From 9e3844fd897f03c23f9500ca703fcd9a954749bb Mon Sep 17 00:00:00 2001 From: Satoshi Qazi Muhammed Date: Thu, 30 Jul 2026 02:02:28 -0700 Subject: [PATCH] ci: deploy each function to the project that actually serves it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The functions in this repo do not all live in the same place, and the deploy step I added yesterday sent all of them to the self-hosted host on vps3. telegram-bot and ask are served from the cloud project vbhftvdayqfmcgmzdxfv. Both Telegram bots reach it by webhook — ?bot=krd is @pezkuwichainBot and ?bot=dks is @DKSKurdistanBot — and news.pex.mom's assistant calls ask there. Copies of both still sit in the vps3 volume from before that split, holding a bot token revoked on 2026-07-19, and take no traffic. Deploying to vps3 was therefore updating a dead copy while the live one kept running old code. So the self-hosted job now excludes those two, and a second job deploys them to the cloud project. That closes a real gap: they had been deployed by hand for months, and git drifted far enough behind that on 2026-07-21 the running function body had to be extracted from the deployed bundle to recover it. The host registry records the split too, so the gate cannot be pointed at the wrong target by accident. --- .github/workflows/deploy.yml | 40 ++++++++++++++++++++++++++++++++++-- 1 file changed, 38 insertions(+), 2 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 2740ea9..baabf0a 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -70,14 +70,22 @@ jobs: # stops a repeat of the 2026-06-28 incident where another project's deploy # silently replaced telegram-auth and broke sign-in for a month. deploy-functions: - name: Deploy edge functions + name: Deploy edge functions (self-hosted) needs: deploy runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 + # telegram-bot and ask are excluded on purpose: both Telegram bots and the + # news.pex.mom assistant are served from the cloud project, not from here. + # Stale copies of both still sit in this volume from before that split and + # take no traffic. They are deployed by the deploy-cloud-functions job. - name: Package functions - run: tar czf functions.tgz -C supabase functions + run: | + tar czf functions.tgz -C supabase \ + --exclude='functions/telegram-bot' \ + --exclude='functions/ask' \ + functions - name: Copy to staging on VPS uses: appleboy/scp-action@v1.0.0 @@ -104,3 +112,31 @@ jobs: --project pezkuwi-telegram-miniapp \ --src "$BASE/functions" \ --restart + + # The two Telegram bots and the news.pex.mom assistant run on the cloud + # Supabase project, reached by webhook at + # vbhftvdayqfmcgmzdxfv.supabase.co/functions/v1/telegram-bot?bot=krd|dks. + # These were deployed by hand for months, which let the source in git drift + # behind what was actually running — badly enough that on 2026-07-21 the live + # function body had to be pulled back out of the deployed bundle to recover it. + deploy-cloud-functions: + name: Deploy edge functions (cloud) + needs: deploy + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - name: Deploy telegram-bot and ask + env: + SUPABASE_ACCESS_TOKEN: ${{ secrets.SUPABASE_ACCESS_TOKEN }} + run: | + set -e + if [ -z "$SUPABASE_ACCESS_TOKEN" ]; then + echo "::error::SUPABASE_ACCESS_TOKEN is not set — the bots would silently keep running old code" + exit 1 + fi + for fn in telegram-bot ask; do + npx --yes supabase@latest functions deploy "$fn" \ + --project-ref vbhftvdayqfmcgmzdxfv \ + --no-verify-jwt + done