Standardize Astro validation and Garage publishing #11
3 changed files with 38 additions and 24 deletions
|
|
@ -1,25 +1,20 @@
|
||||||
name: Publish static bundles
|
name: Build and publish static site
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches: [main]
|
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
concurrency:
|
concurrency:
|
||||||
group: publish-main
|
group: site-${{ github.ref }}
|
||||||
cancel-in-progress: true
|
cancel-in-progress: true
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
publish:
|
build:
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container:
|
container:
|
||||||
image: node:24-bookworm
|
image: node:24-bookworm
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
env:
|
env:
|
||||||
AWS_ACCESS_KEY_ID: ${{ secrets.GARAGE_SITES_ACCESS_KEY_ID }}
|
|
||||||
AWS_SECRET_ACCESS_KEY: ${{ secrets.GARAGE_SITES_SECRET_ACCESS_KEY }}
|
|
||||||
AWS_DEFAULT_REGION: garage-sites
|
|
||||||
GARAGE_S3_ENDPOINT: https://s3-sites.bcgen.ie
|
|
||||||
NODE_OPTIONS: --max-old-space-size=768
|
NODE_OPTIONS: --max-old-space-size=768
|
||||||
PUBLIC_ANALYTICS_DASHBOARD_URL: ${{ secrets.PUBLIC_ANALYTICS_DASHBOARD_URL }}
|
PUBLIC_ANALYTICS_DASHBOARD_URL: ${{ secrets.PUBLIC_ANALYTICS_DASHBOARD_URL }}
|
||||||
PUBLIC_CONTACT_FORM_ENDPOINT: ${{ secrets.PUBLIC_CONTACT_FORM_ENDPOINT }}
|
PUBLIC_CONTACT_FORM_ENDPOINT: ${{ secrets.PUBLIC_CONTACT_FORM_ENDPOINT }}
|
||||||
|
|
@ -30,19 +25,16 @@ jobs:
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Install build and S3 tools
|
- name: Install validation tools
|
||||||
run: |
|
run: |
|
||||||
set -eu
|
|
||||||
apt-get update -qq
|
apt-get update -qq
|
||||||
apt-get install -y -q ca-certificates python3-venv
|
apt-get install -y -q python3
|
||||||
python3 -m venv /opt/awscli
|
|
||||||
/opt/awscli/bin/pip install --quiet awscli
|
- name: Install dependencies
|
||||||
|
run: npm ci --no-audit --no-fund
|
||||||
|
|
||||||
- name: Build and validate Astro output
|
- name: Build and validate Astro output
|
||||||
run: |
|
run: npm run check
|
||||||
set -eu
|
|
||||||
npm ci --no-audit --no-fund
|
|
||||||
npm run check
|
|
||||||
|
|
||||||
- name: Split public and protected admin bundles
|
- name: Split public and protected admin bundles
|
||||||
run: |
|
run: |
|
||||||
|
|
@ -59,7 +51,22 @@ jobs:
|
||||||
cp -a dist/admin/content bundle-admin/admin/content
|
cp -a dist/admin/content bundle-admin/admin/content
|
||||||
cp dist/css/admin.css bundle-admin/css/admin.css
|
cp dist/css/admin.css bundle-admin/css/admin.css
|
||||||
|
|
||||||
- name: Publish to Garage
|
- name: Install Garage publishing tools
|
||||||
|
if: github.ref == 'refs/heads/main'
|
||||||
|
run: |
|
||||||
|
set -eu
|
||||||
|
apt-get update -qq
|
||||||
|
apt-get install -y -q ca-certificates python3-venv
|
||||||
|
python3 -m venv /opt/awscli
|
||||||
|
/opt/awscli/bin/pip install --quiet awscli
|
||||||
|
|
||||||
|
- name: Publish main to Garage
|
||||||
|
if: github.ref == 'refs/heads/main'
|
||||||
|
env:
|
||||||
|
AWS_ACCESS_KEY_ID: ${{ secrets.GARAGE_SITES_ACCESS_KEY_ID }}
|
||||||
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.GARAGE_SITES_SECRET_ACCESS_KEY }}
|
||||||
|
AWS_DEFAULT_REGION: garage-sites
|
||||||
|
GARAGE_S3_ENDPOINT: https://s3-sites.bcgen.ie
|
||||||
run: |
|
run: |
|
||||||
set -eu
|
set -eu
|
||||||
aws=/opt/awscli/bin/aws
|
aws=/opt/awscli/bin/aws
|
||||||
|
|
|
||||||
|
|
@ -24,6 +24,8 @@ migration continues.
|
||||||
- Keep the structure simple and close to what the user asks for.
|
- Keep the structure simple and close to what the user asks for.
|
||||||
- `.forgejo/` and deployment configuration are not special unless the user says
|
- `.forgejo/` and deployment configuration are not special unless the user says
|
||||||
they are.
|
they are.
|
||||||
|
- Feature-branch Actions build and validate only. Production Garage publishing
|
||||||
|
is restricted to commits on `main`.
|
||||||
|
|
||||||
## Repo Map
|
## Repo Map
|
||||||
|
|
||||||
|
|
|
||||||
17
README.md
17
README.md
|
|
@ -110,13 +110,18 @@ http://localhost:4321/
|
||||||
|
|
||||||
## Deployment
|
## Deployment
|
||||||
|
|
||||||
This project deploys as a static Astro build. A deployment job should install
|
This project deploys as a static Astro build through Forgejo Actions. Every
|
||||||
dependencies, run the build, and publish the generated `dist/` directory:
|
branch push installs dependencies, builds the complete site, audits its links,
|
||||||
|
and prepares the separate public and protected-admin bundles. Feature branches
|
||||||
|
never receive Garage publishing credentials and never change production.
|
||||||
|
|
||||||
|
Only commits on `main` synchronize the validated bundles to `familyfed.ie` and
|
||||||
|
`admin.familyfed.ie` in Garage. A manual workflow dispatch is subject to the
|
||||||
|
same branch guard: dispatching a feature branch builds it but cannot publish it.
|
||||||
|
|
||||||
|
The equivalent local validation is:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
npm ci
|
npm ci
|
||||||
npm run build
|
npm run check
|
||||||
```
|
```
|
||||||
|
|
||||||
Use `npm run start` only when you intentionally want Astro to serve the built
|
|
||||||
output in an environment such as a local or Nomad preview job.
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue