Standardize Astro validation and Garage publishing #11

Merged
samuel merged 1 commit from codex/standardize-astro-garage into main 2026-07-29 16:46:40 +00:00
3 changed files with 38 additions and 24 deletions
Showing only changes of commit 39b96cd34e - Show all commits

View file

@ -1,25 +1,20 @@
name: Publish static bundles
name: Build and publish static site
on:
push:
branches: [main]
workflow_dispatch:
concurrency:
group: publish-main
group: site-${{ github.ref }}
cancel-in-progress: true
jobs:
publish:
build:
runs-on: docker
container:
image: node:24-bookworm
timeout-minutes: 30
env:
AWS_ACCESS_KEY_ID: ${{ secrets.GARAGE_SITES_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.GARAGE_SITES_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: garage-sites
GARAGE_S3_ENDPOINT: https://s3-sites.bcgen.ie
NODE_OPTIONS: --max-old-space-size=768
PUBLIC_ANALYTICS_DASHBOARD_URL: ${{ secrets.PUBLIC_ANALYTICS_DASHBOARD_URL }}
PUBLIC_CONTACT_FORM_ENDPOINT: ${{ secrets.PUBLIC_CONTACT_FORM_ENDPOINT }}
@ -30,19 +25,16 @@ jobs:
steps:
- uses: actions/checkout@v4
- name: Install build and S3 tools
- name: Install validation tools
run: |
set -eu
apt-get update -qq
apt-get install -y -q ca-certificates python3-venv
python3 -m venv /opt/awscli
/opt/awscli/bin/pip install --quiet awscli
apt-get install -y -q python3
- name: Install dependencies
run: npm ci --no-audit --no-fund
- name: Build and validate Astro output
run: |
set -eu
npm ci --no-audit --no-fund
npm run check
run: npm run check
- name: Split public and protected admin bundles
run: |
@ -59,7 +51,22 @@ jobs:
cp -a dist/admin/content bundle-admin/admin/content
cp dist/css/admin.css bundle-admin/css/admin.css
- name: Publish to Garage
- name: Install Garage publishing tools
if: github.ref == 'refs/heads/main'
run: |
set -eu
apt-get update -qq
apt-get install -y -q ca-certificates python3-venv
python3 -m venv /opt/awscli
/opt/awscli/bin/pip install --quiet awscli
- name: Publish main to Garage
if: github.ref == 'refs/heads/main'
env:
AWS_ACCESS_KEY_ID: ${{ secrets.GARAGE_SITES_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.GARAGE_SITES_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: garage-sites
GARAGE_S3_ENDPOINT: https://s3-sites.bcgen.ie
run: |
set -eu
aws=/opt/awscli/bin/aws

View file

@ -24,6 +24,8 @@ migration continues.
- Keep the structure simple and close to what the user asks for.
- `.forgejo/` and deployment configuration are not special unless the user says
they are.
- Feature-branch Actions build and validate only. Production Garage publishing
is restricted to commits on `main`.
## Repo Map

View file

@ -110,13 +110,18 @@ http://localhost:4321/
## Deployment
This project deploys as a static Astro build. A deployment job should install
dependencies, run the build, and publish the generated `dist/` directory:
This project deploys as a static Astro build through Forgejo Actions. Every
branch push installs dependencies, builds the complete site, audits its links,
and prepares the separate public and protected-admin bundles. Feature branches
never receive Garage publishing credentials and never change production.
Only commits on `main` synchronize the validated bundles to `familyfed.ie` and
`admin.familyfed.ie` in Garage. A manual workflow dispatch is subject to the
same branch guard: dispatching a feature branch builds it but cannot publish it.
The equivalent local validation is:
```bash
npm ci
npm run build
npm run check
```
Use `npm run start` only when you intentionally want Astro to serve the built
output in an environment such as a local or Nomad preview job.