| 1 | name: Web Frontend |
| 2 | |
| 3 | on: |
| 4 | push: |
| 5 | branches: [master, main] |
| 6 | paths: |
| 7 | # Everything the web gates read, not only web/. derive-facts, |
| 8 | # check-facts, check-docs, check-cloud-facts, gt-site and the vitest |
| 9 | # contract tests read these repo paths (and git history of the model |
| 10 | # declarations under crates/). workflow_dispatch ignores path filters, |
| 11 | # so a manual deploy always runs. |
| 12 | - 'web/**' |
| 13 | - 'crates/**' |
| 14 | - 'docs/**' |
| 15 | - '*.md' |
| 16 | - 'LICENSE' |
| 17 | - 'Cargo.toml' |
| 18 | - 'package.json' |
| 19 | - 'npm/codewhale/**' |
| 20 | - 'vendor/codewhale-design/**' |
| 21 | - 'telemetry-ingest/test/golden/**' |
| 22 | - 'workflows/**' |
| 23 | - 'fleets/**' |
| 24 | - '.codewhale/**' |
| 25 | - '.github/SECURITY.md' |
| 26 | - '.github/workflows/web.yml' |
| 27 | - 'scripts/export-design-tokens.py' |
| 28 | pull_request: |
| 29 | branches: [master, main] |
| 30 | # Same list as push above. |
| 31 | paths: |
| 32 | - 'web/**' |
| 33 | - 'crates/**' |
| 34 | - 'docs/**' |
| 35 | - '*.md' |
| 36 | - 'LICENSE' |
| 37 | - 'Cargo.toml' |
| 38 | - 'package.json' |
| 39 | - 'npm/codewhale/**' |
| 40 | - 'vendor/codewhale-design/**' |
| 41 | - 'telemetry-ingest/test/golden/**' |
| 42 | - 'workflows/**' |
| 43 | - 'fleets/**' |
| 44 | - '.codewhale/**' |
| 45 | - '.github/SECURITY.md' |
| 46 | - '.github/workflows/web.yml' |
| 47 | - 'scripts/export-design-tokens.py' |
| 48 | workflow_dispatch: |
| 49 | |
| 50 | permissions: |
| 51 | contents: read |
| 52 | |
| 53 | concurrency: |
| 54 | # A new push to a PR cancels its superseded web run. Push and dispatch runs |
| 55 | # get a per-run group so a queued manual deploy is never cancelled by a |
| 56 | # later push (the deploy job additionally serializes on its own group). |
| 57 | group: ${{ github.event_name == 'pull_request' && format('web-pr-{0}', github.event.pull_request.number) || format('web-{0}', github.run_id) }} |
| 58 | cancel-in-progress: ${{ github.event_name == 'pull_request' }} |
| 59 | |
| 60 | jobs: |
| 61 | lint: |
| 62 | name: Lint & Type Check |
| 63 | runs-on: ubuntu-latest |
| 64 | timeout-minutes: 30 |
| 65 | defaults: |
| 66 | run: |
| 67 | working-directory: web |
| 68 | steps: |
| 69 | - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 |
| 70 | with: |
| 71 | # `check:facts` derives each model's `addedAt` from the commit date on |
| 72 | # which its id first appeared in the model declaration paths |
| 73 | # (web/scripts/facts-lib.mjs). A shallow checkout cannot see that |
| 74 | # history, so every date collapses to the tip commit and the committed |
| 75 | # facts always read as stale. ci.yml pins depth 0 for the same reason. |
| 76 | fetch-depth: 0 |
| 77 | - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 |
| 78 | with: |
| 79 | node-version: 22 |
| 80 | cache: 'npm' |
| 81 | cache-dependency-path: web/package-lock.json |
| 82 | - name: Install dependencies |
| 83 | run: npm ci |
| 84 | - name: Run tests |
| 85 | run: npm test |
| 86 | - name: Check web surface |
| 87 | # The shared gate checks committed facts before generating build inputs. |
| 88 | env: |
| 89 | GITHUB_TOKEN: ${{ github.token }} |
| 90 | run: npm run check |
| 91 | |
| 92 | deploy-reminder: |
| 93 | name: Deployment approval needed |
| 94 | runs-on: ubuntu-latest |
| 95 | timeout-minutes: 5 |
| 96 | needs: lint |
| 97 | if: github.event_name == 'push' && github.ref == 'refs/heads/main' |
| 98 | steps: |
| 99 | - name: Surface the manual deployment gate |
| 100 | env: |
| 101 | REVISION: ${{ github.sha }} |
| 102 | run: | |
| 103 | echo "::notice title=Web deployment approval needed::Revision ${REVISION} passed the web gates but is not deployed. Dispatch web.yml on main to publish it." |
