Skip to content

docs(starlight): migrate social config from record to array shape #15

docs(starlight): migrate social config from record to array shape

docs(starlight): migrate social config from record to array shape #15

# docs-deploy-trigger — fire a repository_dispatch into sbpp.github.io

Check failure on line 1 in .github/workflows/docs-deploy-trigger.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/docs-deploy-trigger.yml

Invalid workflow file

(Line: 67, Col: 13): Unrecognized named-value: 'secrets'. Located at position 1 within expression: secrets.DOCS_DEPLOY_PAT != ''
# whenever main moves under docs/, kicking the Pages deploy in the
# sibling repo.
#
# Cadence: only on push to main with a docs/** path filter. PRs use
# docs-build.yml to validate; this workflow is the production trigger.
#
# Required repo configuration BEFORE this workflow does anything (one-time
# cutover step):
#
# - Create a fine-grained PAT scoped to `sbpp/sbpp.github.io` only,
# with the `Actions: Read and write` repository permission. (Classic
# PATs work too, but the fine-grained variant is strictly narrower
# and the right default.) Max expiry is one year — set a calendar
# reminder to rotate.
# - Repo SECRET `DOCS_DEPLOY_PAT` = the token value.
#
# Until `DOCS_DEPLOY_PAT` is set, the dispatch step below is skipped via
# its `if: secrets.DOCS_DEPLOY_PAT != ''` guard — every push to `docs/**`
# shows up as a green run with the dispatch step marked "Skipped",
# instead of red-failing on a missing credential. This stops the
# original anti-pattern (#1339-followup) where the dispatch hard-erred
# and an operator who hasn't done the cutover yet sees a stream of
# confusing failures.
#
# The deploy shell in sbpp.github.io also has a `workflow_dispatch`
# trigger as a manual fallback while the PAT is pending.
name: docs-deploy-trigger
on:
push:
branches:
- main
paths:
- 'docs/**'
- '.github/workflows/docs-deploy-trigger.yml'
# Allow at most one in-flight trigger at a time; if a second push lands
# while the first is still running, queue the second and skip any
# intermediate runs. The dispatched workflow in sbpp.github.io is
# itself idempotent (it always builds from sourcebans-pp@main), so
# coalescing here is safe.
concurrency:
group: docs-deploy-trigger
cancel-in-progress: false
jobs:
trigger:
name: Dispatch docs-changed event
runs-on: ubuntu-24.04
permissions: {}
steps:
# The dispatched workflow in sbpp.github.io listens for
# `event_type: docs-changed`. The client_payload carries the
# commit SHA and ref so the deploy job can pin its sourcebans-pp
# checkout to the exact commit that fired the dispatch (race
# guard for back-to-back pushes).
#
# Step-level `if:` evaluates against `secrets.*` (job-level `if:`
# does not), so we gate the dispatch directly on the PAT being
# configured — no separate feature-flag variable needed. When
# `DOCS_DEPLOY_PAT` is unset, the step is skipped and the run is
# green-with-skipped instead of red-failing.
- name: Dispatch repository_dispatch into sbpp.github.io
if: secrets.DOCS_DEPLOY_PAT != ''
env:
GH_TOKEN: ${{ secrets.DOCS_DEPLOY_PAT }}
run: |
gh api repos/sbpp/sbpp.github.io/dispatches \
--method POST \
--field event_type=docs-changed \
--field 'client_payload[source_repo]=${{ github.repository }}' \
--field 'client_payload[source_sha]=${{ github.sha }}' \
--field 'client_payload[source_ref]=${{ github.ref }}'