Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
4dfcb62
🛠️☁️ ↝ [SSC-30]: Unblock Cloudflare deploys by dropping Free-plan cpu_ms
Gizmotronn Sep 19, 2026
2c02465
🛰️🔐 ↝ [SSC-31 SSC-33]: Stage Vercel hosting and guarded playtests
Gizmotronn Sep 21, 2026
97a456d
🌐🧭 ↝ [SSC-31]: Target Vercel deployments to project scope
Gizmotronn Sep 21, 2026
9ad9fc1
☁️🧭 ↝ [SSC-31]: Cut staging over after Vercel preview
Gizmotronn Sep 21, 2026
1d8341b
🛰️📡 ↝ [SSC-31]: Complete staged domain verification handoff
Gizmotronn Sep 21, 2026
b5c4fd2
🧱☁️ ↝ [SSC-31 SSC-38]: Serve Star Sailors as a static shell plus a th…
claude Sep 25, 2026
12fe6de
📬🛰️ ↝ [SSC-37 SSC-39 SSC-38]: Precompute public data into KV on a cro…
claude Sep 25, 2026
be15031
🚦🪐 ↝ [SSC-35]: Build the staging Worker with the edge API flag on
Gizmotronn Sep 30, 2026
2a05fda
🚀🔭 ↝ [SSC-35]: Deploy the staging Worker on push to the edge API branch
Gizmotronn Sep 30, 2026
2246204
🔬🛰️ ↝ [SSC-35]: Assert the signed-in game reads its research summary …
Gizmotronn Sep 30, 2026
9cc5ccf
🔗🪐 ↝ [SSC-35]: Run the staging playtest after the edge-branch deploy
Gizmotronn Sep 30, 2026
f6526ff
🕰️🔭 ↝ [SSC-35]: Wait for Clerk before routing the first game read to …
Gizmotronn Sep 30, 2026
de8dfa2
🔬🧭 ↝ [SSC-35]: Assert the game's on-load classifications read goes th…
Gizmotronn Sep 30, 2026
a1f08e3
🔁🛰️ ↝ [SSC-35]: Retry playtest provisioning while a fresh Worker secr…
Gizmotronn Sep 30, 2026
7c64ae5
🔑🛰️ ↝ [SSC-35]: Prove the edge Worker accepts the signed-in Clerk tok…
Gizmotronn Sep 30, 2026
3fa0e24
🧪🔑 ↝ [SSC-35]: Report the token claims when the edge Worker rejects t…
Gizmotronn Sep 30, 2026
918155d
🔑🧩 ↝ [SSC-35]: Check the Clerk azp claim only when present so ticket-…
Gizmotronn Sep 30, 2026
53b57c8
🧬☁️ ↝ [SSC-38 SSC-31 SSC-37 SSC-39 SSC-35]: Merge the static-shell Wo…
Gizmotronn Sep 30, 2026
2010726
🧬🛰️ ↝ [SSC-38 SSC-31]: Merge staging history and drop the Vercel work…
Gizmotronn Sep 30, 2026
ce1b5de
🔧🛰️ ↝ [SSC-38 SSC-31]: Fix the duplicate push trigger so staging depl…
Gizmotronn Sep 30, 2026
2a50eab
📏🛰️ ↝ [SSC-38 SSC-35]: Run the budget measurement after each staging …
Gizmotronn Sep 30, 2026
e1a7cd7
🔄🛰️ ↝ [SSC-38 SSC-37]: Refresh one snapshot per cron tick to stay ins…
Gizmotronn Sep 30, 2026
78145af
📏🧪 ↝ [SSC-38]: Repeat signed-in reads in the playtest so authenticate…
Gizmotronn Sep 30, 2026
782cf27
🧬🚦 ↝ [SSC-38]: Merge main so the Cloudflare-native cutover can fast-f…
Gizmotronn Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 27 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,33 @@ jobs:
- name: Unit tests
run: yarn test:unit

cloudflare:
# SSC-31: production is a static export plus a thin Worker. A server
# action, force-dynamic page, or new dynamic route without
# generateStaticParams breaks the export; catch it here, not at deploy.
name: Cloudflare static build
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
with:
node-version: "22"
cache: yarn

