GitHub Actions workflow triggered via workflow_dispatch that runs pulumi up against the production stack.
Wire up required secrets (Cloudflare API token, GCP credentials) as GitHub Actions secrets — document what's needed, don't commit values.
Restrict who can trigger it (manual production deploy) — e.g. require it be run from main and limit to maintainers.
Acceptance criteria
A maintainer can manually trigger the deploy workflow (Actions tab or gh workflow run) and it runs pulumi up; the deploy fails loudly (and is visible) if pulumi up errors.
Dependencies
Depends on #2 (Pulumi IaC to run). Not merge-gated — it's triggered manually rather than automatically on merge, though a maintainer should typically only run it after CI (#3) has passed on the commit being deployed.
## Context
Part of [JMR-dev/LibreMail#11](https://github.com/JMR-dev/LibreMail/issues/11) — "Deployment from GitHub Actions."
## Scope
- [ ] GitHub Actions workflow triggered via `workflow_dispatch` that runs `pulumi up` against the production stack.
- [ ] Wire up required secrets (Cloudflare API token, GCP credentials) as GitHub Actions secrets — document what's needed, don't commit values.
- [ ] Restrict who can trigger it (manual production deploy) — e.g. require it be run from `main` and limit to maintainers.
## Acceptance criteria
- A maintainer can manually trigger the deploy workflow (Actions tab or `gh workflow run`) and it runs `pulumi up`; the deploy fails loudly (and is visible) if `pulumi up` errors.
## Dependencies
Depends on #2 (Pulumi IaC to run). Not merge-gated — it's triggered manually rather than automatically on merge, though a maintainer should typically only run it after CI (#3) has passed on the commit being deployed.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Context
Part of JMR-dev/LibreMail#11 — "Deployment from GitHub Actions."
Scope
workflow_dispatchthat runspulumi upagainst the production stack.mainand limit to maintainers.Acceptance criteria
gh workflow run) and it runspulumi up; the deploy fails loudly (and is visible) ifpulumi uperrors.Dependencies
Depends on #2 (Pulumi IaC to run). Not merge-gated — it's triggered manually rather than automatically on merge, though a maintainer should typically only run it after CI (#3) has passed on the commit being deployed.