mirror of
https://github.com/ever-co/ever-gauzy.git
synced 2026-10-02 01:54:50 +08:00
Four merges to develop this morning left five superseded runs building dead
commits while the branch head waited. Applied one policy, per class:
- build.yml: cancel-in-progress was `github.event_name == 'pull_request'`, so
branch pushes never superseded each other — every merge started its own 3-h
compile. Now true for all events; it writes nothing outside the run.
- release-{demo,stage,prod}: made the release ATOMIC so it becomes safe to
supersede. `github-tag-action` now runs with dry_run (calculate only) and
`ncipollo/release-action` creates the tag AND the release in one call with
`commit: github.sha`. Previously the tag was pushed by an earlier step, so a
cancelled run stranded a tag with no release forever (the next run computes the
NEXT version and never backfills). With that window gone: cancel-in-progress true.
- 6 non-prod image builds: now supersede within their own workflow+ref, matching
what the prod image builds already did. Group stays per-workflow — the shared
`gauzy-docker-build` group is what starved them before. Trade-off documented in
the file: an intermediate version tag may end up without an image, which is inert
because demo/stage deploy from :latest.
- 26 deploy workflows had NO concurrency key at all, so every merge queued its own
deploy. They now share a group per workflow+ref with cancel-in-progress FALSE:
superseded PENDING runs collapse to the newest, but a rollout already applying is
never interrupted.
Left alone deliberately: cache-janitor and external-uptime-monitor (cron probes,
must not cancel each other) and harvest-secrets-to-openbao (manual only).
Every file parses as YAML; the classification came from reading each workflow's
steps for external side effects, not from its name.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
57 lines
1.8 KiB
YAML
57 lines
1.8 KiB
YAML
name: Deploy to Render Demo
|
|
|
|
on:
|
|
workflow_run:
|
|
workflows: ['Build and Publish Docker Images Demo']
|
|
branches:
|
|
- render
|
|
types:
|
|
- completed
|
|
|
|
# Least-privilege scope for the automatic GITHUB_TOKEN.
|
|
# This workflow only builds/tests/deploys from a checkout — read access is sufficient.
|
|
concurrency:
|
|
# Collapse superseded runs WITHOUT interrupting one that is already applying: GitHub
|
|
# keeps a single pending run per group, so a newer commit replaces the one waiting
|
|
# while the in-flight deploy finishes. `cancel-in-progress: true` is deliberately NOT
|
|
# used here — killing a rollout mid-apply can leave the target half-updated.
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: false
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
deploy-demo:
|
|
runs-on: ${{ vars.RUNNER_LINUX_X64_4 || 'ubuntu-latest' }}
|
|
timeout-minutes: 300
|
|
|
|
environment: demo
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v5
|
|
|
|
- name: Set up Render CLI
|
|
run: |
|
|
wget -O render https://github.com/render-oss/render-cli/releases/download/v0.1.8/render-linux-x86_64
|
|
chmod +x render
|
|
sudo mv render /usr/local/bin/render
|
|
mkdir ~/.render
|
|
cat << EOF > ~/.render/config.yaml
|
|
version: 1
|
|
sshPreserveHosts: true
|
|
profiles:
|
|
default:
|
|
defaultRegion: oregon
|
|
apiKey: ${{ secrets.RENDER_API_KEY }}
|
|
demo:
|
|
defaultRegion: oregon
|
|
apiKey: ${{ secrets.RENDER_API_KEY }}
|
|
EOF
|
|
|
|
- name: Deploy Services
|
|
run: |
|
|
cp .render/render.demo.yaml ./render.yaml
|
|
render blueprint launch --profile demo
|