Files
ever-gauzy/.github/workflows/deploy-render-demo.yml
Ruslan KonviserandClaude Fable 5 0caa9ae72c ci: only the newest commit builds — supersede policy across all 67 workflows
Four merges to develop this morning left five superseded runs building dead
commits while the branch head waited. Applied one policy, per class:

- build.yml: cancel-in-progress was `github.event_name == 'pull_request'`, so
  branch pushes never superseded each other — every merge started its own 3-h
  compile. Now true for all events; it writes nothing outside the run.
- release-{demo,stage,prod}: made the release ATOMIC so it becomes safe to
  supersede. `github-tag-action` now runs with dry_run (calculate only) and
  `ncipollo/release-action` creates the tag AND the release in one call with
  `commit: github.sha`. Previously the tag was pushed by an earlier step, so a
  cancelled run stranded a tag with no release forever (the next run computes the
  NEXT version and never backfills). With that window gone: cancel-in-progress true.
- 6 non-prod image builds: now supersede within their own workflow+ref, matching
  what the prod image builds already did. Group stays per-workflow — the shared
  `gauzy-docker-build` group is what starved them before. Trade-off documented in
  the file: an intermediate version tag may end up without an image, which is inert
  because demo/stage deploy from :latest.
- 26 deploy workflows had NO concurrency key at all, so every merge queued its own
  deploy. They now share a group per workflow+ref with cancel-in-progress FALSE:
  superseded PENDING runs collapse to the newest, but a rollout already applying is
  never interrupted.

Left alone deliberately: cache-janitor and external-uptime-monitor (cron probes,
must not cancel each other) and harvest-secrets-to-openbao (manual only).

Every file parses as YAML; the classification came from reading each workflow's
steps for external side effects, not from its name.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-20 14:24:27 +02:00

57 lines
1.8 KiB
YAML

name: Deploy to Render Demo
on:
workflow_run:
workflows: ['Build and Publish Docker Images Demo']
branches:
- render
types:
- completed
# Least-privilege scope for the automatic GITHUB_TOKEN.
# This workflow only builds/tests/deploys from a checkout — read access is sufficient.
concurrency:
# Collapse superseded runs WITHOUT interrupting one that is already applying: GitHub
# keeps a single pending run per group, so a newer commit replaces the one waiting
# while the in-flight deploy finishes. `cancel-in-progress: true` is deliberately NOT
# used here — killing a rollout mid-apply can leave the target half-updated.
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
permissions:
contents: read
jobs:
deploy-demo:
runs-on: ${{ vars.RUNNER_LINUX_X64_4 || 'ubuntu-latest' }}
timeout-minutes: 300
environment: demo
steps:
- name: Checkout code
uses: actions/checkout@v5
- name: Set up Render CLI
run: |
wget -O render https://github.com/render-oss/render-cli/releases/download/v0.1.8/render-linux-x86_64
chmod +x render
sudo mv render /usr/local/bin/render
mkdir ~/.render
cat << EOF > ~/.render/config.yaml
version: 1
sshPreserveHosts: true
profiles:
default:
defaultRegion: oregon
apiKey: ${{ secrets.RENDER_API_KEY }}
demo:
defaultRegion: oregon
apiKey: ${{ secrets.RENDER_API_KEY }}
EOF
- name: Deploy Services
run: |
cp .render/render.demo.yaml ./render.yaml
render blueprint launch --profile demo