Skip to content

ci: skip production deploys for documentation-only changes - #24

Merged
saqibmanan merged 1 commit into
mainfrom
ci-skip-deploy-for-docs
Sep 8, 2026
Merged

saqibmanan merged 1 commit into
mainfrom
ci-skip-deploy-for-docs

Conversation

@saqibmanan

Copy link
Copy Markdown
Contributor

Two changes, one of which fixes a comment that had become actively misleading.

1. Documentation changes no longer redeploy production

Merging a README edit (#23) rebuilt the image and restarted Keycloak. Harmless in itself, but it is a needless restart of the auth server every product depends on, and it buries real deploys among cosmetic ones in the run history.

paths-ignore:
  - '**.md'
  - 'LICENSE'
  - '.gitignore'
  - 'docs/**'
  - '.vscode/**'

Only files that cannot affect the built image or the deployment. Verified both directions:

Path Behaviour
src/login/pages/Register.tsx still deploys
Dockerfile, package.json still deploys
deploy/docker-compose.staging.yml still deploys
.github/workflows/deploy-keycloak-staging.yml still deploys
README.md, SECURITY.md, LICENSE, .gitignore, docs/** skipped

2. Corrects a now-dangerous comment

The environment: comment previously said keycloak-staging was kept so it could be flipped back to "in one line" if the production environment misbehaved.

That advice is now wrong. That environment holds placeholder secrets — it is being kept to be repurposed for a real staging server later. Following the old comment would break the deploy without explaining why: appleboy/ssh-action reports a bad key as an opaque handshake failure, not as a credentials problem, so it would look like a broken box rather than a misrouted environment.

The comment now says the opposite, and records the constraint that caused the original two-PR split: GitHub cannot move secrets between environments, so a future switch means adding EC2_HOST, EC2_USERNAME and EC2_PRIVATE_KEY to the target first.

Merging a README edit rebuilt the image and restarted Keycloak. Harmless
in itself, but it is a needless restart of the auth server every product
depends on, and it buries real deploys among cosmetic ones in the run
history.

paths-ignore covers only files that cannot affect the built image or the
deployment: markdown, LICENSE, .gitignore, docs/ and .vscode/. Verified
that src/, the Dockerfile, package.json, the compose file and this
workflow all still trigger a deploy.

Also corrects a comment that had become dangerous. It previously said
keycloak-staging was kept so the environment could be flipped back "in
one line" if the production environment misbehaved. That environment now
holds placeholder secrets - it is being kept to be repurposed for a real
staging server - so following that advice would break the deploy without
saying why: appleboy/ssh-action reports a bad key as an opaque handshake
error, not as a credentials problem. The comment now says the opposite,
and records that secrets must be added to a target environment before
switching to it, because GitHub cannot move them.
@saqibmanan
saqibmanan merged commit d822a85 into main Sep 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant