Skip to content

ci: route all workflows homeserver-first with GitHub-hosted fallback #45

ci: route all workflows homeserver-first with GitHub-hosted fallback

ci: route all workflows homeserver-first with GitHub-hosted fallback #45

Workflow file for this run

name: Branding site
on:
pull_request:
paths:
- "branding/**"
- ".github/workflows/pages.yml"
push:
branches:
- main
paths:
- "branding/**"
- ".github/workflows/pages.yml"
workflow_dispatch:
permissions:
contents: read
# The ci-target router dispatches the ci-heartbeat canary with
# GITHUB_TOKEN, and a called reusable workflow can never exceed the
# caller's envelope -- under-granting it startup-fails the whole run
# as "Invalid workflow file". The deploy job keeps its own narrower
# job-level envelope (pages: write, id-token: write).
actions: write
concurrency:
group: pages
cancel-in-progress: false
jobs:
# Executor routing ("homeserver first, GitHub-hosted fallback") via the
# shared ci-router.yml -- same trust gate and heartbeat liveness proof
# quality.yml's ci-target job documents. The build's whole runtime is
# checkout files plus a stdlib python script and an artifact upload, so
# it is executor-agnostic and simply picks runs-on off the router
# output; on fallback days it reports under the "(GitHub-hosted)"
# suffixed name per quality.yml's pair-naming rule.
ci-target:
name: Pick CI executor
uses: ./.github/workflows/ci-router.yml
with:
ci_homeserver_prs: ${{ vars.CI_HOMESERVER_PRS || '' }}
build:
name: Build Pages artifact${{ needs.ci-target.outputs.homeserver != 'true' && ' (GitHub-hosted)' || '' }}
needs: [ci-target]
runs-on: ${{ needs.ci-target.outputs.homeserver == 'true' && fromJSON('["self-hosted", "linux", "x64", "honeypot-ci"]') || fromJSON('["ubuntu-latest"]') }}
timeout-minutes: ${{ needs.ci-target.outputs.homeserver == 'true' && 15 || 360 }}
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Configure Pages
uses: actions/configure-pages@v6
- name: Build branding site
run: python branding/scripts/build_pages_site.py --output _site
- name: Upload Pages artifact
uses: actions/upload-pages-artifact@v5
with:
path: _site
# Stays GitHub-hosted unconditionally: it is a seconds-long API call
# against the github-pages environment (no compute to relocate), and
# routing it through the heartbeat would only add a router leg between
# the artifact upload above and the deploy.
deploy:
name: Deploy Pages
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
needs: build
permissions:
pages: write
id-token: write
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
runs-on: ubuntu-latest
steps:
- name: Deploy Pages
id: deployment
uses: actions/deploy-pages@v5