- name: Install dependencies
run: yarn install --frozen-lockfile

- name: Build static shell
run: yarn cf:build
env:
# Any well-formed key; the build only embeds it.
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY: pk_test_Y2xlcmsuZXhhbXBsZS5jb20k

- name: Bundle the app Worker
run: npx wrangler deploy --dry-run --outdir .wrangler/dry-run

e2e:
name: E2E Tests
runs-on: ubuntu-latest
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
name: OpenNext Worker (reusable)
name: Cloudflare app Worker (reusable)

# SSC-31: builds the static Next.js export (`yarn cf:build` -> out/) and
# deploys it with the app Worker (workers/app) that serves /api/*, /ingest/*
# and dynamic pages. No OpenNext, no Next.js server, no SSR.
#
# Shared by production and staging. Secrets already on the Worker persist
# across `wrangler deploy` — do not `secret put` here. Each secret put
# publishes a new Worker version; doing that after every commit is what
Expand Down Expand Up @@ -57,8 +61,10 @@ jobs:
CLERK_SECRET_KEY: ${{ secrets.CLERK_SECRET_KEY }}
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY: ${{ secrets.NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY }}

- name: Build (OpenNext Cloudflare adapter)
run: npx opennextjs-cloudflare build
- name: Build static shell and check the Worker
run: |
yarn cf:build
npx vitest run workers
env:
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY: ${{ secrets.NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY }}
NEXT_PUBLIC_CLERK_SIGN_IN_URL: ${{ vars.NEXT_PUBLIC_CLERK_SIGN_IN_URL }}
Expand All @@ -73,6 +79,16 @@ jobs:
posthog_api_key: ${{ vars.NEXT_PUBLIC_POSTHOG_KEY }}
posthog_project_id: ${{ vars.POSTHOG_PROJECT_ID }}
posthog_region: US Cloud
NEXT_PUBLIC_VAPID_PUBLIC_KEY: ${{ secrets.VAPID_PUBLIC_KEY }}

# SSC-37/SSC-39: creates the KV namespace and job queues on first run and
# writes the namespace id into wrangler.jsonc. The API token needs
# Workers KV Storage: Edit and Queues: Edit.
- name: Ensure KV namespace and queues
run: node scripts/cloudflare/ensure-resources.mjs ${{ inputs.wrangler_env_args }}
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}

- uses: cloudflare/wrangler-action@v3
with:
Expand All @@ -84,7 +100,10 @@ jobs:
# with "Not enough arguments following: env" (broke prod deploy on
# 2026-09-17, see run 35190488025). Plain `deploy` still targets the
# top-level env correctly; it just logs a harmless warning.
command: ${{ inputs.wrangler_command }}
# The publishable key is public; the Worker derives the Clerk issuer
# (JWKS) from it to verify session JWTs locally.
# The VAPID public key is public too; queued push jobs need it to sign.
command: ${{ inputs.wrangler_command }} --var NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY:${{ secrets.NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY }} ${{ secrets.VAPID_PUBLIC_KEY && format('--var NEXT_PUBLIC_VAPID_PUBLIC_KEY:{0}', secrets.VAPID_PUBLIC_KEY) || '' }}

- name: Confirm Worker secrets already exist
run: |
Expand Down
83 changes: 0 additions & 83 deletions .github/workflows/cutover-vercel-domain.yml

This file was deleted.

92 changes: 0 additions & 92 deletions .github/workflows/deploy-api-worker.yml

This file was deleted.

45 changes: 34 additions & 11 deletions .github/workflows/deploy-cloudflare-staging.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
name: Deploy to Cloudflare Workers (Legacy Staging)
name: Deploy staging to Cloudflare Workers

# Constant preview target for signal-k/client: same OpenNext Cloudflare
# adapter as production, deployed to the wrangler.jsonc `env.staging`
# Constant staging target for signal-k/client: same static shell + app
# Worker build as production, deployed to the wrangler.jsonc `env.staging`
# Worker at the constant https://staging.starsailors.space custom domain.
# That's a real subdomain of the apex (not *.workers.dev) on purpose:
# production's Clerk instance uses a custom Frontend API proxy domain
Expand All @@ -11,21 +11,32 @@ name: Deploy to Cloudflare Workers (Legacy Staging)
# Clerk instance as production (not a separate staging backend) so
# accounts/data stay one ecosystem; only the frontend Worker differs.
on:
# SSC-31 moves the staging host to Vercel Node hosting. Keep this workflow
# dispatch-only until the Cloudflare Worker domain is detached, so a staging
# push cannot accidentally reclaim staging.starsailors.space.
workflow_dispatch: {}
# Edge API rollout check: deploys only from this one branch, never `staging`.
push:
branches: [ssc-edge-api-staging]
branches: [staging, ssc-edge-api-staging]
paths:
- "src/**"
- "public/**"
- "package.json"
- "yarn.lock"
- "next.config.*"
- "wrangler.jsonc"
- "workers/**"
- "scripts/cloudflare/**"
- "tsconfig.json"
- "postcss.config.*"
- "tailwind.config.*"
- "components.json"
- ".github/workflows/deploy-cloudflare-staging.yml"
- ".github/workflows/cloudflare-app-worker.yml"
workflow_dispatch: {}

concurrency:
group: cloudflare-staging
cancel-in-progress: true

jobs:
deploy:
uses: ./.github/workflows/open-next-worker.yml
uses: ./.github/workflows/cloudflare-app-worker.yml
secrets: inherit
with:
wrangler_command: deploy --env staging
Expand All @@ -34,6 +45,18 @@ jobs:
# Edge API rollout: after the edge-branch deploy, play the signed-in game on it.
playtest:
needs: deploy
if: github.ref == 'refs/heads/ssc-edge-api-staging'
if: github.ref == 'refs/heads/ssc-edge-api-staging' || github.ref == 'refs/heads/staging'
uses: ./.github/workflows/staging-playtest.yml
secrets: inherit

# SSC-38: record CPU, subrequests, size and errors per route on the deployed
# staging Worker. Independent of the playtest so one failure can't hide the other.
# Runs after the playtest (pass or fail) so its secret changes don't land
# mid-measurement.
budget:
needs: [deploy, playtest]
if: always() && needs.deploy.result == 'success'
uses: ./.github/workflows/measure-cloudflare-budget.yml
secrets: inherit
with:
target: staging
12 changes: 6 additions & 6 deletions .github/workflows/deploy-cloudflare.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
name: Deploy to Cloudflare Workers

# Client is a full Next.js app (API routes, server actions, server-side
# Pocketbase admin auth) -- not a static SPA like Atlas, so this deploys via
# the OpenNext Cloudflare adapter (Workers + Assets), not cloudflare/pages-action.
# SSC-31: static Next.js export on Workers Static Assets plus the thin app
# Worker (workers/app) for /api/*. See docs/runbooks/cloudflare-cutover.md.
#
# Frequent main commits are expected. Cancel superseded runs so only the latest
# code publishes, and never `wrangler secret put` here (that publishes an extra
Expand All @@ -17,13 +16,14 @@ on:
- "yarn.lock"
- "next.config.*"
- "wrangler.jsonc"
- "open-next.config.*"
- "workers/**"
- "scripts/cloudflare/**"
- "tsconfig.json"
- "postcss.config.*"
- "tailwind.config.*"
- "components.json"
- ".github/workflows/deploy-cloudflare.yml"
- ".github/workflows/open-next-worker.yml"
- ".github/workflows/cloudflare-app-worker.yml"
workflow_dispatch: {}

concurrency:
Expand All @@ -32,7 +32,7 @@ concurrency:

jobs:
deploy:
uses: ./.github/workflows/open-next-worker.yml
uses: ./.github/workflows/cloudflare-app-worker.yml
secrets: inherit
with:
wrangler_command: deploy
Expand Down
Loading
Loading