diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 2740ea9..baabf0a 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -70,14 +70,22 @@ jobs: # stops a repeat of the 2026-06-28 incident where another project's deploy # silently replaced telegram-auth and broke sign-in for a month. deploy-functions: - name: Deploy edge functions + name: Deploy edge functions (self-hosted) needs: deploy runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 + # telegram-bot and ask are excluded on purpose: both Telegram bots and the + # news.pex.mom assistant are served from the cloud project, not from here. + # Stale copies of both still sit in this volume from before that split and + # take no traffic. They are deployed by the deploy-cloud-functions job. - name: Package functions - run: tar czf functions.tgz -C supabase functions + run: | + tar czf functions.tgz -C supabase \ + --exclude='functions/telegram-bot' \ + --exclude='functions/ask' \ + functions - name: Copy to staging on VPS uses: appleboy/scp-action@v1.0.0 @@ -104,3 +112,31 @@ jobs: --project pezkuwi-telegram-miniapp \ --src "$BASE/functions" \ --restart + + # The two Telegram bots and the news.pex.mom assistant run on the cloud + # Supabase project, reached by webhook at + # vbhftvdayqfmcgmzdxfv.supabase.co/functions/v1/telegram-bot?bot=krd|dks. + # These were deployed by hand for months, which let the source in git drift + # behind what was actually running — badly enough that on 2026-07-21 the live + # function body had to be pulled back out of the deployed bundle to recover it. + deploy-cloud-functions: + name: Deploy edge functions (cloud) + needs: deploy + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - name: Deploy telegram-bot and ask + env: + SUPABASE_ACCESS_TOKEN: ${{ secrets.SUPABASE_ACCESS_TOKEN }} + run: | + set -e + if [ -z "$SUPABASE_ACCESS_TOKEN" ]; then + echo "::error::SUPABASE_ACCESS_TOKEN is not set — the bots would silently keep running old code" + exit 1 + fi + for fn in telegram-bot ask; do + npx --yes supabase@latest functions deploy "$fn" \ + --project-ref vbhftvdayqfmcgmzdxfv \ + --no-verify-jwt + done