Skip to content

fix(bench): hot loops join vm.json, a broken snapshot fails, and memo… #2

fix(bench): hot loops join vm.json, a broken snapshot fails, and memo…

fix(bench): hot loops join vm.json, a broken snapshot fails, and memo… #2

Workflow file for this run

name: CI / CD
# Builds stage into this run's tmp CDN prefix, tests read it back, main ships to dev and a tag to prod.
on:
push:
branches: [main]
tags: ["v*"]
pull_request:
branches: [main]
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
env:
EDGE_RUN: ${{ github.run_id }}
EDGE_CDN_BASE: https://cdn.tmp.edgepython.com/${{ github.run_id }}
jobs:
compiler:
name: Compiler
runs-on: ubuntu-26.04
permissions:
contents: write
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
steps:
- uses: actions/checkout@v7
# A tag names the release the CLI reports, so the earliest job refuses one the manifests disagree with.
- name: Check the version
if: startsWith(github.ref, 'refs/tags/v')
run: |
tag="${GITHUB_REF_NAME#v}"
# An edge floor names engine releases, so a release follows the rule every edge.json version does.
if ! [[ "$tag" =~ ^(0|[1-9][0-9]?)\.(0|[1-9][0-9]?)\.(0|[1-9][0-9]?)$ ]]; then
echo "tag $GITHUB_REF_NAME is not major.minor.patch with each part 0 to 99 and no leading zeros" >&2
exit 1
fi
root=$(grep -m1 '^version = ' Cargo.toml | cut -d'"' -f2)
cli=$(grep -m1 '^version = ' cli/Cargo.toml | cut -d'"' -f2)
if [ "$root" != "$tag" ] || [ "$cli" != "$tag" ]; then
echo "tag $GITHUB_REF_NAME ships $tag, Cargo.toml says $root and cli/Cargo.toml says $cli" >&2
exit 1
fi
- uses: ./.github/actions/compiler
with:
github-token: ${{ github.token }}
js:
name: JS
needs: [compiler]
runs-on: ubuntu-26.04
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
steps:
- uses: actions/checkout@v7
- uses: ./.github/actions/js
# cli/build.rs embeds the compiler and std builds this run staged on tmp.
cli:
name: CLI / ${{ matrix.entry }}
needs: [js]
strategy:
fail-fast: false
matrix:
include:
- entry: lint
mode: lint
runner: ubuntu-26.04
- entry: x86_64-unknown-linux-musl
mode: release
target: x86_64-unknown-linux-musl
runner: ubuntu-26.04
- entry: aarch64-unknown-linux-musl
mode: release
target: aarch64-unknown-linux-musl
runner: ubuntu-26.04-arm
- entry: aarch64-apple-darwin
mode: release
target: aarch64-apple-darwin
runner: macos-15
- entry: x86_64-apple-darwin
mode: release
target: x86_64-apple-darwin
runner: macos-15
runs-on: ${{ matrix.runner }}
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
steps:
- uses: actions/checkout@v7
- uses: ./.github/actions/cli
with:
mode: ${{ matrix.mode }}
target: ${{ matrix.target }}
# Every suite runs against the tmp CDN this run staged, never the deployed one.
test:
name: Test / ${{ matrix.entry }}
needs: [cli]
runs-on: ubuntu-26.04
strategy:
fail-fast: false
matrix:
include:
- entry: js
suite: js
- entry: cli-engine
cli: engine
- entry: cli-network
cli: network
- entry: cli-actors
cli: actors
- entry: cli-skill
cli: skill
steps:
- uses: actions/checkout@v7
- if: matrix.suite
uses: ./.github/actions/test
- if: matrix.cli
uses: ./.github/actions/cli
with:
mode: test
suite: ${{ matrix.cli }}
site:
name: Site
needs: [compiler]
runs-on: ubuntu-26.04
steps:
- uses: actions/checkout@v7
- uses: ./.github/actions/site
# Holds the engine to the reference seconds of bench/.snapshot once its tests pass.
bench:
name: Bench
needs: [compiler]
runs-on: ubuntu-26.04
steps:
- uses: actions/checkout@v7
- uses: ./.github/actions/bench
# Typechecks the deploy scripts and proves dev and prod can never name the same resource.
infra:
name: Infra
runs-on: ubuntu-26.04
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version-file: site/.node-version
cache: npm
cache-dependency-path: infra/package-lock.json
- name: Install
working-directory: infra
run: npm ci
- name: Check
working-directory: infra
run: npm run check && npm test
# Pushes only, since pull requests get no secrets. Main warns about a difference and a tag refuses to ship one.
database:
name: Database
needs: [infra]
if: github.event_name == 'push'
runs-on: ubuntu-26.04
env:
EDGE_ENV: prod
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
steps:
- uses: actions/checkout@v7
- uses: ./.github/actions/database
with:
strict: ${{ startsWith(github.ref, 'refs/tags/v') }}
# Main pushes only, the tested tmp tree and the site ship together to dev.
promote:
name: Promote
needs: [test, site, infra]
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: ubuntu-26.04
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
CLOUDFLARE_ACCESS_EMAILS: ${{ secrets.DEV_CLOUDFLARE_ACCESS_EMAILS }}
OAUTH_GITHUB_ID: ${{ secrets.DEV_OAUTH_GITHUB_ID }}
OAUTH_GITHUB_SECRET: ${{ secrets.DEV_OAUTH_GITHUB_SECRET }}
OAUTH_GOOGLE_ID: ${{ secrets.DEV_OAUTH_GOOGLE_ID }}
OAUTH_GOOGLE_SECRET: ${{ secrets.DEV_OAUTH_GOOGLE_SECRET }}
steps:
- uses: actions/checkout@v7
- uses: ./.github/actions/promote
# A v tag ships the same tested tree to production, no Access gate and its own OAuth apps.
ship:
name: Ship
needs: [test, site, infra, database]
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-26.04
# Required reviewers on this environment hold the run until the migrations are approved.
environment: production
env:
EDGE_ENV: prod
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
OAUTH_GITHUB_ID: ${{ secrets.PROD_OAUTH_GITHUB_ID }}
OAUTH_GITHUB_SECRET: ${{ secrets.PROD_OAUTH_GITHUB_SECRET }}
OAUTH_GOOGLE_ID: ${{ secrets.PROD_OAUTH_GOOGLE_ID }}
OAUTH_GOOGLE_SECRET: ${{ secrets.PROD_OAUTH_GOOGLE_SECRET }}
steps:
- uses: actions/checkout@v7
- uses: ./.github/actions/promote