Repository navigation
fix(bench): hot loops join vm.json, a broken snapshot fails, and memo… #2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI / CD | |
| # Builds stage into this run's tmp CDN prefix, tests read it back, main ships to dev and a tag to prod. | |
| on: | |
| push: | |
| branches: [main] | |
| tags: ["v*"] | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| env: | |
| EDGE_RUN: ${{ github.run_id }} | |
| EDGE_CDN_BASE: https://cdn.tmp.edgepython.com/${{ github.run_id }} | |
| jobs: | |
| compiler: | |
| name: Compiler | |
| runs-on: ubuntu-26.04 | |
| permissions: | |
| contents: write | |
| env: | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| # A tag names the release the CLI reports, so the earliest job refuses one the manifests disagree with. | |
| - name: Check the version | |
| if: startsWith(github.ref, 'refs/tags/v') | |
| run: | | |
| tag="${GITHUB_REF_NAME#v}" | |
| # An edge floor names engine releases, so a release follows the rule every edge.json version does. | |
| if ! [[ "$tag" =~ ^(0|[1-9][0-9]?)\.(0|[1-9][0-9]?)\.(0|[1-9][0-9]?)$ ]]; then | |
| echo "tag $GITHUB_REF_NAME is not major.minor.patch with each part 0 to 99 and no leading zeros" >&2 | |
| exit 1 | |
| fi | |
| root=$(grep -m1 '^version = ' Cargo.toml | cut -d'"' -f2) | |
| cli=$(grep -m1 '^version = ' cli/Cargo.toml | cut -d'"' -f2) | |
| if [ "$root" != "$tag" ] || [ "$cli" != "$tag" ]; then | |
| echo "tag $GITHUB_REF_NAME ships $tag, Cargo.toml says $root and cli/Cargo.toml says $cli" >&2 | |
| exit 1 | |
| fi | |
| - uses: ./.github/actions/compiler | |
| with: | |
| github-token: ${{ github.token }} | |
| js: | |
| name: JS | |
| needs: [compiler] | |
| runs-on: ubuntu-26.04 | |
| env: | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: ./.github/actions/js | |
| # cli/build.rs embeds the compiler and std builds this run staged on tmp. | |
| cli: | |
| name: CLI / ${{ matrix.entry }} | |
| needs: [js] | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - entry: lint | |
| mode: lint | |
| runner: ubuntu-26.04 | |
| - entry: x86_64-unknown-linux-musl | |
| mode: release | |
| target: x86_64-unknown-linux-musl | |
| runner: ubuntu-26.04 | |
| - entry: aarch64-unknown-linux-musl | |
| mode: release | |
| target: aarch64-unknown-linux-musl | |
| runner: ubuntu-26.04-arm | |
| - entry: aarch64-apple-darwin | |
| mode: release | |
| target: aarch64-apple-darwin | |
| runner: macos-15 | |
| - entry: x86_64-apple-darwin | |
| mode: release | |
| target: x86_64-apple-darwin | |
| runner: macos-15 | |
| runs-on: ${{ matrix.runner }} | |
| env: | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: ./.github/actions/cli | |
| with: | |
| mode: ${{ matrix.mode }} | |
| target: ${{ matrix.target }} | |
| # Every suite runs against the tmp CDN this run staged, never the deployed one. | |
| test: | |
| name: Test / ${{ matrix.entry }} | |
| needs: [cli] | |
| runs-on: ubuntu-26.04 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - entry: js | |
| suite: js | |
| - entry: cli-engine | |
| cli: engine | |
| - entry: cli-network | |
| cli: network | |
| - entry: cli-actors | |
| cli: actors | |
| - entry: cli-skill | |
| cli: skill | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - if: matrix.suite | |
| uses: ./.github/actions/test | |
| - if: matrix.cli | |
| uses: ./.github/actions/cli | |
| with: | |
| mode: test | |
| suite: ${{ matrix.cli }} | |
| site: | |
| name: Site | |
| needs: [compiler] | |
| runs-on: ubuntu-26.04 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: ./.github/actions/site | |
| # Holds the engine to the reference seconds of bench/.snapshot once its tests pass. | |
| bench: | |
| name: Bench | |
| needs: [compiler] | |
| runs-on: ubuntu-26.04 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: ./.github/actions/bench | |
| # Typechecks the deploy scripts and proves dev and prod can never name the same resource. | |
| infra: | |
| name: Infra | |
| runs-on: ubuntu-26.04 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version-file: site/.node-version | |
| cache: npm | |
| cache-dependency-path: infra/package-lock.json | |
| - name: Install | |
| working-directory: infra | |
| run: npm ci | |
| - name: Check | |
| working-directory: infra | |
| run: npm run check && npm test | |
| # Pushes only, since pull requests get no secrets. Main warns about a difference and a tag refuses to ship one. | |
| database: | |
| name: Database | |
| needs: [infra] | |
| if: github.event_name == 'push' | |
| runs-on: ubuntu-26.04 | |
| env: | |
| EDGE_ENV: prod | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: ./.github/actions/database | |
| with: | |
| strict: ${{ startsWith(github.ref, 'refs/tags/v') }} | |
| # Main pushes only, the tested tmp tree and the site ship together to dev. | |
| promote: | |
| name: Promote | |
| needs: [test, site, infra] | |
| if: github.event_name == 'push' && github.ref == 'refs/heads/main' | |
| runs-on: ubuntu-26.04 | |
| env: | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} | |
| CLOUDFLARE_ACCESS_EMAILS: ${{ secrets.DEV_CLOUDFLARE_ACCESS_EMAILS }} | |
| OAUTH_GITHUB_ID: ${{ secrets.DEV_OAUTH_GITHUB_ID }} | |
| OAUTH_GITHUB_SECRET: ${{ secrets.DEV_OAUTH_GITHUB_SECRET }} | |
| OAUTH_GOOGLE_ID: ${{ secrets.DEV_OAUTH_GOOGLE_ID }} | |
| OAUTH_GOOGLE_SECRET: ${{ secrets.DEV_OAUTH_GOOGLE_SECRET }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: ./.github/actions/promote | |
| # A v tag ships the same tested tree to production, no Access gate and its own OAuth apps. | |
| ship: | |
| name: Ship | |
| needs: [test, site, infra, database] | |
| if: startsWith(github.ref, 'refs/tags/v') | |
| runs-on: ubuntu-26.04 | |
| # Required reviewers on this environment hold the run until the migrations are approved. | |
| environment: production | |
| env: | |
| EDGE_ENV: prod | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} | |
| OAUTH_GITHUB_ID: ${{ secrets.PROD_OAUTH_GITHUB_ID }} | |
| OAUTH_GITHUB_SECRET: ${{ secrets.PROD_OAUTH_GITHUB_SECRET }} | |
| OAUTH_GOOGLE_ID: ${{ secrets.PROD_OAUTH_GOOGLE_ID }} | |
| OAUTH_GOOGLE_SECRET: ${{ secrets.PROD_OAUTH_GOOGLE_SECRET }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: ./.github/actions/promote |