Match deploy.yml (merged in #46): bump ci.yml pnpm 10->11 and Node 22->26 so CI and CD build in the same environment. Actions stay pinned to their latest release SHAs (unchanged); Go 1.26 + TinyGo 0.41.1 latest. actionlint clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Set pnpm to 11 and Node to 26. Verified every action is pinned to its latest release commit SHA with the correct version comment (checkout v7.0.0, setup-go v6.5.0, setup-tinygo v3.0.0, pnpm/action-setup v6.0.9, setup-node v6.4.0, pulumi/actions v7.0.0); Go 1.26 and TinyGo 0.41.1 are the latest.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a manual, workflow_dispatch-only CD workflow and close the infra
binding-wiring gap (#9) so the deployed Worker is actually functional.
Deliverable 1 - .github/workflows/deploy.yml:
- workflow_dispatch only, with a `stack` choice input (default prod).
- Gated to the `production` GitHub Actions environment and to the main
branch (guard step fails otherwise); no push/PR trigger.
- Reuses ci.yml's Go 1.26 + TinyGo + pnpm setup and the TinyGo net/http
patch, builds the Wasm Worker (pnpm run build), then runs pulumi up over
infra/ via pulumi/actions, injecting the built ../build/worker.mjs as the
workerScriptPath config. Provider/backend creds come from environment
secrets (nothing committed). All actions pinned by commit SHA; actionlint
clean.
Deliverable 2 - infra/deploy.go binding wiring (#9):
- WorkersScript now carries the R2 bucket binding (REPORTS_BUCKET), the four
Secrets Store bindings (BUGREPORT_ENC_KEYRING, ADMIN_TOKEN, GITHUB_TOKEN,
OTEL_EXPORTER_OTLP_HEADERS), and the plain vars (GITHUB_REPO, OTEL_*),
matching wrangler.jsonc and the Worker runtime contract.
- New WorkersCronTrigger resource registers the two Friday UTC crons (#13),
bound to the Worker.
- Real built artifact wired via ContentFile + computed ContentSha256 when
the workerScriptPath config is set; documented placeholder otherwise
(keeps the program testable without the artifact, as #2 did).
- secretsStoreId is a new required config; git rate-limit ruleset insertion
point (#6/#7) kept reserved.
- Extended the WithMocks tests to assert the R2 + Secrets Store + var
bindings, the crons, and the artifact ContentFile/ContentSha256 path.
- Updated Pulumi.<stack>.yaml and infra/README.md with the full
secret/config list and how a maintainer triggers the deploy.
Verified in infra/: go build, go vet, go test all green; actionlint clean
on deploy.yml. No deploy/preview/provision was run.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
setup-go's built-in module cache defaults to keying only on the root
go.sum, so the infra/ module's heavy Pulumi SDK dependencies
(pulumi/sdk, pulumi-cloudflare, pulumi-gcp) re-downloaded on every run.
Set cache-dependency-path to hash both go.sum and infra/go.sum so
infra/'s deps are restored from cache. The cache warms on the first
(cold) run; the speedup lands on subsequent (warm) runs.
Closes#32
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
TinyGo 0.41.1 and earlier vendor tinygo-org/net@e54965e, whose net/http
js/wasm overlay (roundtrip_js.go) calls the private t.roundTrip fallback
removed from Go 1.25+/1.26 net/http, so `pnpm run build` fails to compile
on Go 1.26 (tinygo-org/tinygo#5467). No released TinyGo carries the fix
yet: it landed in tinygo-org/net@1026408a on 2026-04-27, after 0.41.1
shipped 2026-04-22, and is already on TinyGo's dev branch.
Keep Go 1.26 and apply the exact upstream fix in CI before the build:
- .ci/tinygo-net-roundtrip.patch: byte-exact tinygo-org/net@1026408a diff
(its parent e54965e is the commit 0.41.1 ships), targeting
src/net/http/roundtrip_js.go.
- ci.yml: new "Patch TinyGo net/http (temporary)" step applies it to
$(tinygo env TINYGOROOT) via `git apply`, failing loudly on drift.
- .gitattributes: force LF on *.patch so `git apply` works on the Linux
runner regardless of the committer's platform.
- README: document the temporary patch and its removal condition.
Temporary: remove the patch and the CI step once a TinyGo release later
than 0.41.1 ships the net fix. Tracking #26.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Undoes the go.mod/setup-go pin to 1.25 from the previous commit. The
maintainer requires Go 1.26. The TinyGo net/http wasm build failure is
an upstream toolchain bug (tinygo-org/tinygo#5467) and is being resolved
separately without changing the Go version. Not pushed pending the
toolchain-fix decision (issue #26).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
TinyGo 0.41.1's bundled net/http override (roundtrip_js.go) fails to
compile against the Go 1.26 stdlib:
net/http/roundtrip_js.go:73:12: t.roundTrip undefined (type *Transport
has no field or method roundTrip, but does have method RoundTrip)
This is tinygo-org/tinygo#5467 (closed 2026-06-20, but not in any tagged
TinyGo release as of 0.41.1, released 2026-04-22). Go 1.25.x is the
newest line TinyGo 0.41.1 fully supports; syumai/workers v0.33.0 needs
only go 1.21.3 and the handler uses only net/http + encoding/json, so
downgrading is safe:
- go.mod: go 1.26.2 -> go 1.25.0 (so GOTOOLCHAIN won't auto-upgrade past
what TinyGo supports)
- ci.yml: setup-go go-version 1.26 -> 1.25 (TinyGo pin stays 0.41.1)
- README: document the pinned TinyGo/Go matrix and the #5467 rationale
go vet ./..., go test ./..., and actionlint stay green locally.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The autoupdate workflow authenticated its branch-update pushes with the
default GITHUB_TOKEN. Pushes made with GITHUB_TOKEN do not re-trigger
downstream workflow runs, so status checks were not re-run on updated PR
branches.
Source the token from the STATUS_CHECKS_RETRIGGER_TOKEN PAT (scoped to the
"production" environment) instead. The action still reads GITHUB_TOKEN from
env, so only the value changes. Add `environment: production` to the job so
the environment-scoped secret is accessible, and update the explanatory
comment accordingly.
Closes#23
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add .github/workflows/ci.yml running on pull_request (targeting main) and
push to main. A single ubuntu-latest job "ci":
- checks out the repo, sets up Go 1.26, pnpm 10 + Node 22 (pnpm store
cache), and TinyGo 0.41.1 (Binaryen/wasm-opt included);
- runs pnpm install --frozen-lockfile, go vet ./..., go test ./...;
- conditionally vets/tests an infra/ Go module if infra/go.mod exists
(no-op until ticket #2 adds it);
- runs pnpm run build to confirm the TinyGo/Wasm Worker builds end to end.
Every action is pinned by full commit SHA with a "# vX.Y.Z" comment,
matching the supply-chain style of .github/workflows/autoupdate.yml.
Validated with actionlint (clean).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add .github/workflows/autoupdate.yml. On every push to main, the
chinthakagodawita/autoupdate action merges main into all open PRs that
target it (PR_FILTER: "all"), keeping branches current as PRs merge.
The action is pinned to commit 0707656 (v1.7.0) for supply-chain safety.
Uses the default GITHUB_TOKEN with minimal contents:write and
pull-requests:write permissions.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>