d3ro-voice/.forgejo/workflows/deploy-site.yml
Yun Chan b8a09c0333
Some checks failed
ci / 정본·보안·린트·타입·테스트 (push) Failing after 59s
ci / 워크스페이스 빌드 검증 (push) Has been skipped
ci / 모바일 린트·타입·Jest (push) Successful in 41s
ci / Supabase Edge Functions + Cloudflare Worker (push) Successful in 21s
ci / .NET API 서버 테스트 (push) Successful in 16s
deploy-site / deploy (push) Successful in 21s
ci(forgejo): install the .nvmrc Node before npm on the Linux runner
The first real Forgejo CI run failed because the linux-builder runner ships
Node 18.19: scripts using import.meta.dirname threw, and its older npm
reported the mobile lock as out of sync with the file: dependency on
packages/core (the lock is in sync under Node 24's npm).

bootstrap-linux-toolchain.sh gains a checksum-verified `node` mode
(24.19.0, the .nvmrc version); ci.yml (quality, build-validation,
mobile-quality) and deploy-site.yml add it to GITHUB_PATH before npm runs.
2026-09-26 21:05:34 +09:00

80 lines
3.7 KiB
YAML

name: deploy-site
# 사이트(site/) 배포의 유일한 경로: Cloudflare Pages `d3ro` (d3ro.chanpaca.net).
# 예전 deploy-site-windows.yml(수동 전용·배포 검증 없음)과 .github/workflows/deploy-site.yml
# (GitHub Pages, 실행된 적 없음)을 이 파일로 합쳤다.
#
# site/는 저장소 루트의 packages/core/src/*.ts 를 상대 import 하므로 전체 트리를 체크아웃한다
# (sparse checkout 금지).
#
# 필요한 시크릿: CF_API_TOKEN(또는 CLOUDFLARE_API_TOKEN), CF_ACCOUNT_ID(또는 CLOUDFLARE_ACCOUNT_ID)
on:
push:
branches: [main]
workflow_dispatch:
jobs:
deploy:
runs-on: linux-builder
steps:
- name: checkout
env: { CI_TOKEN: "${{ github.token }}" }
run: |
proto="${GITHUB_SERVER_URL%%://*}"; host="${GITHUB_SERVER_URL#*://}"
url="$proto://actions:${CI_TOKEN}@${host%/}/${GITHUB_REPOSITORY}.git"
[ -d .git ] || git init -q .
git remote remove origin 2>/dev/null || true
git remote add origin "$url"
git fetch -q --depth 1 origin "$GITHUB_REF"
git checkout -q -f FETCH_HEAD
git clean -qfdx
- name: Node (.nvmrc) 설치
shell: bash
run: |
set -euo pipefail
export CI_PROJECT_DIR="${XDG_CACHE_HOME:-$HOME/.cache}/d3ro-ci"
. scripts/ci/bootstrap-linux-toolchain.sh node
dirname "$(command -v node)" >> "$GITHUB_PATH"
- name: 모바일 릴리스 공개 경계 검사
run: node scripts/ci/verify-mobile-release-boundary.mjs --self-test
- name: 의존성 설치 및 사이트 빌드
run: |
npm ci --prefix site
npm run build --prefix site
node -e "const fs=require('node:fs'); const v=require('./release/product-version.json').version; fs.writeFileSync('site/dist/release-identity.json', JSON.stringify({commit:process.env.GITHUB_SHA,version:v},null,2)+'\n')"
- name: Cloudflare Pages 배포 (d3ro.chanpaca.net)
env:
CLOUDFLARE_API_TOKEN: "${{ secrets.CF_API_TOKEN || secrets.CLOUDFLARE_API_TOKEN }}"
CLOUDFLARE_ACCOUNT_ID: "${{ secrets.CF_ACCOUNT_ID || secrets.CLOUDFLARE_ACCOUNT_ID }}"
run: |
if [ -n "$CLOUDFLARE_API_TOKEN" ]; then
echo "Cloudflare Pages 배포 시작 (d3ro)..."
npx --yes wrangler@latest pages deploy site/dist \
--project-name d3ro \
--branch main \
--commit-dirty=true || \
npx --yes wrangler@latest pages deploy site/dist \
--project-name d3ro-voice \
--branch main \
--commit-dirty=true
else
echo "CLOUDFLARE_API_TOKEN 없음" >&2
exit 1
fi
- name: 공개 배포 식별자 검증
run: |
curl --fail --silent --show-error --retry 6 --retry-delay 5 \
https://d3ro.chanpaca.net/release-identity.json \
--output release-identity.live.json
node -e "const fs=require('node:fs'); const live=JSON.parse(fs.readFileSync('release-identity.live.json','utf8')); if(live.commit!==process.env.GITHUB_SHA) throw new Error('public commit mismatch'); const expected=require('./release/product-version.json').version; if(live.version!==expected) throw new Error('public version mismatch')"
node scripts/ci/verify-android-app-links.mjs
curl --fail --silent --show-error https://d3ro.chanpaca.net/ --output /dev/null
curl --fail --silent --show-error https://d3ro.chanpaca.net/privacy/ --output /dev/null
curl --fail --silent --show-error https://d3ro.chanpaca.net/terms/ --output /dev/null
curl --fail --silent --show-error https://d3ro.chanpaca.net/delete-account/ --output /dev/null