| 104 | { |
| 105 | echo "## Web deployment approval needed" |
| 106 | echo |
| 107 | echo "Revision \`${REVISION}\` passed the web gates but has **not** been deployed." |
| 108 | echo |
| 109 | echo "A maintainer can publish it with \`gh workflow run web.yml --repo codewhale-hq/CodeWhale --ref main\`." |
| 110 | } >> "$GITHUB_STEP_SUMMARY" |
| 111 | |
| 112 | deploy: |
| 113 | name: Deploy to Cloudflare |
| 114 | runs-on: ubuntu-latest |
| 115 | timeout-minutes: 30 |
| 116 | needs: lint |
| 117 | # Deploy is MANUAL ONLY: a human dispatches this workflow on main. Pushes |
| 118 | # and pull requests still run `lint` above, but they never reach Cloudflare. |
| 119 | # This mirrors scripts/check-cloudflare-deploy-env.mjs, which fails closed |
| 120 | # unless GITHUB_EVENT_NAME is workflow_dispatch, GITHUB_REF is |
| 121 | # refs/heads/main, and GITHUB_SHA is an exact 40-hex revision — a push |
| 122 | # trigger here would only produce a red job after `lint` had already run. |
| 123 | # lib/deploy-preflight.test.ts asserts both halves of that contract. |
| 124 | # `needs: lint` is the gate: facts drift, docs parity, tests, ESLint, tsc, |
| 125 | # and a production build all pass before anything reaches Cloudflare. |
| 126 | if: >- |
| 127 | github.event_name == 'workflow_dispatch' |
| 128 | && github.ref == 'refs/heads/main' |
| 129 | # Serialize deploys so two dispatches landing close together cannot race and |
| 130 | # leave Cloudflare serving the older bundle. Never cancel in progress: a |
| 131 | # half-finished OpenNext upload is worse than a queued one. |
| 132 | concurrency: |
| 133 | group: deploy-codewhale-web |
| 134 | cancel-in-progress: false |
| 135 | defaults: |
| 136 | run: |
| 137 | working-directory: web |
| 138 | env: |
| 139 | CLOUDFLARE_ACCOUNT_ID: ${{ vars.CLOUDFLARE_ACCOUNT_ID }} |
| 140 | CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} |
| 141 | steps: |
| 142 | - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 |
| 143 | # Pin the checkout to the exact revision this dispatch resolved, so the |
| 144 | # SHA reported to compare:deployed-facts and asserted on the public |
| 145 | # receipt below is the SHA that was actually built, even if main moves |
| 146 | # while the run is queued behind the concurrency group. |
| 147 | with: |
| 148 | ref: ${{ github.sha }} |
| 149 | - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 |
| 150 | with: |
| 151 | node-version: 22 |
| 152 | cache: 'npm' |
| 153 | cache-dependency-path: web/package-lock.json |
| 154 | - name: Install dependencies |
| 155 | run: npm ci |
| 156 | - name: Record deployed/source drift |
| 157 | # Read-only and credential-free. A mismatch is the normal state here — |
| 158 | # it is the gap this run is about to close — so this step reports |
| 159 | # without gating. The real assertion is the post-deploy verification |
| 160 | # below, which must observe this exact revision on the public receipt. |
| 161 | run: npm run compare:deployed-facts -- --expected-revision "$GITHUB_SHA" |
| 162 | - name: Check Cloudflare deploy environment |
| 163 | run: npm run check:deploy-env |
| 164 | # npm's deploy script performs one OpenNext build, then deploys that exact |
| 165 | # bundle. Wrangler must not run a custom post-cache build: OpenNext |
| 166 | # populates the remote cache before it hands the bundle to Wrangler. |
| 167 | - name: Build and deploy exact OpenNext bundle |
| 168 | run: npm run deploy |
| 169 | - name: Verify exact deployed revision |
| 170 | # The public /api/facts receipt must identify this workflow's exact |
| 171 | # checkout before the manual deployment run can finish green. |
| 172 | run: npm run check:deployed-facts -- --expected-revision "$GITHUB_SHA" --attempts 10 --retry-delay-ms 3000 |
| 173 |