Skip to content

Publish only commits that pass CI - #388

Merged
Nicolas Palpacuer (NickPPC) merged 1 commit into
mainfrom
ci/deploy-after-ci
Sep 30, 2026
Merged

Nicolas Palpacuer (NickPPC) merged 1 commit into
mainfrom
ci/deploy-after-ci

Conversation

@NickPPC

Copy link
Copy Markdown
Member

Summary

Deploy now runs CI and the web-app checks on the exact commit it publishes, and tags nothing unless both pass. Before, it ran in parallel with CI on every main push, so a red commit was still tagged and uploaded to the registry as an rc.

⚠️ Rollout: ci.yml and web-app.yml lose their push: main triggers — main is checked once, inside Deploy. Markdown-only pushes (Deploy's paths-ignore) are no longer checked on main.

❓ After merge (settings, not code): add web-app to the main protection required checks. It now reports on every PR, and as a skipped job when web-app/ is untouched.

Changes

  • Deploy is gated on CI: ci.yml and web-app.yml are called as reusable workflows, and compute-version needs both
  • The web app is type-checked: tsc --noEmit, because lint and node --test strip types without checking them
  • An untidy go.mod fails CI: go mod tidy -diff; make setup now runs go mod download, so neither CI nor the registry build rewrites the module graph
  • Least-privilege deploy token: read-only by default, contents: write only on the rc-tagging job, no persisted credentials, expression values passed to shell through env
  • Deploys are serialised: a concurrency group, so two quick pushes can't compute the same -rc.N

Testing

  • actionlint is clean, and go mod tidy -diff is clean on current main.
  • This first runs for real on the PR's own checks (CI plus the new changes job). The Deploy path runs on the first push to main after merge; watch that run.
Claude Code prompts used
  • "/repo-audit --exhaustive"
  • "Can you start a new worktree and create a draft PR each for the first 2 red items? A2 and A5? Can you recommend steps to improve E1?"
  • "Can you create a PR with items 1, 3, 4, 6, and 7?"

🤖 Generated with Claude Code

deploy.yml ran on every push to main in parallel with CI and never
waited for it, so a commit that failed build, lint or tests was still
tagged and uploaded to the registry. It now calls ci.yml and
web-app.yml as reusable workflows and tags nothing unless both pass on
that commit; the two no longer run their own push triggers, so main
isn't checked twice.

The web-app job also type-checks with tsc, since lint and node --test
strip types without checking them. It runs on every PR and skips its
work when web-app/ is untouched, so it can be made a required check.

CI now fails on an untidy go.mod with `go mod tidy -diff`, and
`make setup` downloads modules instead of tidying them, so neither CI
nor the registry build rewrites the committed module graph.

deploy.yml defaults to read-only, grants contents: write only to the
job that pushes the rc tag, checks out without persisted credentials,
passes expression values to shell through env, and serialises runs so
two pushes can't compute the same rc tag.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@NickPPC
Nicolas Palpacuer (NickPPC) marked this pull request as ready for review September 30, 2026 15:27
@NickPPC
Nicolas Palpacuer (NickPPC) merged commit b4048d1 into main Sep 30, 2026
6 checks passed
@NickPPC
Nicolas Palpacuer (NickPPC) deleted the ci/deploy-after-ci branch September 30, 2026 15:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant