Repository navigation
Limit the permission mode a machine will run (#946) #17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy Connect | |
| on: | |
| push: | |
| branches: | |
| - main | |
| paths: | |
| - "apps/connect/**" | |
| - "packages/connect-db/**" | |
| - "packages/tunnel-contract/**" | |
| workflow_dispatch: | |
| env: | |
| NODE_VERSION: "22.x" | |
| PNPM_VERSION: "9.15.0" | |
| permissions: | |
| contents: read | |
| # Shared group with deploy-web so the two never run `wrangler d1 migrations | |
| # apply` concurrently against the same prod D1: a parallel double-apply would | |
| # fail on already-applied SQL (e.g. 0005's CREATE TRIGGER). Serializing the | |
| # two workflows makes the second run's migrate step a tracked no-op. | |
| # cancel-in-progress:false so a queued deploy waits rather than being dropped. | |
| concurrency: | |
| group: connect-db-deploy-${{ github.ref }} | |
| cancel-in-progress: false | |
| jobs: | |
| deploy: | |
| name: Deploy tunnel gate to Cloudflare Workers | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Set up pnpm | |
| uses: pnpm/action-setup@v4 | |
| with: | |
| version: ${{ env.PNPM_VERSION }} | |
| run_install: false | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: pnpm | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile --prefer-offline | |
| # Apply any pending connect-db migrations BEFORE the new worker ships so | |
| # it never queries columns prod D1 doesn't have yet. The d1_migrations | |
| # tracking table (seeded 2026-07-08 with the previously hand-applied | |
| # chain) makes this a no-op when nothing is pending. | |
| - name: Apply connect-db migrations | |
| env: | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| run: pnpm --filter @bb/connect exec wrangler d1 migrations apply DB --remote | |
| # No build step: the gate is a single worker entry (src/worker.ts) and | |
| # wrangler's esbuild bundles its workspace deps (@bb/connect-db, | |
| # @bb/tunnel-contract) straight from source. Plain `wrangler deploy` | |
| # uses the top-level (production) config -> the bb-connect worker on | |
| # *.getbb.app. BETTER_AUTH_SECRET is set once by hand (it must equal | |
| # bb-web's) and is intentionally NOT synced from CI. | |
| - name: Deploy tunnel gate | |
| env: | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| run: pnpm --filter @bb/connect exec wrangler deploy |