From 8aead29e78eb22adcc11469cc424bb10c8aab9d4 Mon Sep 17 00:00:00 2001 From: Teodor Calin Date: Thu, 28 May 2026 13:33:52 -0700 Subject: [PATCH] ci: add Cloudflare Pages deploy step to ci.yml MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Restores automated deployment for the production site at pilotprotocol.pages.dev. The deploy was lost when deploy-website.yml was removed (PILOT-169) and never re-wired after the web4 → website split. The new step runs only on push-to-main (forks/PRs are skipped — they don't have the secrets and shouldn't publish to production anyway). Uses cloudflare/wrangler-action@v3 with the new CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID secrets now configured on this repo. --- .github/workflows/ci.yml | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 61116c6c..3b71e657 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -8,6 +8,8 @@ on: permissions: contents: read + # Required by wrangler-action for OIDC / deployments comment posting. + deployments: write jobs: build: @@ -30,3 +32,24 @@ jobs: name: site-build path: dist/ retention-days: 7 + + # Deploy to Cloudflare Pages: + # - push to main → production (pilotprotocol.pages.dev) + # - PR from internal branch → preview (.pilotprotocol.pages.dev) + # - PR from a fork → skipped (no secret access on forks) + - name: Deploy to Cloudflare Pages + if: | + github.event_name == 'push' || + (github.event_name == 'pull_request' && + github.event.pull_request.head.repo.full_name == github.repository) + uses: cloudflare/wrangler-action@v3 + with: + apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }} + accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} + # Cloudflare treats branch=main as production, anything else + # as a preview environment with a branch-keyed subdomain. + command: >- + pages deploy dist + --project-name=pilotprotocol + --branch=${{ github.event_name == 'push' && 'main' || github.head_ref }} + --commit-dirty=true