Repository navigation
128 lines (121 loc) · 5.27 KB
/
Copy pathdeploy.yml
File metadata and controls
128 lines (121 loc) · 5.27 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
name: Deploy
# Deploys both surfaces on push to main:
# - Worker → contextmem-backend (API/MCP backend)
# - Pages → contextmem.pages.dev (web frontend)
#
# OFF BY DEFAULT: both jobs are gated on the repo VARIABLE `DEPLOY_ENABLED == 'true'`,
# so a fork/clone without Cloudflare credentials shows these jobs as *skipped*
# (green CI) instead of failing red. You can always deploy manually with
# `wrangler deploy` / `wrangler pages deploy`.
#
# To turn ON CI auto-deploy:
# 1. Create a Cloudflare API token with: Workers Scripts:Edit, Cloudflare Pages:Edit,
# D1:Edit, Workers R2 Storage:Edit, Workers KV:Edit, Queues:Edit,
# Account Settings:Read, and User Details:Read.
# 2. Add repo SECRETS: CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID,
# CONTEXTMEM_NAMESPACE_IMPORT_TOKEN (pushed as a Worker secret).
# 3. Add repo VARIABLE: DEPLOY_ENABLED = true.
# Other Worker secrets are managed in the Cloudflare dashboard (not pushed by CI):
# FIRECRAWL_API_KEY, MEMWAL_ACCOUNT_ID, MEMWAL_API_URL, MEMWAL_PRIVATE_KEY, TATUM_API_KEY
# Optional repo variable: CONTEXTMEM_API_BASE (worker URL the web build points at).
# When CI deploy is ON, DISABLE Cloudflare Git auto-deploy for Pages (avoids double-deploys).
on:
push:
branches: [main, staging]
workflow_dispatch:
concurrency:
group: deploy-${{ github.ref }}
cancel-in-progress: false
jobs:
deploy-worker:
runs-on: ubuntu-latest
if: ${{ vars.DEPLOY_ENABLED == 'true' && github.ref == 'refs/heads/main' }}
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.6
- run: bun install --frozen-lockfile
- name: Deploy Worker
uses: cloudflare/wrangler-action@v3
with:
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
workingDirectory: apps/api/cloudflare
# Force bun: this is a bun workspace, npm chokes on `workspace:*` deps
# (EUNSUPPORTEDPROTOCOL) when wrangler-action tries to self-install.
packageManager: bun
wranglerVersion: "4.95.0"
command: deploy
secrets: |
CONTEXTMEM_NAMESPACE_IMPORT_TOKEN
env:
CONTEXTMEM_NAMESPACE_IMPORT_TOKEN: ${{ secrets.CONTEXTMEM_NAMESPACE_IMPORT_TOKEN }}
deploy-pages:
runs-on: ubuntu-latest
if: ${{ vars.DEPLOY_ENABLED == 'true' && github.ref == 'refs/heads/main' }}
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.6
- run: bun install --frozen-lockfile
- name: Build web
run: bun run --filter @contextmem/web build
env:
VITE_CONTEXTMEM_API_BASE: ${{ vars.CONTEXTMEM_API_BASE || 'https://contextmem-backend.petlofi.workers.dev' }}
- name: Deploy Pages
uses: cloudflare/wrangler-action@v3
with:
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
packageManager: bun
wranglerVersion: "4.95.0"
command: pages deploy apps/web/dist --project-name=contextmem --branch=main
# ── Staging (push to `staging` branch) ────────────────────────────────
# Deploys the isolated staging Worker (env.staging in wrangler.jsonc) and a
# `staging` preview deployment on the same Pages project.
# One-time setup before the first staging deploy:
# 1. Create resources (see commands in PR/README), put the D1 id in wrangler.jsonc.
# 2. Push the staging Worker secret once:
# echo "<token>" | bunx wrangler@4.95.0 secret put CONTEXTMEM_NAMESPACE_IMPORT_TOKEN \
# --env staging --config apps/api/cloudflare/wrangler.jsonc
deploy-worker-staging:
runs-on: ubuntu-latest
if: ${{ vars.DEPLOY_ENABLED == 'true' && github.ref == 'refs/heads/staging' }}
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.6
- run: bun install --frozen-lockfile
- name: Deploy Worker (staging)
uses: cloudflare/wrangler-action@v3
with:
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
workingDirectory: apps/api/cloudflare
packageManager: bun
wranglerVersion: "4.95.0"
command: deploy --env staging
deploy-pages-staging:
runs-on: ubuntu-latest
if: ${{ vars.DEPLOY_ENABLED == 'true' && github.ref == 'refs/heads/staging' }}
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.6
- run: bun install --frozen-lockfile
- name: Build web (staging)
run: bun run --filter @contextmem/web build
env:
VITE_CONTEXTMEM_API_BASE: ${{ vars.CONTEXTMEM_API_BASE_STAGING || 'https://contextmem-backend-staging.petlofi.workers.dev' }}
- name: Deploy Pages (staging)
uses: cloudflare/wrangler-action@v3
with:
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
packageManager: bun
wranglerVersion: "4.95.0"
command: pages deploy apps/web/dist --project-name=contextmem --branch=staging