ci: deploy each function to the project that actually serves it

The functions in this repo do not all live in the same place, and the deploy
step I added yesterday sent all of them to the self-hosted host on vps3.

telegram-bot and ask are served from the cloud project vbhftvdayqfmcgmzdxfv.
Both Telegram bots reach it by webhook — ?bot=krd is @pezkuwichainBot and
?bot=dks is @DKSKurdistanBot — and news.pex.mom's assistant calls ask there.
Copies of both still sit in the vps3 volume from before that split, holding a
bot token revoked on 2026-07-19, and take no traffic. Deploying to vps3 was
therefore updating a dead copy while the live one kept running old code.

So the self-hosted job now excludes those two, and a second job deploys them to
the cloud project. That closes a real gap: they had been deployed by hand for
months, and git drifted far enough behind that on 2026-07-21 the running
function body had to be extracted from the deployed bundle to recover it.

The host registry records the split too, so the gate cannot be pointed at the
wrong target by accident.
This commit is contained in:
2026-07-30 02:02:28 -07:00
parent aa5ea29106
commit 9e3844fd89
+38 -2
View File
@@ -70,14 +70,22 @@ jobs:
# stops a repeat of the 2026-06-28 incident where another project's deploy
# silently replaced telegram-auth and broke sign-in for a month.
deploy-functions:
name: Deploy edge functions
name: Deploy edge functions (self-hosted)
needs: deploy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# telegram-bot and ask are excluded on purpose: both Telegram bots and the
# news.pex.mom assistant are served from the cloud project, not from here.
# Stale copies of both still sit in this volume from before that split and
# take no traffic. They are deployed by the deploy-cloud-functions job.
- name: Package functions
run: tar czf functions.tgz -C supabase functions
run: |
tar czf functions.tgz -C supabase \
--exclude='functions/telegram-bot' \
--exclude='functions/ask' \
functions
- name: Copy to staging on VPS
uses: appleboy/scp-action@v1.0.0
@@ -104,3 +112,31 @@ jobs:
--project pezkuwi-telegram-miniapp \
--src "$BASE/functions" \
--restart
# The two Telegram bots and the news.pex.mom assistant run on the cloud
# Supabase project, reached by webhook at
# vbhftvdayqfmcgmzdxfv.supabase.co/functions/v1/telegram-bot?bot=krd|dks.
# These were deployed by hand for months, which let the source in git drift
# behind what was actually running — badly enough that on 2026-07-21 the live
# function body had to be pulled back out of the deployed bundle to recover it.
deploy-cloud-functions:
name: Deploy edge functions (cloud)
needs: deploy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Deploy telegram-bot and ask
env:
SUPABASE_ACCESS_TOKEN: ${{ secrets.SUPABASE_ACCESS_TOKEN }}
run: |
set -e
if [ -z "$SUPABASE_ACCESS_TOKEN" ]; then
echo "::error::SUPABASE_ACCESS_TOKEN is not set — the bots would silently keep running old code"
exit 1
fi
for fn in telegram-bot ask; do
npx --yes supabase@latest functions deploy "$fn" \
--project-ref vbhftvdayqfmcgmzdxfv \
--no-verify-jwt
done