public and protected admin bundles run: | @@ -51,22 +59,7 @@ jobs: cp -a dist/admin/content bundle-admin/admin/content cp dist/css/admin.css bundle-admin/css/admin.css - - name: Install Garage publishing tools - if: github.ref == 'refs/heads/main' - run: | - set -eu - apt-get update -qq - apt-get install -y -q ca-certificates python3-venv - python3 -m venv /opt/awscli - /opt/awscli/bin/pip install --quiet awscli - - - name: Publish main to Garage - if: github.ref == 'refs/heads/main' - env: - AWS_ACCESS_KEY_ID: ${{ secrets.GARAGE_SITES_ACCESS_KEY_ID }} - AWS_SECRET_ACCESS_KEY: ${{ secrets.GARAGE_SITES_SECRET_ACCESS_KEY }} - AWS_DEFAULT_REGION: garage-sites - GARAGE_S3_ENDPOINT: https://s3-sites.bcgen.ie + - name: Publish to Garage run: | set -eu aws=/opt/awscli/bin/aws diff --git a/AGENTS.md b/AGENTS.md index cc02b214..f5199c97 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -24,8 +24,6 @@ migration continues. - Keep the structure simple and close to what the user asks for. - `.forgejo/` and deployment configuration are not special unless the user says they are. -- Feature-branch Actions build and validate only. Production Garage publishing - is restricted to commits on `main`. ## Repo Map diff --git a/README.md b/README.md index d06b59f3..8f6dd6e3 100644 --- a/README.md +++ b/README.md @@ -110,18 +110,13 @@ http://localhost:4321/ ## Deployment -This project deploys as a static Astro build through Forgejo Actions. Every -branch push installs dependencies, builds the complete site, audits its links, -and prepares the separate public and protected-admin bundles. Feature branches -never receive Garage publishing credentials and never change production. - -Only commits on `main` synchronize the validated bundles to `familyfed.ie` and -`admin.familyfed.ie` in Garage. A manual workflow dispatch is subject to the -same branch guard: dispatching a feature branch builds it but cannot publish it. - -The equivalent local validation is: +This project deploys as a static Astro build. A deployment job should install +dependencies, run the build, and publish the generated `dist/` directory: ```bash npm ci -npm run check +npm run build ``` + +Use `npm run start` only when you intentionally want Astro to serve the built +output in an environment such as a local or Nomad preview job.