Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 38 additions & 6 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,15 @@
name: Test
name: Test & Deploy

# Deploy automation is deferred deliberately, same rationale as
# Sentinel-License-Service's workflow of the same name: a human should
# be watching the first-ever deploy of new infrastructure (including,
# for this service, the first-ever Postgres instance in this family).
# This workflow only covers lint + dependency audit + tests.
# Tests on every push and PR; deploys to Fly on pushes to master.
#
# Deploy automation used to be deferred here so a human could watch the
# first-ever deploy of new infrastructure. That rationale expired once
# the service was live, and leaving it deferred created a worse problem:
# fly.toml became a file that did nothing. A scale-to-zero change was
# merged with CI green on 2026-09-09 and simply never reached Fly —
# the app kept running always-on until someone noticed and deployed by
# hand. Config that silently doesn't apply is more dangerous than no
# config, so this now ships.
#
# Unlike License-Service's version, this one needs a real Postgres
# service container — JSONB isn't SQLite-portable, and this service is
Expand Down Expand Up @@ -63,3 +68,30 @@ jobs:

- name: Run tests
run: uv run pytest -v

deploy:
name: Deploy to Fly.io
runs-on: ubuntu-latest
needs: test
# Push-only: a PR runs the tests above but never ships.
if: github.event_name == 'push'
# Serialize so two quick pushes don't race on the machine update.
concurrency:
group: deploy-sentinel-sync
cancel-in-progress: true
steps:
- uses: actions/checkout@v7

- uses: superfly/flyctl-actions/setup-flyctl@master

# --ha=false: Fly provisions TWO machines by default and this
# service needs one. It did exactly that on the 2026-09-09 manual
# deploy and the extra machine had to be scaled away by hand.
#
# No --strategy override: this app has no volume, so the default
# rolling strategy works. (Command Center needs `immediate`
# because its web machine mounts a single-attachment volume.)
- name: flyctl deploy
run: flyctl deploy --remote-only --ha=false --yes
env:
FLY_API_TOKEN: ${{ secrets.FLY_API_TOKEN }}