rig: deploy from the root cph-staging checkout; guard against wrong-branch/dirty builds - #31
Merged
Merged
Conversation
…ranch/dirty builds The dedicated .worktrees/cph-staging worktree was retired when cph-staging became the primary root checkout (2026-07-20), which broke the Makefile's DEPLOY_DIR default. Point DEPLOY_DIR at the root checkout and add a check-deploy-src guard so builds refuse to run unless the checkout is on cph-staging with clean backend/ and frontend/ — production can never silently drift from branch history.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The checkout layout changed on 2026-07-20:
cph-stagingbecame the primary checkout at the repository root, and its dedicated worktree at.worktrees/cph-stagingwas removed (a branch can only be checked out in one place). That broke the deploy Makefile's defaultDEPLOY_DIR ?= $(MAIN_DIR)/.worktrees/cph-staging—make ship/make buildfailed on a nonexistent path.What
DEPLOY_DIRnow defaults to the root checkout (MAIN_DIR), which is thecph-stagingbranch.check-deploy-srcguard, a prerequisite ofbuild-api/build-web: refuses to build unless the deploy checkout is oncph-stagingand has no uncommittedbackend//frontend/changes. This mechanically enforces the project rule that production is always built from committedcph-staginghistory (every change lands via a PR first), closing the drift class found earlier where production ran an un-pushed local commit.Verification
DEPLOY_DIRpointed at thecph-masterworktree.make check-deploy-srcgreen on cleancph-staging) + livemake smokeverified post-merge.Follow-up to #28 (which repointed deploys at the cph-staging worktree before the worktree was retired).