diff --git a/.tangled/workflows/deploy.yml b/.tangled/workflows/deploy.yml index a54387b..e7f116d 100644 --- a/.tangled/workflows/deploy.yml +++ b/.tangled/workflows/deploy.yml @@ -1,16 +1,16 @@ -# Type-check, then tell Coolify to deploy. +# Tell Coolify to deploy on every push to main. # -# Coolify does the build itself (it clones this repo and builds the Dockerfile), -# so this pipeline is a gate, not a builder: if `pnpm check` fails, the deploy -# request is never sent and the running site is left alone. +# Coolify does everything else itself — it clones main, type-checks and builds +# the Dockerfile, and only swaps the container if that succeeds — so this +# pipeline is just the trigger. It doesn't need the repository or a Node +# toolchain, which keeps it to a couple of seconds and keeps the dependency +# install in exactly one place. # -# Tangled's own webhooks (Settings -> Hooks) can't be used directly here — they -# send only a URL plus an HMAC signature, and Coolify's deploy API wants a -# bearer token — so the pipeline makes the call instead. -# -# Coolify sits behind Cloudflare Access, so the call carries two credentials: -# the service-token pair gets it past the edge (unauthenticated requests never -# reach the panel at all), and the bearer token authenticates to Coolify. +# Tangled's own webhooks (Settings -> Hooks) can't be used directly: they send +# a URL plus an HMAC signature, and this call needs two credentials of its own. +# Coolify sits behind Cloudflare Access, so the service-token pair gets the +# request past the edge (unauthenticated traffic never reaches the panel) and +# the bearer token authenticates to Coolify. # # Repo secrets (Settings -> Secrets): # COOLIFY_DEPLOY_URL — https:///api/v1/deploy?uuid= @@ -24,18 +24,14 @@ when: engine: "nixery" +clone: + skip: true + dependencies: nixpkgs: - - nodejs_22 - - pnpm - curl steps: - - name: "type-check" - command: | - pnpm install --frozen-lockfile - pnpm check - - name: "deploy" command: | curl --fail-with-body -sS -X POST "$COOLIFY_DEPLOY_URL" \ diff --git a/Dockerfile b/Dockerfile index b331178..96f63ec 100644 --- a/Dockerfile +++ b/Dockerfile @@ -20,6 +20,12 @@ COPY patches ./patches RUN pnpm install --frozen-lockfile COPY . . + +# Type-check here rather than in the pipeline, so it gates the thing it should +# gate: a failed build means Coolify never swaps the container and the running +# site is left alone. `vite build` alone wouldn't catch this — svelte-check and +# tsc are what read the types. +RUN pnpm check RUN pnpm build FROM nginx:1.27-alpine