A development-proposal PR previously got no check at all (the workflow only fired on push to main) - so branch protection's required status check, the thing that makes the automation's merge_when_checks_succeed an actual lint gate, had nothing to require. Lint now runs on both events; the content-reload NATS publish stays push-only. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
37 lines
1.3 KiB
YAML
37 lines
1.3 KiB
YAML
name: Lint and reload
|
|
|
|
# Lint runs on PRs too - it's the status check branch protection
|
|
# requires before the development-commit automation's PRs may merge
|
|
# (merge_when_checks_succeed). The reload only ever fires on a push
|
|
# that actually landed on main.
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
lint:
|
|
runs-on: bare
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
# Same bare-metal runner/host as portal's own deploy job, which
|
|
# publishes this binary to a stable path on every deploy - runs
|
|
# portal's real transition-table/shape validation directly, not a
|
|
# hand-maintained yq/jq subset of the same rules (lint.sh, now
|
|
# superseded and removed).
|
|
- name: Lint questions
|
|
run: /srv/app/uhhm-portal/current/question_lint --path questions
|
|
|
|
reload:
|
|
runs-on: bare
|
|
needs: lint
|
|
if: github.event_name == 'push'
|
|
steps:
|
|
# Tells every running portal instance to re-fetch and atomically
|
|
# swap in the new content - see content::watch_for_reload in the
|
|
# portal repo. Fire and forget: no reply expected, no payload
|
|
# needed (the subject alone is the whole message).
|
|
- name: Tell portal to reload content
|
|
run: nats pub portal.content.reload '' --server "nats://infra:${{ secrets.NATS_TOKEN }}@127.0.0.1:4222"
|