diff --git a/.github/workflows/deploy-relay.yml b/.github/workflows/deploy-relay.yml index db0f7e63d7..6a55960738 100644 --- a/.github/workflows/deploy-relay.yml +++ b/.github/workflows/deploy-relay.yml @@ -1,9 +1,16 @@ name: Deploy Pylon Connect relay on: + # Only relay changes deploy. The relay also bundles shared workspace packages, + # but those change on nearly every merge and would redeploy production each + # time; when one of them matters to the relay, dispatch this workflow by hand. + # This file is deliberately not listed, so editing the workflow never deploys. push: branches: - pylon + paths: + - infra/relay/** + - "!infra/relay/**/*.md" # Infrastructure drifts and deploys fail for reasons unrelated to a commit, # so the stack can be reapplied without pushing one. workflow_dispatch: @@ -70,7 +77,7 @@ jobs: # no-op after the first and survives the store being deleted. - name: Bootstrap Alchemy state store working-directory: infra/relay - run: node node_modules/alchemy/bin/cli.js cloudflare bootstrap + run: node node_modules/alchemy/bin/cli.js provider cloudflare bootstrap env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} diff --git a/docs/operations/release.md b/docs/operations/release.md index 64929b73c9..2aa477b9cb 100644 --- a/docs/operations/release.md +++ b/docs/operations/release.md @@ -104,8 +104,8 @@ The relay is a shared control plane versioned separately from client releases. S client builds must point at the same relay so users see the same linked environments when switching release channels. -`.github/workflows/deploy-relay.yml` deploys Alchemy stage `prod` on pushes to `pylon` when the -`DEPLOY_RELAY` repository variable is `true`. Operators can also run it manually from `pylon`; +`.github/workflows/deploy-relay.yml` deploys Alchemy stage `prod` when a push to `pylon` changes +`infra/relay/` and the `DEPLOY_RELAY` repository variable is `true`. Operators can also run it manually from `pylon`; runs selected from other branches do not deploy. The release workflow reads the relay URL and Clerk client configuration from the existing `production` GitHub Actions environment before building desktop, CLI, or hosted web artifacts. diff --git a/infra/relay/README.md b/infra/relay/README.md index e216bf3200..af52c2e12a 100644 --- a/infra/relay/README.md +++ b/infra/relay/README.md @@ -128,7 +128,8 @@ Recover by deploying beta.76 or later again; do not edit `relay_migrations` by h ### Deployment CI The relay is versioned separately from client releases. `.github/workflows/deploy-relay.yml` deploys -the shared Alchemy `prod` stage on every push to `pylon`. Stable and nightly release builds both +the shared Alchemy `prod` stage when a push to `pylon` changes `infra/relay/`. A change that reaches +the relay only through a shared workspace package needs a manual run of that workflow. Stable and nightly release builds both resolve their static public config from the same `production` GitHub environment. Pull requests do not deploy relay stages. Developers can deploy personal non-production stages locally with any stage name other than `prod`.