-
Notifications
You must be signed in to change notification settings - Fork 0
197 lines (177 loc) · 7.05 KB
/
Copy pathdeploy.yml
File metadata and controls
197 lines (177 loc) · 7.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
name: Deploy to GitHub Pages
on:
push:
branches: [main]
workflow_dispatch:
inputs:
pages-base:
description: >-
Astro base path for project-level GitHub Pages (e.g. /purview-dev/).
Leave empty for a custom domain or organisation Pages site.
required: false
type: string
default: ""
schedule:
# Weekly refresh of release information from GitHub and NuGet.
- cron: "17 4 * * 1"
repository_dispatch:
# Fired by a release workflow in another purview-dev repository. The
# expected payload contract is documented in the README.
types: [purview-site-rebuild]
permissions:
contents: read
pages: write
id-token: write
concurrency:
group: pages
cancel-in-progress: false
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout
# actions/checkout v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
# Full history so sitemap `lastmod` can use each source file's real
# last-commit date (see src/src/lib/discovery/last-modified.ts).
fetch-depth: 0
- name: Install Bun
# oven-sh/setup-bun v2.2.0
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6
with:
bun-version: 1.4.2
- name: Install Just
# taiki-e/install-action v2.87.13
uses: taiki-e/install-action@9983c65e42da123ff25d1f78505eb6de315aa172
with:
tool: just@1.58.0
# The repository is a Bun workspace: the lockfile and root `package.json`
# live here, the Astro site package lives in `src/`, and every `bun run`
# / `just` recipe delegates to `src/` (see `package.json` scripts).
- name: Install dependencies
run: bun install --frozen-lockfile
- name: Capture the currently deployed discovery manifest
# Captured before the new site is deployed so the post-deploy IndexNow
# step can diff "what changed". Published as /_discovery/previous.json
# (public, non-sensitive) so no cross-job artifact is needed.
env:
SITE_URL: ${{ vars.SITE_URL }}
run: |
ORIGIN="${SITE_URL:-https://purview.dev}"
mkdir -p .discovery-capture
if curl -fsSL "$ORIGIN/discover.json" -o .discovery-capture/previous.json; then
echo "Captured the previous discovery manifest."
else
echo '{"schemaVersion":0,"resources":[]}' > .discovery-capture/previous.json
echo "No previous discovery manifest (first deployment)."
fi
- name: Run validation
# `just validate` runs a live data sync on fresh checkouts (no cache /
# docs mirror yet), so pass a token to avoid unauthenticated rate limits.
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: just validate
- name: Refresh live release and documentation data
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: DATA_MODE=live bun run data:sync
- name: Resolve deployment base and site URL
id: pages-config
env:
REPO_NAME: ${{ github.event.repository.name }}
OWNER: ${{ github.repository_owner }}
run: |
BASE="${{ vars.PAGES_BASE }}"
if [ -n "${{ inputs.pages-base }}" ]; then
BASE="${{ inputs.pages-base }}"
fi
if [ -z "$BASE" ]; then
if [ "$REPO_NAME" = "$OWNER.github.io" ]; then
BASE="/"
else
BASE="/$REPO_NAME"
fi
fi
SITE="${{ vars.SITE_URL }}"
if [ -z "$SITE" ]; then
SITE="https://$OWNER.github.io"
fi
echo "pages-base=$BASE" >> "$GITHUB_OUTPUT"
echo "site-url=$SITE" >> "$GITHUB_OUTPUT"
- name: Build site with live data
# The build never receives the IndexNow key: the key verification file is
# written from the secret by a separate step below (see docs/discovery.md).
env:
PAGES_BASE: ${{ steps.pages-config.outputs.pages-base }}
SITE_URL: ${{ steps.pages-config.outputs.site-url }}
run: bun run build
- name: Write the IndexNow key verification file
# The key is supplied only by the INDEXNOW_KEY repository secret and is
# never part of the build or its logs. This writes /<key>.txt, the file
# IndexNow fetches to prove ownership of the domain.
env:
INDEXNOW_KEY: ${{ secrets.INDEXNOW_KEY }}
run: |
if [ -z "${INDEXNOW_KEY}" ]; then
echo "::warning::INDEXNOW_KEY is not configured; skipping the key verification file."
exit 0
fi
bun run discovery:key
- name: Publish the previous discovery manifest for change detection
run: |
mkdir -p src/dist/_discovery
cp .discovery-capture/previous.json src/dist/_discovery/previous.json
- name: Configure Pages
# actions/configure-pages v6.0.0
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d
- name: Upload Pages artifact
# actions/upload-pages-artifact v5.0.0
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9
with:
# Build output is written into the `src/` package (see package.json).
path: ./src/dist
deploy:
needs: build
runs-on: ubuntu-latest
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- name: Deploy to GitHub Pages
id: deployment
# actions/deploy-pages v5.0.1
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346
indexnow:
# Runs only after a successful production deployment. A failed deploy must
# never tell search engines that new URLs are live. The site deployment
# stands on its own; a notification failure is reported here, not by
# rolling the deployment back.
needs: deploy
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
steps:
- name: Checkout
# actions/checkout v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
- name: Install Bun
# oven-sh/setup-bun v2.2.0
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6
with:
bun-version: 1.4.2
- name: Notify IndexNow about changed URLs
# Submits only URLs added or modified since the previous deployment.
# `discovery:indexnow` has no external dependencies, so no `bun install`
# is needed. The IndexNow key is never printed.
env:
SITE_URL: ${{ vars.SITE_URL }}
INDEXNOW_KEY: ${{ secrets.INDEXNOW_KEY }}
run: |
if [ -z "${INDEXNOW_KEY}" ]; then
echo "::warning::INDEXNOW_KEY is not configured; skipping the IndexNow notification."
exit 0
fi
ORIGIN="${SITE_URL:-https://purview.dev}"
bun run discovery:indexnow \
--current "$ORIGIN/discover.json" \
--previous "$ORIGIN/_discovery/previous.json"