Set pnpm to 11 and Node to 26. Verified every action is pinned to its latest release commit SHA with the correct version comment (checkout v7.0.0, setup-go v6.5.0, setup-tinygo v3.0.0, pnpm/action-setup v6.0.9, setup-node v6.4.0, pulumi/actions v7.0.0); Go 1.26 and TinyGo 0.41.1 are the latest.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a manual, workflow_dispatch-only CD workflow and close the infra
binding-wiring gap (#9) so the deployed Worker is actually functional.
Deliverable 1 - .github/workflows/deploy.yml:
- workflow_dispatch only, with a `stack` choice input (default prod).
- Gated to the `production` GitHub Actions environment and to the main
branch (guard step fails otherwise); no push/PR trigger.
- Reuses ci.yml's Go 1.26 + TinyGo + pnpm setup and the TinyGo net/http
patch, builds the Wasm Worker (pnpm run build), then runs pulumi up over
infra/ via pulumi/actions, injecting the built ../build/worker.mjs as the
workerScriptPath config. Provider/backend creds come from environment
secrets (nothing committed). All actions pinned by commit SHA; actionlint
clean.
Deliverable 2 - infra/deploy.go binding wiring (#9):
- WorkersScript now carries the R2 bucket binding (REPORTS_BUCKET), the four
Secrets Store bindings (BUGREPORT_ENC_KEYRING, ADMIN_TOKEN, GITHUB_TOKEN,
OTEL_EXPORTER_OTLP_HEADERS), and the plain vars (GITHUB_REPO, OTEL_*),
matching wrangler.jsonc and the Worker runtime contract.
- New WorkersCronTrigger resource registers the two Friday UTC crons (#13),
bound to the Worker.
- Real built artifact wired via ContentFile + computed ContentSha256 when
the workerScriptPath config is set; documented placeholder otherwise
(keeps the program testable without the artifact, as #2 did).
- secretsStoreId is a new required config; git rate-limit ruleset insertion
point (#6/#7) kept reserved.
- Extended the WithMocks tests to assert the R2 + Secrets Store + var
bindings, the crons, and the artifact ContentFile/ContentSha256 path.
- Updated Pulumi.<stack>.yaml and infra/README.md with the full
secret/config list and how a maintainer triggers the deploy.
Verified in infra/: go build, go vet, go test all green; actionlint clean
on deploy.yml. No deploy/preview/provision was run.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>