name: Deploy on: workflow_run: workflows: - CI types: - completed branches: - main workflow_dispatch: permissions: contents: read deployments: write concurrency: group: deploy-production cancel-in-progress: false env: BUN_VERSION: 1.3.11 jobs: deploy: if: > github.event_name == 'workflow_dispatch' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && github.event.workflow_run.head_branch == 'main') runs-on: ubuntu-latest timeout-minutes: 20 steps: - name: Check out the revision that passed CI uses: actions/checkout@v6 with: ref: ${{ github.event_name == 'workflow_run' && github.event.workflow_run.head_sha || github.sha }} - name: Set up Bun uses: oven-sh/setup-bun@v2 with: bun-version: ${{ env.BUN_VERSION }} - name: Install dependencies run: bun install --frozen-lockfile - name: Verify deployment credentials env: CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} run: | if [ -z "$CLOUDFLARE_ACCOUNT_ID" ]; then echo "CLOUDFLARE_ACCOUNT_ID secret is required for deployment." >&2 exit 1 fi if [ -z "$CLOUDFLARE_API_TOKEN" ]; then echo "CLOUDFLARE_API_TOKEN secret is required for deployment." >&2 exit 1 fi - name: Deploy to Cloudflare Workers env: CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} run: bunx wrangler deploy --keep-vars --message "GitHub Actions deploy for ${GITHUB_SHA}"