chore(release): bump version to 1.4.3 #924
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build & Deploy main to mittwald | |
| on: | |
| push: | |
| branches: | |
| - main | |
| # `publish.yml` dispatches this after it created a GitHub Release that no push | |
| # to `main` follows — a pre-graduated promotion (RFC #2711). The docs bake the | |
| # GitHub Releases list in at build time (`output: "export"`), so without a | |
| # rebuild `/releases` keeps showing the release before the promotion. Also the | |
| # manual handle for any other "the deployed site is stale" case. | |
| workflow_dispatch: | |
| env: | |
| REGISTRY: ghcr.io | |
| IMAGE_NAME: ${{ github.repository }} | |
| concurrency: | |
| group: deploy-main-${{ github.ref }} | |
| cancel-in-progress: false | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| permissions: | |
| contents: read | |
| packages: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - app: docs | |
| context: apps/docs | |
| image_suffix: docs | |
| - app: storybook | |
| context: packages/components | |
| image_suffix: storybook | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v6 | |
| - uses: ./.github/actions/prepare-workspace | |
| # The image used to build this itself, which meant a second toolchain | |
| # install and the whole dependency chain rebuilt inside the image — 80 of | |
| # the 449 seconds a docs preview took. Here the runner builds that chain | |
| # and the image only packages what comes out. | |
| # | |
| # NEXT_BASE_PATH was a build-arg for the same reason; the value is the one | |
| # the Dockerfile passed. | |
| - name: Build the docs | |
| if: matrix.image_suffix == 'docs' | |
| run: pnpm nx build docs | |
| env: | |
| NEXT_BASE_PATH: "" | |
| # `main` is the writer that seeds this cache for everyone else. A PR reads | |
| # caches from its own branch and from the default branch, never from | |
| # another PR's. Without an entry written here the broadest restore-key in | |
| # build-previews.yml finds nothing, so every PR's first docs build | |
| # compiles cold. Turbopack's persistent build cache lives in this | |
| # directory (~200MB) and is on by default in Next 16. | |
| # | |
| # Save only — the same split as the nx cache (test.yml writes, everyone | |
| # else restores). What this job builds goes straight to production, so it | |
| # depends on the source and the lockfile alone, never on a blob an earlier | |
| # run left behind. Restoring here would also let the broadest restore-key | |
| # carry a cache across a Next version bump into the deployed image. After | |
| # the build rather than in a post-step, so a build that failed seeds | |
| # nothing. | |
| - name: Save the Next.js build cache | |
| if: matrix.image_suffix == 'docs' | |
| uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0 | |
| with: | |
| path: apps/docs/.next/cache | |
| key: | |
| nextjs-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}-${{ | |
| github.sha }} | |
| # Two commands because `build:storybook` declares no nx dependency on the | |
| # components build — the same pair the Dockerfile ran. | |
| - name: Build Storybook | |
| if: matrix.image_suffix == 'storybook' | |
| run: | | |
| pnpm nx build components | |
| pnpm nx build:storybook components | |
| - name: Log in to the Container registry | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| registry: ${{ env.REGISTRY }} | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Extract metadata for Docs | |
| id: meta-docs | |
| if: matrix.image_suffix == 'docs' | |
| uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 | |
| with: | |
| images: | |
| ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}/${{ matrix.image_suffix }} | |
| tags: | | |
| type=ref,event=branch | |
| type=raw,value=latest | |
| type=sha | |
| - name: Extract metadata for Storybook | |
| id: meta-storybook | |
| if: matrix.image_suffix == 'storybook' | |
| uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 | |
| with: | |
| images: | |
| ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}/${{ matrix.image_suffix }} | |
| tags: | | |
| type=ref,event=branch | |
| type=raw,value=latest | |
| type=sha | |
| - name: Build and push Docker image | |
| uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 | |
| with: | |
| # The built output and the server config beside it, nothing else — see | |
| # the context's own .dockerignore. | |
| context: ${{ matrix.context }} | |
| push: true | |
| provenance: false # single-manifest image (as before v7) | |
| tags: | |
| ${{ matrix.image_suffix == 'docs' && steps.meta-docs.outputs.tags || | |
| steps.meta-storybook.outputs.tags }} | |
| labels: | |
| ${{ matrix.image_suffix == 'docs' && steps.meta-docs.outputs.labels | |
| || steps.meta-storybook.outputs.labels }} | |
| - name: Trigger docs redeploy webhook | |
| if: matrix.image_suffix == 'docs' | |
| run: | |
| curl --fail --silent --show-error --location "$FLOW_REDEPLOY_WEBHOOK" | |
| env: | |
| FLOW_REDEPLOY_WEBHOOK: ${{ secrets.FLOW_REDEPLOY_WEBHOOK }} | |
| - name: Trigger storybook redeploy webhook | |
| if: matrix.image_suffix == 'storybook' | |
| run: | |
| curl --fail --silent --show-error --location | |
| "$STORYBOOK_REDEPLOY_WEBHOOK" | |
| env: | |
| STORYBOOK_REDEPLOY_WEBHOOK: ${{ secrets.STORYBOOK_REDEPLOY_WEBHOOK }} |