From 92b657368c0b7935c55b7cf730a595aa65424467 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Mon, 28 Sep 2026 09:27:06 +0200 Subject: [PATCH] fix(docs): skip the docs deploy on pushes to the template itself After #190 the secrets guard worked: run 36390914494 skipped the Cloudflare publish and no app-template.conduction.nl record exists. But the shared workflow's "Verify the LIVE site" step then failed the run, as it does for any skipped publish, so every docs push to the template went red. In the template, pushes now skip the job. Pull requests still run it, and there the shared workflow only builds and validates. Scaffolded apps are not templates, so they run every push as before. The secrets guard stays as a second line of defence. --- .github/workflows/documentation.yml | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/.github/workflows/documentation.yml b/.github/workflows/documentation.yml index 97c68ad..24e862d 100644 --- a/.github/workflows/documentation.yml +++ b/.github/workflows/documentation.yml @@ -15,17 +15,21 @@ on: jobs: deploy: uses: ConductionNL/.github/.github/workflows/documentation.yml@main - # A reusable workflow receives no secrets by default. Without this mapping - # the publish step finds CF_API_TOKEN empty, skips itself, and the run ends - # green having changed nothing. - # # The template repository itself must never publish: the org secrets reach # it, and the deploy registers every host as a Cloudflare custom domain, so # one push here would put a live app-template.conduction.nl site online. - # The check reads GitHub's is_template flag rather than the repository name, - # because app-create rewrites the template's repository name into the new - # app's, which would switch publishing off in every scaffolded app. - # The template still builds and validates its docs on every run. + # Both guards read GitHub's is_template flag rather than the repository + # name, because app-create rewrites the template's repository name into the + # new app's, which would switch publishing off in every scaffolded app. + # + # In the template, pushes skip this job entirely: the shared workflow's + # "Verify the LIVE site" step fails every run whose publish was skipped. + # Pull requests still run it, and on a pull request the shared workflow + # only builds and validates, so the template's docs stay checked. + if: ${{ !github.event.repository.is_template || github.event_name == 'pull_request' }} + # A reusable workflow receives no secrets by default; without this mapping + # the publish step skips and nothing reaches the live site. The template + # never gets the secrets, even if the job above is ever made to run. secrets: CF_API_TOKEN: ${{ !github.event.repository.is_template && secrets.CF_API_TOKEN || '' }} CF_ACCOUNT_ID: ${{ !github.event.repository.is_template && secrets.CF_ACCOUNT_ID || '' }}