Repository navigation
142 lines (135 loc) · 5.41 KB
/
Copy pathpreview-deploy.yaml
File metadata and controls
142 lines (135 loc) · 5.41 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
# Publish the site built by preview-pr.yaml to Cloudflare Pages. It runs from
# the default branch with the secrets, and never runs the PR code: it only
# uploads the files built by preview-pr.yaml.
name: preview-deploy
on:
workflow_run:
workflows: [preview-pr]
types: [completed]
permissions:
contents: read
# The statuses are set on the PR commit, so they show among the PR checks
env:
GH_TOKEN: ${{ github.token }}
HEAD_SHA: ${{ github.event.workflow_run.head_sha }}
RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
jobs:
# Tells the PR that the deploy of a fork waits for an approval, linking the
# run where a maintainer can approve it
request-approval:
if: >-
github.event.workflow_run.event == 'pull_request' &&
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.head_repository.full_name != github.repository
runs-on: ubuntu-latest
permissions:
statuses: write
steps:
- name: Report approval required
run: |
gh api "repos/$GITHUB_REPOSITORY/statuses/$HEAD_SHA" \
-f state=pending -f context=preview-deploy/approval \
-f description="Waiting for a maintainer to approve the preview deploy" \
-f target_url="$RUN_URL"
# PRs from forks wait for a manual approval of the "external" environment
authorize:
if: github.event.workflow_run.event == 'pull_request' && github.event.workflow_run.conclusion == 'success'
environment:
${{ github.event.workflow_run.head_repository.full_name != github.repository &&
'external' || 'internal' }}
runs-on: ubuntu-latest
permissions:
statuses: write
steps:
- name: Report approval granted
if: github.event.workflow_run.head_repository.full_name != github.repository
run: |
gh api "repos/$GITHUB_REPOSITORY/statuses/$HEAD_SHA" \
-f state=success -f context=preview-deploy/approval \
-f description="Preview deploy approved" \
-f target_url="$RUN_URL"
# Closes the approval status when the deploy is rejected or never approved
approval-rejected:
needs: [request-approval, authorize]
if: >-
always() &&
needs.request-approval.result == 'success' &&
needs.authorize.result != 'success'
runs-on: ubuntu-latest
permissions:
statuses: write
steps:
- name: Report approval rejected
run: |
gh api "repos/$GITHUB_REPOSITORY/statuses/$HEAD_SHA" \
-f state=failure -f context=preview-deploy/approval \
-f description="Preview deploy not approved" \
-f target_url="$RUN_URL"
deploy:
needs: authorize
runs-on: ubuntu-latest
permissions:
actions: read
pull-requests: write
statuses: write
# Shows the preview link on the job, like the Pages deploy
environment:
name: preview
url: ${{ steps.preview-pages.outputs.deployment-url }}
steps:
# Shows the deploy among the PR checks, next to the build
- name: Report deploy started
run: |
gh api "repos/$GITHUB_REPOSITORY/statuses/$HEAD_SHA" \
-f state=pending -f context=preview-deploy \
-f description="Publishing the preview to Cloudflare Pages..." \
-f target_url="$RUN_URL"
- name: Download artifacts
uses: actions/download-artifact@v4
with:
run-id: ${{ github.event.workflow_run.id }}
github-token: ${{ github.token }}
# The artifacts come from the PR code: make sure the number is really
# the PR of the commit that was built
- name: Find the PR
id: pr
run: |
number=$(cat pr-number/pr-number)
[[ "$number" =~ ^[0-9]+$ ]] || { echo "Invalid PR number"; exit 1; }
sha=$(gh api "repos/$GITHUB_REPOSITORY/pulls/$number" --jq .head.sha)
[[ "$sha" == "$HEAD_SHA" ]] || { echo "PR #$number is not at $HEAD_SHA"; exit 1; }
echo "number=$number" >> "$GITHUB_OUTPUT"
- name: Extract site
run: mkdir dist && tar -xf github-pages/artifact.tar -C dist
- name: Publish to Cloudflare Pages
id: preview-pages
uses: cloudflare/wrangler-action@v3
with:
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT }}
command: pages deploy dist --project-name=hack-gpon-preview --branch=preview
- name: Comment on the PR
env:
URL: ${{ steps.preview-pages.outputs.deployment-url }}
run: |
gh pr comment "${{ steps.pr.outputs.number }}" --repo "$GITHUB_REPOSITORY" \
--body "Preview of the website obtained from the PR: $URL"
- name: Report deploy status
if: always()
env:
OUTCOME: ${{ steps.preview-pages.outcome }}
URL: ${{ steps.preview-pages.outputs.deployment-url }}
run: |
if [ "$OUTCOME" = "success" ]; then
state=success
description="Preview published to Cloudflare Pages."
target_url="$URL"
else
state=failure
description="Preview deploy failed, see the workflow run."
target_url="$RUN_URL"
fi
gh api "repos/$GITHUB_REPOSITORY/statuses/$HEAD_SHA" \
-f state="$state" -f context=preview-deploy \
-f description="$description" \
-f target_url="$target_url"