Skip to content

fix(desktop): restore Home and Browser release contracts (#1567) #494

fix(desktop): restore Home and Browser release contracts (#1567)

fix(desktop): restore Home and Browser release contracts (#1567) #494

Workflow file for this run

name: Deploy Web Surfaces
# Merged = deployed for the web tier. The desktop/iOS release workflow never
# touches these five surfaces (hosted web client on Cloudflare Pages + four
# Workers), which let production drift silently in the past. Push-to-main
# deploys exactly the surfaces whose code changed; workflow_dispatch deploys
# everything (manual full reconcile). Secrets are never exposed to fork PRs
# because this only runs on push to main and manual dispatch.
on:
push:
branches: [main]
paths:
- "apps/desktop/src/renderer/**"
- "apps/desktop/src/shared/**"
- "apps/desktop/vite.webclient.config.ts"
- "apps/account-directory/**"
- "apps/webhook-relay/**"
- "apps/tunnel-relay/**"
- "apps/push-relay/**"
- ".github/workflows/deploy-web.yml"
workflow_dispatch:
permissions:
contents: read
concurrency:
group: deploy-web
cancel-in-progress: false
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
jobs:
changes:
runs-on: ubuntu-latest
outputs:
webclient: ${{ steps.filter.outputs.webclient }}
account-directory: ${{ steps.filter.outputs.account-directory }}
webhook-relay: ${{ steps.filter.outputs.webhook-relay }}
tunnel-relay: ${{ steps.filter.outputs.tunnel-relay }}
push-relay: ${{ steps.filter.outputs.push-relay }}
steps:
- uses: actions/checkout@v4
- uses: dorny/paths-filter@v3
id: filter
with:
filters: |
webclient:
- "apps/desktop/src/renderer/**"
- "apps/desktop/src/shared/**"
- "apps/desktop/vite.webclient.config.ts"
account-directory:
- "apps/account-directory/**"
webhook-relay:
- "apps/webhook-relay/**"
tunnel-relay:
- "apps/tunnel-relay/**"
push-relay:
- "apps/push-relay/**"
webclient:
needs: changes
if: needs.changes.outputs.webclient == 'true' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- name: Install desktop dependencies
run: cd apps/desktop && npm ci
- name: Build web client
run: cd apps/desktop && npm run build:webclient
- name: Deploy to Cloudflare Pages
run: npx wrangler@4 pages deploy apps/desktop/dist/web-client --project-name ade-web-client --branch main --commit-hash "$GITHUB_SHA" --commit-dirty=false
- name: Verify live bundle
run: |
built="$(basename apps/desktop/dist/web-client/assets/index-*.js)"
for i in 1 2 3 4 5 6; do
live="$(curl -fsS https://app.ade-app.dev | grep -oE 'index-[A-Za-z0-9_-]+\.js' | head -1 || true)"
[ "$built" = "$live" ] && { echo "verified: $live"; exit 0; }
echo "waiting for propagation ($i): built=$built live=$live"; sleep 20
done
echo "::error::deployed bundle did not propagate (built=$built live=$live)"; exit 1
account-directory:
needs: changes
if: needs.changes.outputs.account-directory == 'true' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- run: cd apps/account-directory && npm ci
- name: Apply D1 migrations and deploy production Worker
run: cd apps/account-directory && npm run deploy:production
- name: Verify health
run: curl -fsS https://ade-account-directory-production.arulsharma1028.workers.dev/health | grep -q '"ok":true'
webhook-relay:
needs: changes
if: needs.changes.outputs.webhook-relay == 'true' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- run: cd apps/webhook-relay && npm ci
- name: Deploy Worker
run: cd apps/webhook-relay && npm run deploy
tunnel-relay:
needs: changes
if: needs.changes.outputs.tunnel-relay == 'true' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- run: cd apps/tunnel-relay && npm ci
- name: Deploy Worker
run: cd apps/tunnel-relay && npm run deploy -- --tag "$GITHUB_SHA" --message "main $GITHUB_SHA"
- name: Verify deployed protocol and Worker version
run: |
for attempt in {1..18}; do
health="$(curl -fsS https://ade-tunnel-relay.arulsharma1028.workers.dev/health || true)"
if HEALTH_JSON="$health" EXPECTED_SHA="$GITHUB_SHA" node -e '
try {
const value = JSON.parse(process.env.HEALTH_JSON);
const valid = value.ok === true
&& value.service === "ade-tunnel-relay"
&& value.protocolVersion === 2
&& value.workerVersion?.tag === process.env.EXPECTED_SHA;
process.exit(valid ? 0 : 1);
} catch {
process.exit(1);
}
'; then
echo "verified tunnel relay protocol v2 at Worker tag $GITHUB_SHA"
exit 0
fi
echo "waiting for tunnel relay deployment propagation ($attempt/18)"
sleep 10
done
echo "::error::tunnel relay health did not reach protocol v2 at Worker tag $GITHUB_SHA"
exit 1
push-relay:
needs: changes
if: needs.changes.outputs.push-relay == 'true' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- run: cd apps/push-relay && npm ci
- name: Mint Clerk smoke tokens and deploy Worker
env:
CLERK_PROD_SECRET_KEY: ${{ secrets.CLERK_PROD_SECRET_KEY }}
CLERK_PROD_PUBLISHABLE_KEY: ${{ secrets.CLERK_PROD_PUBLISHABLE_KEY }}
ADE_PUSH_RELAY_SMOKE_USER_ID: ${{ secrets.ADE_PUSH_RELAY_SMOKE_USER_ID }}
CLERK_SECRET_KEY: ${{ secrets.CLERK_SECRET_KEY }}
CLERK_PUBLISHABLE_KEY: ${{ secrets.CLERK_PUBLISHABLE_KEY }}
ADE_PUSH_RELAY_SECONDARY_SMOKE_USER_ID: ${{ secrets.ADE_PUSH_RELAY_SECONDARY_SMOKE_USER_ID }}
run: cd apps/push-relay && npm run deploy:ci