Commit Graph

3 Commits

Author SHA1 Message Date
Marcos Paulo 25ef5af63e fix: refuse to publish a build that logged a vite error
verify-and-publish / gate (push) Successful in 14m30s
verify-and-publish / publish (push) Has been skipped
The build output went to /dev/null and only the exit code was checked,
which `astro build` returns as 0 even when vite cannot resolve an asset.
Run by hand -- the gate is not in the loop then -- this script would have
force-pushed that build over the live site.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-06 09:15:42 +00:00
Marcos Paulo 6b4f2e6bd0 fix: give publish-pages a temp index path that does not exist yet
git reads an existing empty file as a truncated index and dies with
"index file smaller than expected", so mktemp's own file cannot be used
as GIT_INDEX_FILE.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-06 09:09:42 +00:00
Marcos Paulo dc6cb5a0a3 ci: publish to pages from a pre-push hook
verify-and-publish / gate (push) Successful in 22m13s
verify-and-publish / publish (push) Has been skipped
Pushing main now rebuilds the site and force-pushes dist/ to pages.

.agents/scripts/publish-pages.sh does the work. It never checks pages
out: it writes a tree straight from dist/ with write-tree and
commit-tree, so the working tree is untouched and a failure halfway
through leaves nothing behind. The commit is parented on the current
pages tip, so the branch keeps its history and a rollback is one
force-push to an earlier commit -- which the script prints before it
pushes.

It refuses to publish when the working tree is dirty, when HEAD is not
main, when HEAD is not the commit being pushed, or when any of the ten
routes is missing or empty in dist/. A build can succeed and still emit a
stub; that is exactly how this site would go down.

The hook guards three ways. AF_PUBLISHING short-circuits it so the
publisher's own push does not re-enter it forever. AF_NO_PUBLISH=1 lets
you push main without publishing. And because git has no post-push hook,
the publish necessarily runs before main lands -- so it first checks that
the remote tip is an ancestor of what is being pushed, and skips
publishing when the push could still be rejected as a non-fast-forward.

Also rewrites the operations guide's rollback section, which still
described merging main into pages with --ff-only. That has not been true
since pages started carrying build output.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-06 09:06:21 +00:00