ci/woodpecker/push/woodpecker Pipeline was successful
Caught from the linter warnings on the first real pipeline run (#1) — the production-promotion step's event filter used \`deploy\`, an invalid event name, so it would never have matched Woodpecker's actual deploy-button event (\`deployment\`) and the production step would have silently never run. Staging's own deploy (a push-triggered step) was unaffected and verified working on that same run. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017DUU6CnxECCDeqDNYJgr5x
85 lines
3.0 KiB
YAML
85 lines
3.0 KiB
YAML
# See deployment-plan.md's "CI/CD plan" section for the full rationale.
|
|
#
|
|
# Shape: every push (any branch) lints, typechecks, and auto-deploys to a
|
|
# single shared staging environment (its own Cloudflare Workers + its own
|
|
# Supabase project — never shares data with production). Production is
|
|
# never touched automatically — promoting to it is a manual "Deploy" button
|
|
# click on a main-branch pipeline run in the Woodpecker UI (Woodpecker's
|
|
# deployment event), which is why deploy-production is gated on
|
|
# `event: deployment` rather than `event: push`.
|
|
#
|
|
# Debian-based node image (not Alpine) for every step: the Supabase CLI's
|
|
# downloaded binary has had musl/Alpine compatibility issues in the past.
|
|
# Woodpecker shares one workspace across all steps in a pipeline run, so
|
|
# `npm ci` in the install step is enough for every later step to reuse.
|
|
|
|
steps:
|
|
- name: install
|
|
image: node:22-bookworm
|
|
commands:
|
|
- npm ci
|
|
|
|
- name: lint
|
|
image: node:22-bookworm
|
|
commands:
|
|
- npm run lint
|
|
|
|
- name: typecheck
|
|
image: node:22-bookworm
|
|
commands:
|
|
- npx tsc -b
|
|
|
|
- name: deploy-staging
|
|
image: node:22-bookworm
|
|
when:
|
|
- event: push
|
|
environment:
|
|
VITE_SUPABASE_URL:
|
|
from_secret: staging_supabase_url
|
|
VITE_SUPABASE_ANON_KEY:
|
|
from_secret: staging_supabase_anon_key
|
|
CLOUDFLARE_API_TOKEN:
|
|
from_secret: cloudflare_api_token
|
|
CLOUDFLARE_ACCOUNT_ID:
|
|
from_secret: cloudflare_account_id
|
|
SUPABASE_ACCESS_TOKEN:
|
|
from_secret: supabase_access_token
|
|
SUPABASE_PROJECT_REF:
|
|
from_secret: staging_supabase_project_ref
|
|
SUPABASE_DB_PASSWORD:
|
|
from_secret: staging_supabase_db_password
|
|
commands:
|
|
- npm run build
|
|
- npx wrangler deploy --config wrangler.app.jsonc --env staging
|
|
- npx wrangler deploy --config wrangler.site.jsonc --env staging
|
|
- npx supabase db push --project-ref $SUPABASE_PROJECT_REF --password "$SUPABASE_DB_PASSWORD"
|
|
- npx supabase functions deploy admin-user-action --project-ref $SUPABASE_PROJECT_REF
|
|
|
|
- name: deploy-production
|
|
image: node:22-bookworm
|
|
when:
|
|
- event: deployment
|
|
branch: main
|
|
evaluate: 'CI_PIPELINE_DEPLOY_TARGET == "production"'
|
|
environment:
|
|
VITE_SUPABASE_URL:
|
|
from_secret: prod_supabase_url
|
|
VITE_SUPABASE_ANON_KEY:
|
|
from_secret: prod_supabase_anon_key
|
|
CLOUDFLARE_API_TOKEN:
|
|
from_secret: cloudflare_api_token
|
|
CLOUDFLARE_ACCOUNT_ID:
|
|
from_secret: cloudflare_account_id
|
|
SUPABASE_ACCESS_TOKEN:
|
|
from_secret: supabase_access_token
|
|
SUPABASE_PROJECT_REF:
|
|
from_secret: prod_supabase_project_ref
|
|
SUPABASE_DB_PASSWORD:
|
|
from_secret: prod_supabase_db_password
|
|
commands:
|
|
- npm run build
|
|
- npx wrangler deploy --config wrangler.app.jsonc
|
|
- npx wrangler deploy --config wrangler.site.jsonc
|
|
- npx supabase db push --project-ref $SUPABASE_PROJECT_REF --password "$SUPABASE_DB_PASSWORD"
|
|
- npx supabase functions deploy admin-user-action --project-ref $SUPABASE_PROJECT_REF
|