@@ -167,93 +167,6 @@ jobs:
167167 - '!webapp/src/**/*.stories.*'
168168 - '!webapp/src/test/**'
169169
170- # Coolify creates previews for trusted same-repository pull requests. This job waits for the
171- # immutable application-server image, then updates the preview to the exact head commit. Coolify's
172- # deploy API only accepts a pull request that already has a preview, so a missing preview remains a
173- # safe no-op. Instance identifiers come from repository variables; forks never receive credentials.
174- preview :
175- name : " Preview / Coolify"
176- runs-on : ubuntu-latest
177- # Wait for Docker so SOURCE_COMMIT always names an image that already exists in GHCR. `always`
178- # preserves the link/no-op behavior when the Docker workflow is legitimately skipped.
179- needs : [detect-changes, Docker]
180- if : >-
181- always() &&
182- github.event_name == 'pull_request' &&
183- vars.COOLIFY_URL != '' &&
184- vars.COOLIFY_APP_UUID != '' &&
185- (needs.Docker.result == 'success' || needs.Docker.result == 'skipped')
186- permissions :
187- statuses : write
188- timeout-minutes : 2
189- env :
190- COOLIFY_URL : ${{ vars.COOLIFY_URL }}
191- COOLIFY_APP_UUID : ${{ vars.COOLIFY_APP_UUID }}
192- COOLIFY_PROJECT_UUID : ${{ vars.COOLIFY_PROJECT_UUID }}
193- COOLIFY_ENVIRONMENT_UUID : ${{ vars.COOLIFY_ENVIRONMENT_UUID }}
194- steps :
195- - name : Link the preview deployments page on the PR
196- if : vars.COOLIFY_PROJECT_UUID != '' && vars.COOLIFY_ENVIRONMENT_UUID != ''
197- uses : actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
198- with :
199- script : |
200- const { COOLIFY_URL, COOLIFY_PROJECT_UUID, COOLIFY_ENVIRONMENT_UUID, COOLIFY_APP_UUID } = process.env;
201- await github.rest.repos.createCommitStatus({
202- owner: context.repo.owner,
203- repo: context.repo.repo,
204- sha: context.payload.pull_request.head.sha,
205- state: 'success',
206- target_url: `${COOLIFY_URL}/project/${COOLIFY_PROJECT_UUID}/environment/${COOLIFY_ENVIRONMENT_UUID}/application/${COOLIFY_APP_UUID}/preview-deployments`,
207- description: 'Click Details to view Coolify preview deployments',
208- context: 'Preview / Coolify',
209- });
210-
211- # Forks are skipped deliberately: a preview runs with the instance's real credentials.
212- - name : Update this PR's preview deployment, if it has one
213- if : >-
214- (github.event.action == 'opened' ||
215- github.event.action == 'reopened' ||
216- github.event.action == 'synchronize') &&
217- github.event.pull_request.head.repo.full_name == github.repository
218- env :
219- COOLIFY_TOKEN : ${{ secrets.COOLIFY_API_TOKEN }}
220- PR_NUMBER : ${{ github.event.pull_request.number }}
221- APP_SERVER_PUBLISHED : ${{ needs.Docker.outputs.application-server-published }}
222- run : |
223- set -euo pipefail
224-
225- if [ -z "${COOLIFY_TOKEN}" ]; then
226- echo "::notice::COOLIFY_API_TOKEN is not configured; skipping preview update."
227- exit 0
228- fi
229-
230- # Coolify pins the preview to SOURCE_COMMIT, so without that tag the deployment can only
231- # fail on `manifest unknown` — under a green check, since queueing one always succeeds.
232- if [ "${APP_SERVER_PUBLISHED}" != 'true' ]; then
233- echo "::notice::No application-server image for this commit; skipping preview update."
234- exit 0
235- fi
236-
237- body=$(mktemp)
238- status=$(curl -sS -o "${body}" -w '%{http_code}' -X POST \
239- -H "Authorization: Bearer ${COOLIFY_TOKEN}" \
240- -H 'Accept: application/json' \
241- --retry 3 --retry-connrefused --max-time 30 \
242- "${COOLIFY_URL}/api/v1/deploy?uuid=${COOLIFY_APP_UUID}&pr=${PR_NUMBER}")
243-
244- if [ "${status}" -ge 400 ]; then
245- echo "::error::Coolify returned HTTP ${status}: $(cat "${body}")"
246- exit 1
247- fi
248-
249- deployment=$(jq -r '.deployments[0].deployment_uuid // empty' "${body}")
250- if [ -z "${deployment}" ]; then
251- echo "::notice::PR #${PR_NUMBER} has no preview deployment ($(jq -r '.deployments[0].message // "no deployment queued"' "${body}"))."
252- exit 0
253- fi
254-
255- echo "::notice::Queued Coolify deployment ${deployment} for PR #${PR_NUMBER}."
256-
257170 Quality :
258171 uses : ./.github/workflows/ci-quality-gates.yml
259172 needs : [detect-changes]
@@ -308,9 +221,9 @@ jobs:
308221 # Image builds consume the detected source tree, not Quality outputs. Running both branches at
309222 # once keeps image and preview confidence without adding Docker as a second CI stage.
310223 needs : [detect-changes]
311- # Every same-repository pull request gets a Coolify preview pinned to SOURCE_COMMIT , so it needs
312- # an application-server tag at its head commit even when it touches only docs or the preview
313- # stack. The path filters below therefore gate fork pull requests only — forks get no preview.
224+ # Any same-repository pull request can be opted into a preview after CI , so it needs signed,
225+ # commit-addressed image tags even when it touches only docs or the preview stack. The path
226+ # filters below therefore gate fork pull requests only; forks never receive a preview.
314227 if : |
315228 needs.detect-changes.outputs.should_skip != 'true' && (
316229 github.event_name != 'pull_request' ||
0 commit comments