ci: route all workflows homeserver-first with GitHub-hosted fallback #45
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Branding site | |
| on: | |
| pull_request: | |
| paths: | |
| - "branding/**" | |
| - ".github/workflows/pages.yml" | |
| push: | |
| branches: | |
| - main | |
| paths: | |
| - "branding/**" | |
| - ".github/workflows/pages.yml" | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| # The ci-target router dispatches the ci-heartbeat canary with | |
| # GITHUB_TOKEN, and a called reusable workflow can never exceed the | |
| # caller's envelope -- under-granting it startup-fails the whole run | |
| # as "Invalid workflow file". The deploy job keeps its own narrower | |
| # job-level envelope (pages: write, id-token: write). | |
| actions: write | |
| concurrency: | |
| group: pages | |
| cancel-in-progress: false | |
| jobs: | |
| # Executor routing ("homeserver first, GitHub-hosted fallback") via the | |
| # shared ci-router.yml -- same trust gate and heartbeat liveness proof | |
| # quality.yml's ci-target job documents. The build's whole runtime is | |
| # checkout files plus a stdlib python script and an artifact upload, so | |
| # it is executor-agnostic and simply picks runs-on off the router | |
| # output; on fallback days it reports under the "(GitHub-hosted)" | |
| # suffixed name per quality.yml's pair-naming rule. | |
| ci-target: | |
| name: Pick CI executor | |
| uses: ./.github/workflows/ci-router.yml | |
| with: | |
| ci_homeserver_prs: ${{ vars.CI_HOMESERVER_PRS || '' }} | |
| build: | |
| name: Build Pages artifact${{ needs.ci-target.outputs.homeserver != 'true' && ' (GitHub-hosted)' || '' }} | |
| needs: [ci-target] | |
| runs-on: ${{ needs.ci-target.outputs.homeserver == 'true' && fromJSON('["self-hosted", "linux", "x64", "honeypot-ci"]') || fromJSON('["ubuntu-latest"]') }} | |
| timeout-minutes: ${{ needs.ci-target.outputs.homeserver == 'true' && 15 || 360 }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Configure Pages | |
| uses: actions/configure-pages@v6 | |
| - name: Build branding site | |
| run: python branding/scripts/build_pages_site.py --output _site | |
| - name: Upload Pages artifact | |
| uses: actions/upload-pages-artifact@v5 | |
| with: | |
| path: _site | |
| # Stays GitHub-hosted unconditionally: it is a seconds-long API call | |
| # against the github-pages environment (no compute to relocate), and | |
| # routing it through the heartbeat would only add a router leg between | |
| # the artifact upload above and the deploy. | |
| deploy: | |
| name: Deploy Pages | |
| if: github.event_name == 'push' || github.event_name == 'workflow_dispatch' | |
| needs: build | |
| permissions: | |
| pages: write | |
| id-token: write | |
| environment: | |
| name: github-pages | |
| url: ${{ steps.deployment.outputs.page_url }} | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Deploy Pages | |
| id: deployment | |
| uses: actions/deploy-pages@v5 |