-
Notifications
You must be signed in to change notification settings - Fork 3
184 lines (161 loc) · 6.63 KB
/
Copy pathdeploy-docs.yml
File metadata and controls
184 lines (161 loc) · 6.63 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
name: Deploy Docs
on:
# After CI, not alongside it. A push triggers both at once, so a commit
# that failed its checks would still publish.
workflow_run:
workflows: ["CI"]
types: [completed]
branches: [main]
workflow_dispatch:
concurrency:
group: pages
cancel-in-progress: false
permissions:
contents: read
jobs:
build:
# Only a commit CI validated. workflow_run fires whatever the conclusion
# was, so the conclusion is checked rather than assumed, and a manual
# dispatch is allowed through deliberately.
if: >-
github.event_name == 'workflow_dispatch'
|| github.event.workflow_run.conclusion == 'success'
runs-on: ubuntu-latest
permissions:
contents: read
pages: write
id-token: write
steps:
# The run that validated this commit, not whatever main happens to be.
# Between CI finishing and this starting, main can have moved.
- name: Establish the commit CI validated
id: validated
env:
EVENT: ${{ github.event_name }}
RUN_SHA: ${{ github.event.workflow_run.head_sha }}
run: |
set -euo pipefail
if [ "${EVENT}" = "workflow_dispatch" ]; then
echo "sha=${GITHUB_SHA}" >> "$GITHUB_OUTPUT"
echo "dispatched by hand; publishing ${GITHUB_SHA}"
exit 0
fi
if [ -z "${RUN_SHA}" ]; then
echo "::error::No commit on the triggering run, so nothing is known to be validated"
exit 1
fi
echo "sha=${RUN_SHA}" >> "$GITHUB_OUTPUT"
echo "publishing ${RUN_SHA}, validated by run ${{ github.event.workflow_run.id }}"
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: ${{ steps.validated.outputs.sha }}
# Evidence rather than inference: the codegen artifact exists only if that
# run produced it for this commit. Absent, there is nothing to show CI
# ever saw this tree, so publishing stops.
- name: Take the evidence from the run that validated it
if: github.event_name != 'workflow_dispatch'
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: codegen-output
path: ${{ runner.temp }}/ci-evidence
run-id: ${{ github.event.workflow_run.id }}
github-token: ${{ github.token }}
- name: Confirm the tree is the one that was validated
env:
EXPECTED: ${{ steps.validated.outputs.sha }}
run: |
set -euo pipefail
actual="$(git rev-parse HEAD)"
if [ "${actual}" != "${EXPECTED}" ]; then
echo "::error::Checked out ${actual}, but CI validated ${EXPECTED}"
exit 1
fi
echo "publishing ${actual}, which is the commit CI validated"
- uses: dtolnay/rust-toolchain@5b842231ba77f5c045dba54ac5560fed2db780e2 # stable
with:
toolchain: stable
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
- name: Configure Pages
id: pages
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
- uses: ./.github/actions/rust-nightly
with:
components: rustfmt
# codegen.sh is the same work as ci.yml's codegen job, which owns the
# cache. The key hashes the default toolchain, so this runs after
# nightly, as it does there.
- uses: ./.github/actions/rust-cache
with:
shared-key: codegen
save: "false"
- name: Install workspace dependencies
run: npm ci
- name: Run codegen (cargo + rust → ts + truapi build + dts bundle)
run: ./scripts/codegen.sh
- name: Build Rust API docs (HTML)
run: cargo doc -p truapi --no-deps
- name: Install playground dependencies
working-directory: playground
run: yarn install --frozen-lockfile
- name: Cache Next.js build
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: playground/.next/cache
key: ${{ runner.os }}-nextjs-${{ hashFiles('playground/yarn.lock') }}-${{ hashFiles('playground/src/**', 'playground/scripts/**', 'playground/public/**', 'playground/next.config.js', 'playground/tsconfig.json', 'playground/package.json') }}
restore-keys: |
${{ runner.os }}-nextjs-${{ hashFiles('playground/yarn.lock') }}-
- name: Build playground (static export)
working-directory: playground
env:
NEXT_PUBLIC_BASE_PATH: ${{ steps.pages.outputs.base_path }}/playground
run: yarn build
- name: Install explorer dependencies
working-directory: explorer
run: npm ci
- name: Build explorer (static export)
working-directory: explorer
env:
EXPLORER_BASE_PATH: ${{ steps.pages.outputs.base_path }}/
run: npm run build
- name: Assemble GitHub Pages site
run: |
rm -rf site
mkdir -p site
# Explorer SPA at the site root.
cp -R explorer/dist/. site/
# GitHub Pages serves the site-root 404.html for every missing path.
# Serving a copy of the SPA index lets React Router resolve explorer
# deep links (e.g. /trinity-user-agents/v/main/method/foo) on a fresh load.
cp site/index.html site/404.html
# Playground mounted at /playground/ (its Next.js basePath).
mkdir -p site/playground
cp -R playground/out/. site/playground/
# truapi crate's cargo doc mounted at /cargo_doc/ with the crate's
# pages flattened (no /truapi/ prefix). rustdoc HTMLs reference
# static.files via `../../../static.files/`, which from
# /cargo_doc/api/<mod>/ resolves to the site root, so static.files
# must be a sibling of cargo_doc/ (not inside it).
mkdir -p site/cargo_doc
cp -RL target/doc/truapi/. site/cargo_doc/
cp -RL target/doc/static.files site/static.files
touch site/.nojekyll
- name: Upload Pages artifact
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
with:
path: site
deploy:
needs: build
runs-on: ubuntu-latest
permissions:
pages: write
id-token: write
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1