From dcc7c0c7c4c9cb0ffb1de683613618e839334134 Mon Sep 17 00:00:00 2001 From: Theodore Li Date: Wed, 1 Jul 2026 19:02:59 -0700 Subject: [PATCH] ci(dev): auto-deploy Trigger.dev tasks + fail dev db:push on TTY prompt (#5343) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * ci(trigger): auto-deploy Trigger.dev tasks to dev-sim on dev pushes Add a deploy-trigger-dev job that runs `trigger.dev deploy --env preview --branch dev-sim` on pushes to the dev branch, replacing the manual step. Gated after migrate-dev for the same reason as build-dev: the new task code runs against the dev DB, so the schema must be pushed first. Uses Trigger.dev's remote build (no --local-build), so the runner needs no Docker/buildx. Requires a TRIGGER_ACCESS_TOKEN repo secret. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_015orsjbLX34FPFGujSK3AQK * ci(trigger): source TRIGGER_PROJECT_ID from repo secret Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_015orsjbLX34FPFGujSK3AQK * ci(trigger): fail fast when Trigger.dev secrets are unset Guard the deploy step so a missing TRIGGER_ACCESS_TOKEN or TRIGGER_PROJECT_ID exits with a clear message instead of a cryptic trigger.dev CLI error, matching the DATABASE_URL guard in migrations.yml. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_015orsjbLX34FPFGujSK3AQK * ci(migrations): fail dev db:push on interactive prompt or error drizzle-kit push prompts interactively for ambiguous renames (--force only covers data-loss). In CI there's no TTY, so the prompt reads EOF and drizzle can exit 0 without applying — the job goes green while the schema change was silently skipped. Close stdin, reject prompt markers, and require a success marker so an unresolved rename or failed statement fails the job. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_015orsjbLX34FPFGujSK3AQK * ci(migrations): fail dev db:push when drizzle-kit hits a TTY prompt drizzle-kit push needs a TTY to resolve ambiguous renames; in CI it throws "Interactive prompts require a TTY terminal" but still exits 0, so the job went green without applying the schema (e.g. run 28415609570). Fail on that explicit error. Keys on drizzle's own stable message rather than fuzzy prompt text, and a real non-zero exit still fails via set -e. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_015orsjbLX34FPFGujSK3AQK * ci(trigger): scope the access token secret as DEV_TRIGGER_ACCESS_TOKEN The PAT is only used by the dev deploy job, so prefix it DEV_ to match the repo's dev-scoped secret convention. TRIGGER_PROJECT_ID stays unprefixed — it's the shared project (same one prod uses); dev-sim is a preview branch within it, not a separate project. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_015orsjbLX34FPFGujSK3AQK * Adjust warning error * ci: align build-dev checkout to v6 to match the other jobs build-dev was the only job still pinning actions/checkout to the v4 hash; every other job uses v6. Non-functional consistency fix. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_015orsjbLX34FPFGujSK3AQK --------- Co-authored-by: Claude Opus 4.8 (1M context) --- .github/workflows/ci.yml | 47 ++++++++++++++++++++++++++++++-- .github/workflows/migrations.yml | 11 +++++++- 2 files changed, 55 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c62cd2f2d1..25d8348d8c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -92,7 +92,7 @@ jobs: ecr_repo_secret: ECR_PII steps: - name: Checkout code - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 - name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@e7f100cf4c008499ea8adda475de1042d6975c7b # v6 @@ -130,6 +130,49 @@ jobs: provenance: false sbom: false + # Dev: deploy Trigger.dev background tasks to the preview "dev-sim" branch. + # Gated after migrate-dev for the same reason as build-dev — the new task + # code runs against the dev DB, so the schema must be pushed first. + deploy-trigger-dev: + name: Deploy Trigger.dev (Dev) + needs: [migrate-dev] + if: github.event_name == 'push' && github.ref == 'refs/heads/dev' + runs-on: blacksmith-4vcpu-ubuntu-2404 + steps: + - name: Checkout code + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 + + - name: Setup Bun + uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 + with: + bun-version: 1.3.13 + + - name: Cache Bun dependencies + uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5 + with: + path: | + ~/.bun/install/cache + node_modules + **/node_modules + key: ${{ runner.os }}-bun-${{ hashFiles('**/bun.lock') }} + restore-keys: | + ${{ runner.os }}-bun- + + - name: Install dependencies + run: bun install --frozen-lockfile + + - name: Deploy to Trigger.dev + working-directory: ./apps/sim + env: + TRIGGER_ACCESS_TOKEN: ${{ secrets.DEV_TRIGGER_ACCESS_TOKEN }} + TRIGGER_PROJECT_ID: ${{ secrets.TRIGGER_PROJECT_ID }} + run: | + if [ -z "$TRIGGER_ACCESS_TOKEN" ] || [ -z "$TRIGGER_PROJECT_ID" ]; then + echo "ERROR: DEV_TRIGGER_ACCESS_TOKEN and TRIGGER_PROJECT_ID repo secrets must both be set" >&2 + exit 1 + fi + bunx trigger.dev@4.4.3 deploy --env preview --branch dev-sim + # Main/staging: build AMD64 images and push to ECR + GHCR build-amd64: name: Build AMD64 @@ -359,7 +402,7 @@ jobs: steps: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 with: - fetch-depth: 2 # Need at least 2 commits to detect changes + fetch-depth: 2 # Need at least 2 commits to detect changes - uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4 id: filter with: diff --git a/.github/workflows/migrations.yml b/.github/workflows/migrations.yml index f789ec3262..7965eaf5e6 100644 --- a/.github/workflows/migrations.yml +++ b/.github/workflows/migrations.yml @@ -69,7 +69,16 @@ jobs: if [ "${ENVIRONMENT}" = "dev" ]; then echo "Dev environment — pushing schema directly (db:push)" - bun run db:push --force + # drizzle-kit push needs a TTY to resolve ambiguous renames (--force only + # covers data-loss). In CI it throws "Interactive prompts require a TTY + # terminal" but still exits 0, so the job goes green without applying the + # change. tee keeps the output live in the log; we then fail on drizzle's + # own TTY error. A genuine non-zero exit already fails via `set -e`. + bun run db:push --force < /dev/null 2>&1 | tee /tmp/db-push.log + if grep -q "Interactive prompts require a TTY terminal" /tmp/db-push.log; then + echo "ERROR: db:push needs an interactive rename decision; land it as a versioned migration instead of relying on push." >&2 + exit 1 + fi else echo "Applying versioned migrations (db:migrate)" bun run ./scripts/migrate.ts