Files
av-planner/.woodpecker.yml
aarbitandClaude Sonnet 5 a0d62587de
ci/woodpecker/push/woodpecker Pipeline was successful
Add explicit event filters to install/lint/typecheck steps
Woodpecker's linter flags steps with no event filter as a "bad habit" (they'd
otherwise run on every event type, including ones added to Woodpecker in the
future). Scoped to [push, deployment] specifically — not just push — since a
production deploy re-runs the whole pipeline as a deployment event, and
deploy-production's build needs these steps (especially install's node_modules)
to have actually run first.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DUU6CnxECCDeqDNYJgr5x
2026-09-29 15:52:35 -05:00

96 lines
3.5 KiB
YAML

# See deployment-plan.md's "CI/CD plan" section for the full rationale.
#
# Shape: every push (any branch) lints, typechecks, and auto-deploys to a
# single shared staging environment (its own Cloudflare Workers + its own
# Supabase project — never shares data with production). Production is
# never touched automatically — promoting to it is a manual "Deploy" button
# click on a main-branch pipeline run in the Woodpecker UI (Woodpecker's
# deployment event), which is why deploy-production is gated on
# `event: deployment` rather than `event: push`.
#
# Debian-based node image (not Alpine) for every step: the Supabase CLI's
# downloaded binary has had musl/Alpine compatibility issues in the past.
# Woodpecker shares one workspace across all steps in a pipeline run, so
# `npm ci` in the install step is enough for every later step to reuse.
steps:
# Explicit event filter on these three (rather than the no-`when` default,
# which runs on every event Woodpecker knows about) because a deploy-time
# re-run of this pipeline is a `deployment` event, not `push` — install
# has to fire there too, or deploy-production's `npm run build` would run
# with no node_modules.
- name: install
image: node:22-bookworm
when:
- event: [push, deployment]
commands:
- npm ci
- name: lint
image: node:22-bookworm
when:
- event: [push, deployment]
commands:
- npm run lint
- name: typecheck
image: node:22-bookworm
when:
- event: [push, deployment]
commands:
- npx tsc -b
- name: deploy-staging
image: node:22-bookworm
when:
- event: push
environment:
VITE_SUPABASE_URL:
from_secret: staging_supabase_url
VITE_SUPABASE_ANON_KEY:
from_secret: staging_supabase_anon_key
CLOUDFLARE_API_TOKEN:
from_secret: cloudflare_api_token
CLOUDFLARE_ACCOUNT_ID:
from_secret: cloudflare_account_id
SUPABASE_ACCESS_TOKEN:
from_secret: supabase_access_token
SUPABASE_PROJECT_REF:
from_secret: staging_supabase_project_ref
SUPABASE_DB_PASSWORD:
from_secret: staging_supabase_db_password
commands:
- npm run build
- npx wrangler deploy --config wrangler.app.jsonc --env staging
- npx wrangler deploy --config wrangler.site.jsonc --env staging
- npx supabase db push --project-ref $SUPABASE_PROJECT_REF --password "$SUPABASE_DB_PASSWORD"
- npx supabase functions deploy admin-user-action --project-ref $SUPABASE_PROJECT_REF
- name: deploy-production
image: node:22-bookworm
when:
- event: deployment
branch: main
evaluate: 'CI_PIPELINE_DEPLOY_TARGET == "production"'
environment:
VITE_SUPABASE_URL:
from_secret: prod_supabase_url
VITE_SUPABASE_ANON_KEY:
from_secret: prod_supabase_anon_key
CLOUDFLARE_API_TOKEN:
from_secret: cloudflare_api_token
CLOUDFLARE_ACCOUNT_ID:
from_secret: cloudflare_account_id
SUPABASE_ACCESS_TOKEN:
from_secret: supabase_access_token
SUPABASE_PROJECT_REF:
from_secret: prod_supabase_project_ref
SUPABASE_DB_PASSWORD:
from_secret: prod_supabase_db_password
commands:
- npm run build
- npx wrangler deploy --config wrangler.app.jsonc
- npx wrangler deploy --config wrangler.site.jsonc
- npx supabase db push --project-ref $SUPABASE_PROJECT_REF --password "$SUPABASE_DB_PASSWORD"
- npx supabase functions deploy admin-user-action --project-ref $SUPABASE_PROJECT_REF