whattheduck: Harden cover search #1686
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: deploy | |
| permissions: | |
| contents: write | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| force_all: | |
| description: "Build and deploy every package, ignoring change detection" | |
| type: boolean | |
| default: false | |
| push: | |
| branches: | |
| - "master" | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| environment: production | |
| env: | |
| REMOTE_ROOT: apps/dm | |
| PRODUCTION_SSH_HOST: ${{ secrets.PRODUCTION_SSH_HOST }} | |
| PRODUCTION_SSH_USER: ${{ secrets.PRODUCTION_SSH_USER }} | |
| PRODUCTION_SSH_KEY: ${{ secrets.PRODUCTION_SSH_KEY }} | |
| SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} | |
| GH_TOKEN: ${{ github.token }} | |
| name: deploy | |
| steps: | |
| - uses: actions/checkout@v6 | |
| with: | |
| fetch-depth: 0 | |
| lfs: false | |
| - name: Download ONNX model from release | |
| run: | | |
| mkdir -p packages/api/services/story-search/model | |
| curl -L -o packages/api/services/story-search/model/efficientnet_b0_comic_embedding.onnx \ | |
| https://github.com/ducksmanager/core/releases/download/v1.0.0-model/efficientnet_b0_comic_embedding.onnx | |
| - name: Log in to the Container registry | |
| uses: docker/login-action@v4 | |
| with: | |
| registry: ghcr.io | |
| username: bperel | |
| password: ${{ secrets.DOCKER_REGISTRY_TOKEN_DM }} | |
| - name: Derive appropriate SHAs for base and head for `nx affected` commands | |
| uses: nrwl/nx-set-shas@v5 | |
| with: | |
| main-branch-name: master | |
| - run: | | |
| echo "HEAD: ${{ env.NX_HEAD }}" | |
| echo "BASE: ${{ env.NX_BASE }}" | |
| - name: Install pnpm | |
| uses: pnpm/action-setup@v6 | |
| with: | |
| version: 9.8.0 | |
| - name: Use Node.js 26 | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: 26 | |
| cache: "pnpm" | |
| - uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: 1.3.x | |
| - name: Compute affected packages | |
| run: | | |
| lastSuccessfulCommit=${{ env.NX_BASE }} | |
| echo "lastSuccessfulCommit=$lastSuccessfulCommit" >> "$GITHUB_ENV" | |
| pnpm i -g "turbo@$(node -p "require('./package.json').devDependencies.turbo")" | |
| allPackages=$(turbo ls --output=json) | |
| # Files outside every workspace package are invisible to turbo's change | |
| # detection, so treat them as affecting everything. | |
| packageRegex="^($(echo "$allPackages" | jq -r '.packages.items[].path' | paste -sd'|' -))/" | |
| if changedFiles=$(git diff --name-only "$lastSuccessfulCommit" "${{ env.NX_HEAD }}"); then | |
| rootChanges=$(echo "$changedFiles" \ | |
| | grep -vE "$packageRegex" \ | |
| | grep -vE '^(\.github|\.husky|\.vscode|\.claude)/|^(README\.md|LICENSE|keybindings\.json)$' || true) | |
| else | |
| echo "Could not diff $lastSuccessfulCommit against ${{ env.NX_HEAD }}." | |
| rootChanges="(diff unavailable)" | |
| fi | |
| if [ "${{ inputs.force_all }}" == "true" ]; then | |
| echo "force_all requested, selecting every package:" | |
| packages=$(echo "$allPackages" | jq -r '.packages.items[].name') | |
| elif [ -n "$rootChanges" ]; then | |
| echo "Root-level changes affect every package:" | |
| echo "$rootChanges" | sed 's/^/ /' | |
| packages=$(echo "$allPackages" | jq -r '.packages.items[].name') | |
| else | |
| echo "Packages affected since $lastSuccessfulCommit:" | |
| packages=$(turbo ls -F "...[$lastSuccessfulCommit]" --output=json | jq -r '.packages.items[].name') | |
| fi | |
| packages=$(echo "$packages" | grep -vE '^(~ci|~duckguessr-api|~monitoring-grafana)$' || true) | |
| echo "${packages:-(none)}" | |
| if [ -z "$packages" ]; then | |
| echo "has_affected=false" >> "$GITHUB_ENV" | |
| else | |
| echo "has_affected=true" >> "$GITHUB_ENV" | |
| echo "TURBO_FILTERS=$(echo "$packages" | sed 's/^/-F /' | tr '\n' ' ')" >> "$GITHUB_ENV" | |
| fi | |
| - name: Install dependencies | |
| if: env.has_affected == 'true' | |
| env: | |
| PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: "1" | |
| run: | | |
| pnpm -r i --config.platform=linux --config.architecture=x64 | |
| - name: Retrieve pre-build files | |
| if: env.has_affected == 'true' | |
| run: | | |
| ./node_modules/.bin/turbo prod:transfer-files-pre | |
| - uses: docker/setup-buildx-action@v4 | |
| if: env.has_affected == 'true' | |
| - name: Build apps | |
| if: env.has_affected == 'true' | |
| run: | | |
| ./node_modules/.bin/turbo $TURBO_FILTERS build prod:build-docker | |
| - name: Send post-build files | |
| if: env.has_affected == 'true' | |
| run: | | |
| ./node_modules/.bin/turbo $TURBO_FILTERS prod:transfer-files-post | |
| - name: Deploy | |
| if: env.has_affected == 'true' | |
| run: | | |
| ./node_modules/.bin/turbo --concurrency=1 $TURBO_FILTERS prod:deploy |