From 522197defbb93d6e0de0cfaae8d4c23a85fc5e16 Mon Sep 17 00:00:00 2001 From: imharrisonking Date: Mon, 21 Sep 2026 15:47:18 +0100 Subject: [PATCH 1/2] fix: clean preview stages for closed PRs --- .github/workflows/pr-preview-cleanup.yml | 42 +++++++++++++++--------- 1 file changed, 27 insertions(+), 15 deletions(-) diff --git a/.github/workflows/pr-preview-cleanup.yml b/.github/workflows/pr-preview-cleanup.yml index 9c19c8f..6c6e6b0 100644 --- a/.github/workflows/pr-preview-cleanup.yml +++ b/.github/workflows/pr-preview-cleanup.yml @@ -1,7 +1,10 @@ name: PR Cleanup on: - pull_request: + # Run from the base branch so closing a PR targeting dev is cleaned up too. + # This workflow only destroys an explicitly derived pr-N stage and does not + # execute code from the closed PR. + pull_request_target: types: [closed] workflow_dispatch: inputs: @@ -16,7 +19,7 @@ permissions: env: AWS_REGION: eu-west-2 - STAGE_NAME: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.pull_request.number) || format('pr-{0}', github.event.inputs.pr_number) }} + STAGE_NAME: ${{ github.event_name == 'pull_request_target' && format('pr-{0}', github.event.pull_request.number) || format('pr-{0}', github.event.inputs.pr_number) }} jobs: # =========================================== @@ -58,22 +61,31 @@ jobs: # credentials, and provider errors should fail the job directly. run: | set +e - LOG_FILE="$RUNNER_TEMP/sst-remove.log" - npx sst remove --stage "${{ env.STAGE_NAME }}" --print-logs 2>&1 | tee "$LOG_FILE" - EXIT_CODE=${PIPESTATUS[0]} + MAX_ATTEMPTS=3 + for attempt in $(seq 1 "$MAX_ATTEMPTS"); do + LOG_FILE="$RUNNER_TEMP/sst-remove-${attempt}.log" + npx sst remove --stage "${{ env.STAGE_NAME }}" --print-logs 2>&1 | tee "$LOG_FILE" + EXIT_CODE=${PIPESTATUS[0]} - if [ "$EXIT_CODE" -eq 0 ]; then - exit 0 - fi + if [ "$EXIT_CODE" -eq 0 ]; then + exit 0 + fi - if grep -Eiq 'lock|already[[:space:]]+running|another[[:space:]].*process|acquir(e|ing).*state' "$LOG_FILE"; then - echo "lock_failure=true" >> "$GITHUB_OUTPUT" - echo "SST removal failed because the stage appears to be locked; retrying after unlock." - exit 0 - fi + if grep -Eiq 'lock|already[[:space:]]+running|another[[:space:]].*process|acquir(e|ing).*state' "$LOG_FILE"; then + echo "lock_failure=true" >> "$GITHUB_OUTPUT" + echo "SST removal failed because the stage appears to be locked; retrying after unlock." + exit 0 + fi - echo "SST removal failed for a non-lock error; not retrying." - exit "$EXIT_CODE" + if grep -Eiq 'bad status: 5[0-9]{2}|gateway timeout|could not install bun|timed out|econnreset' "$LOG_FILE" && [ "$attempt" -lt "$MAX_ATTEMPTS" ]; then + echo "Transient SST bootstrap/network failure; retrying in 10 seconds (attempt $((attempt + 1))/$MAX_ATTEMPTS)." + sleep 10 + continue + fi + + echo "SST removal failed for a non-retryable error." + exit "$EXIT_CODE" + done - name: Clear stale SST lock if: steps.destroy.outputs.lock_failure == 'true' From ae8369b2af7429de2d6cffdb5ff10c7046a9047a Mon Sep 17 00:00:00 2001 From: imharrisonking Date: Tue, 22 Sep 2026 09:42:48 +0100 Subject: [PATCH 2/2] ci: deploy production through GitHub Actions --- .github/workflows/deploy.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 2d8a945..282d6d6 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -2,7 +2,7 @@ name: Deploy on: push: - branches: [dev] + branches: [dev, production] workflow_dispatch: concurrency: