Commit Graph
11 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 db28f0b368 CI: align build env to pnpm 11 + Node 26
Match deploy.yml (merged in #46): bump ci.yml pnpm 10->11 and Node 22->26 so CI and CD build in the same environment. Actions stay pinned to their latest release SHAs (unchanged); Go 1.26 + TinyGo 0.41.1 latest. actionlint clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 18:58:48 -05:00
JMR-devandClaude Opus 4.8 1e29ab6077 #4 deploy.yml: pnpm 11 + Node 26
Set pnpm to 11 and Node to 26. Verified every action is pinned to its latest release commit SHA with the correct version comment (checkout v7.0.0, setup-go v6.5.0, setup-tinygo v3.0.0, pnpm/action-setup v6.0.9, setup-node v6.4.0, pulumi/actions v7.0.0); Go 1.26 and TinyGo 0.41.1 are the latest.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 18:52:39 -05:00
JMR-devandClaude Opus 4.8 985fb684c5 #4 GitHub Actions CD: deploy via workflow_dispatch
Add a manual, workflow_dispatch-only CD workflow and close the infra
binding-wiring gap (#9) so the deployed Worker is actually functional.

Deliverable 1 - .github/workflows/deploy.yml:
- workflow_dispatch only, with a `stack` choice input (default prod).
- Gated to the `production` GitHub Actions environment and to the main
  branch (guard step fails otherwise); no push/PR trigger.
- Reuses ci.yml's Go 1.26 + TinyGo + pnpm setup and the TinyGo net/http
  patch, builds the Wasm Worker (pnpm run build), then runs pulumi up over
  infra/ via pulumi/actions, injecting the built ../build/worker.mjs as the
  workerScriptPath config. Provider/backend creds come from environment
  secrets (nothing committed). All actions pinned by commit SHA; actionlint
  clean.

Deliverable 2 - infra/deploy.go binding wiring (#9):
- WorkersScript now carries the R2 bucket binding (REPORTS_BUCKET), the four
  Secrets Store bindings (BUGREPORT_ENC_KEYRING, ADMIN_TOKEN, GITHUB_TOKEN,
  OTEL_EXPORTER_OTLP_HEADERS), and the plain vars (GITHUB_REPO, OTEL_*),
  matching wrangler.jsonc and the Worker runtime contract.
- New WorkersCronTrigger resource registers the two Friday UTC crons (#13),
  bound to the Worker.
- Real built artifact wired via ContentFile + computed ContentSha256 when
  the workerScriptPath config is set; documented placeholder otherwise
  (keeps the program testable without the artifact, as #2 did).
- secretsStoreId is a new required config; git rate-limit ruleset insertion
  point (#6/#7) kept reserved.
- Extended the WithMocks tests to assert the R2 + Secrets Store + var
  bindings, the crons, and the artifact ContentFile/ContentSha256 path.
- Updated Pulumi.<stack>.yaml and infra/README.md with the full
  secret/config list and how a maintainer triggers the deploy.

Verified in infra/: go build, go vet, go test all green; actionlint clean
on deploy.yml. No deploy/preview/provision was run.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 17:40:08 -05:00
JMR-devandClaude Opus 4.8 98ee51b21a CI: cache infra/ Go module deps (Pulumi SDKs) to speed up runs
setup-go's built-in module cache defaults to keying only on the root
go.sum, so the infra/ module's heavy Pulumi SDK dependencies
(pulumi/sdk, pulumi-cloudflare, pulumi-gcp) re-downloaded on every run.

Set cache-dependency-path to hash both go.sum and infra/go.sum so
infra/'s deps are restored from cache. The cache warms on the first
(cold) run; the speedup lands on subsequent (warm) runs.

Closes #32

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 15:00:50 -05:00
Jason Ross c0c2925a5a Merge branch 'main' into ticket-3-ci 2026-07-02 14:22:41 -05:00
JMR-devandClaude Opus 4.8 47f9babe35 #26 Fix TinyGo net/http wasm build via pinned upstream patch (Go 1.26)
TinyGo 0.41.1 and earlier vendor tinygo-org/net@e54965e, whose net/http
js/wasm overlay (roundtrip_js.go) calls the private t.roundTrip fallback
removed from Go 1.25+/1.26 net/http, so `pnpm run build` fails to compile
on Go 1.26 (tinygo-org/tinygo#5467). No released TinyGo carries the fix
yet: it landed in tinygo-org/net@1026408a on 2026-04-27, after 0.41.1
shipped 2026-04-22, and is already on TinyGo's dev branch.

