Skip to content

Deploy main via Workers Builds, with a GitHub Actions fallback - #1

Merged
pid1 merged 1 commit into
mainfrom
cf-auto-deploy
Sep 28, 2026
Merged

pid1 merged 1 commit into
mainfrom
cf-auto-deploy

Conversation

@pid1

@pid1 pid1 commented Sep 28, 2026

Copy link
Copy Markdown
Owner

Pushes to main never deployed scram: the Worker has no Workers Builds trigger. This adds what the rx / pid1.github.io pattern needs.

  • build.sh copies public/ to dist/ and writes the commit to dist/.build-id. [build] in wrangler.toml runs it automatically; assets now come from ./dist.
  • public/_headers serves /.build-id with Cache-Control: no-store. It has to be _headers because assets are served before the Worker runs.
  • .github/workflows/cf-fallback.yml sleeps 600 s, compares https://scram.pid1.space/.build-id with github.sha, and only if they differ runs typecheck + tests + wrangler deploy. Docs-only pushes are skipped. Actions are pinned to SHAs, permissions: {}, persist-credentials: false.

Checked locally: typecheck, 38/38 tests, actionlint, wrangler deploy --dry-run, and wrangler dev (/.build-id returns the SHA with no-store; /, /healthcheck and /api/* behave as before).

Before or right after merging

  1. Connect Workers Builds in the dashboard (Workers & Pages > scram > Settings > Builds): repo pid1/scram, branch main, root /, build command npm run typecheck && npm test, deploy command npx wrangler deploy. No build variables needed.
  2. Add repo secrets CLOUDFLARE_API_TOKEN (Workers Scripts: Edit) and CLOUDFLARE_ACCOUNT_ID. Until you add them, the fallback fails whenever it decides to deploy. The live site serves no /.build-id yet, so the first push will always look stale to it.

Neither path applies D1 migrations or touches runtime secrets.

🤖 Generated with Claude Code

https://claude.ai/code/session_01ANZvTxc4uANFhddTwYq4TH

Pushes to main never reached production: the Worker had no Workers Builds
trigger and CI deliberately does not deploy. This adds the pieces for the
same two-path setup rx and pid1.github.io use.

- build.sh stages public/ into dist/ and writes the checked-out commit to
  dist/.build-id. wrangler.toml's [build] runs it before `wrangler dev` and
  `wrangler deploy`, and the assets directory moves to ./dist.
- public/_headers serves /.build-id with Cache-Control: no-store. Static
  assets are served before the Worker runs, so the header has to come from
  _headers rather than from a handler in the router.
- .github/workflows/cf-fallback.yml waits 600s, reads ${SITE}/.build-id, and
  only if the live commit is not github.sha runs typecheck, tests and
  `wrangler deploy`. It skips docs-only pushes.

The Workers Builds connection itself is made in the dashboard. Neither path
touches runtime secrets, which deploys keep, or D1 migrations.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ANZvTxc4uANFhddTwYq4TH
@pid1
pid1 merged commit 7a81eb7 into main Sep 28, 2026
2 checks passed
@pid1
pid1 deleted the cf-auto-deploy branch September 28, 2026 02:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant