diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 84e7082..22bcd02 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -2,7 +2,7 @@ image: name: "$CI_DEPENDENCY_PROXY_GROUP_IMAGE_PREFIX/nixos/nix:latest" entrypoint: - - /root/.nix-profile/bin/bash + - /nix/store/smkzrg2vvp3lng3hq7v9svfni5mnqjh2-bash-interactive-5.2p37/bin/bash stages: - test - build @@ -24,6 +24,8 @@ variables: #FF_GIT_COMMITTERS_API: "true" SECURE_FILES_DOWNLOAD_PATH: .secretskit GIT_DEPTH: "0" + # ignore pipfile and rely on the lockfile for deterministic builds + PIPENV_IGNORE_PIPFILE: "true" # dotenvx stuff DOTENV_PRIVATE_KEY: $DOTENV_PRIVATE_KEY_CI MKDOCS_GIT_COMMITTERS_PLUGIN_TOKEN: $CI_JOB_TOKEN diff --git a/.tangled/workflows/site-deploy.yml b/.tangled/workflows/site-deploy.yml index 2df8ebe..9f32058 100644 --- a/.tangled/workflows/site-deploy.yml +++ b/.tangled/workflows/site-deploy.yml @@ -8,7 +8,7 @@ when: engine: nixery clone: - depth: 0 + depth: 500 submodules: true # sync this with devenv.nix + devenv.yaml (if applicable for additional flakes @@ -39,9 +39,13 @@ environment: steps: - name: Install deps command: | - pipenv install + pipenv install --deploy --ignore-pipfile npm ci environment: PIPENV_IGNORE_PIPFILE: "true" + # We configured our wrangler.toml to use our build script (at ../../bin/build.sh) + # for building the site and doing post-build prep (like copying well-known files + # and such). To minimize admin overhead on secrets management, we use `doppler run` + # to inject secrets from Doppler into the environment for the build and deploy steps. - name: Deploy to Cloudflare Workers (as Static Site) command: doppler run -- npm run deploy:cf \ No newline at end of file diff --git a/bin/build.sh b/bin/build.sh index 61467eb..6d0aa11 100755 --- a/bin/build.sh +++ b/bin/build.sh @@ -4,4 +4,4 @@ set -ex TARGET_DIR="${PWD}/public" pipenv run build cp "$TARGET_DIR/assets/images/favicon.png" "$TARGET_DIR/favicon.ico" -v -#cp "$SOURCE_DIR/.well-known" "$TARGET_DIR/" -rv +cp "$SOURCE_DIR/.well-known" "$TARGET_DIR/" -rv