Keep Go 1.26 and apply the exact upstream fix in CI before the build:
- .ci/tinygo-net-roundtrip.patch: byte-exact tinygo-org/net@1026408a diff
  (its parent e54965e is the commit 0.41.1 ships), targeting
  src/net/http/roundtrip_js.go.
- ci.yml: new "Patch TinyGo net/http (temporary)" step applies it to
  $(tinygo env TINYGOROOT) via `git apply`, failing loudly on drift.
- .gitattributes: force LF on *.patch so `git apply` works on the Linux
  runner regardless of the committer's platform.
- README: document the temporary patch and its removal condition.

Temporary: remove the patch and the CI step once a TinyGo release later
than 0.41.1 ships the net fix. Tracking #26.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 14:06:08 -05:00
JMR-devandClaude Opus 4.8 bd3637d8a6 Revert Go downgrade; keep Go 1.26 per maintainer mandate
Undoes the go.mod/setup-go pin to 1.25 from the previous commit. The
maintainer requires Go 1.26. The TinyGo net/http wasm build failure is
an upstream toolchain bug (tinygo-org/tinygo#5467) and is being resolved
separately without changing the Go version. Not pushed pending the
toolchain-fix decision (issue #26).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:53:46 -05:00
JMR-devandClaude Opus 4.8 f27ad42c24 #26 Pin Go 1.25 + TinyGo 0.41.1 so the Wasm build compiles
TinyGo 0.41.1's bundled net/http override (roundtrip_js.go) fails to
compile against the Go 1.26 stdlib:

  net/http/roundtrip_js.go:73:12: t.roundTrip undefined (type *Transport
  has no field or method roundTrip, but does have method RoundTrip)

This is tinygo-org/tinygo#5467 (closed 2026-06-20, but not in any tagged
TinyGo release as of 0.41.1, released 2026-04-22). Go 1.25.x is the
newest line TinyGo 0.41.1 fully supports; syumai/workers v0.33.0 needs
only go 1.21.3 and the handler uses only net/http + encoding/json, so
downgrading is safe:

- go.mod: go 1.26.2 -> go 1.25.0 (so GOTOOLCHAIN won't auto-upgrade past
  what TinyGo supports)
- ci.yml: setup-go go-version 1.26 -> 1.25 (TinyGo pin stays 0.41.1)
- README: document the pinned TinyGo/Go matrix and the #5467 rationale

go vet ./..., go test ./..., and actionlint stay green locally.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:42:17 -05:00
JMR-devandClaude Opus 4.8 4c2d0ad43f autoupdate: use STATUS_CHECKS_RETRIGGER_TOKEN so branch updates re-trigger checks
The autoupdate workflow authenticated its branch-update pushes with the
default GITHUB_TOKEN. Pushes made with GITHUB_TOKEN do not re-trigger
downstream workflow runs, so status checks were not re-run on updated PR
branches.

Source the token from the STATUS_CHECKS_RETRIGGER_TOKEN PAT (scoped to the
"production" environment) instead. The action still reads GITHUB_TOKEN from
env, so only the value changes. Add `environment: production` to the job so
the environment-scoped secret is accessible, and update the explanatory
comment accordingly.

Closes #23

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:30:53 -05:00
JMR-devandClaude Opus 4.8 610b02ba83 #3 GitHub Actions CI: build, lint, test
Add .github/workflows/ci.yml running on pull_request (targeting main) and
push to main. A single ubuntu-latest job "ci":
- checks out the repo, sets up Go 1.26, pnpm 10 + Node 22 (pnpm store
  cache), and TinyGo 0.41.1 (Binaryen/wasm-opt included);
- runs pnpm install --frozen-lockfile, go vet ./..., go test ./...;
- conditionally vets/tests an infra/ Go module if infra/go.mod exists
  (no-op until ticket #2 adds it);
- runs pnpm run build to confirm the TinyGo/Wasm Worker builds end to end.

Every action is pinned by full commit SHA with a "# vX.Y.Z" comment,
matching the supply-chain style of .github/workflows/autoupdate.yml.
Validated with actionlint (clean).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:30:50 -05:00
Jason RossandClaude Opus 4.8 8e1dc66c54 CI: auto-update open PR branches via autoupdate Action (#20) (#22)
Add .github/workflows/autoupdate.yml. On every push to main, the
chinthakagodawita/autoupdate action merges main into all open PRs that
target it (PR_FILTER: "all"), keeping branches current as PRs merge.

The action is pinned to commit 0707656 (v1.7.0) for supply-chain safety.
Uses the default GITHUB_TOKEN with minimal contents:write and
pull-requests:write permissions.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:22:52 -05:00