Skip to content

fix(deploy): stop the build command resolving to the home workspace - #174

Merged
chitcommit merged 2 commits into
mainfrom
fix/deploy-ignore-workspace
Sep 28, 2026
Merged

chitcommit merged 2 commits into
mainfrom
fix/deploy-ignore-workspace

Conversation

@chitcommit

@chitcommit chitcommit commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

The bug

wrangler deploy fails before uploading anything:

No projects found in "/home/ubuntu"
ERR_PNPM_RECURSIVE_EXEC_NO_PACKAGE  No package found in this workspace

/home/ubuntu/pnpm-workspace.yaml exists, so pnpm walks up past this repo, treats the home directory as the workspace root, finds no packages, and exits 1. The build command's cwd: ".." does not help — the stray workspace file is above that too.

Hit while deploying 03bfbd4 (#173). This blocks every deploy, not just that one.

Why the obvious fix is only half of it

--ignore-workspace fixes pnpm install. It does not fix pnpm exec, which reads the flag as the name of the command to run:

ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL  Command "--ignore-workspace" not found

--no-workspace-root-check fails identically. I tried both before settling on dropping pnpm exec: once the install populates the repo's own node_modules, the binary is addressable directly, so the command calls ./node_modules/.bin/vite.

Verified

Ran the exact new command in the repo root — install completes, vite build writes dist/public, ✓ built in 7.01s.

Both configs

deploy/system-wrangler.jsonc (the --config deploy path) and wrangler.jsonc (the Workers Builds path) carry the same command; both were broken, both fixed. They remain drifted on compatibility_date (2026-03-01 vs 2026-08-07) and observability — pre-existing, untouched here.

🤖 Generated with Claude Code

https://claude.ai/code/session_01W2qFSSKdbsxo7AS8Buo247

Summary by CodeRabbit

  • Chores
    • Updated deployment build steps to use locally installed build tools and install dependencies without workspace handling.
    • Kept build output in the dist/public directory and added a check that the generated site entry page exists and is not empty.

`wrangler deploy` fails before it uploads anything:

    No projects found in "/home/ubuntu"
    ERR_PNPM_RECURSIVE_EXEC_NO_PACKAGE  No package found in this workspace

`/home/ubuntu/pnpm-workspace.yaml` exists, so pnpm walks up past this repo,
treats the home directory as the workspace root, finds no packages there and
exits 1. Both `pnpm install` and `pnpm exec` hit it, and the build command runs
with `cwd: ".."`, which does not escape the problem — the workspace file is
above that too.

`--ignore-workspace` fixes the install. It does NOT fix `pnpm exec`, which reads
the flag as the name of the command to run:

    ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL  Command "--ignore-workspace" not found

Same for `--no-workspace-root-check`. Since the install now populates the repo's
own node_modules, the binary is addressable directly, so this calls
`./node_modules/.bin/vite` and drops `pnpm exec` entirely.

Verified end to end in the repo root: install completes, `vite build` writes
dist/public, "built in 7.01s".

Both configs carry the same command and both were broken. deploy/system-wrangler.jsonc
is the `--config` deploy path; wrangler.jsonc is the Workers Builds path.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W2qFSSKdbsxo7AS8Buo247
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 60ccba3b-6dc3-4922-9cbf-4d47abd91bd7

📥 Commits

Reviewing files that changed from the base of the PR and between e125a65 and eda1727.

📒 Files selected for processing (2)
  • deploy/system-wrangler.jsonc
  • wrangler.jsonc

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Both Worker build commands now install dependencies with --ignore-workspace and run Vite from node_modules/.bin. The main configuration also requires dist/public/index.html to exist and be nonempty.

Changes

Worker build command updates

Layer / File(s) Summary
Update Worker build commands
deploy/system-wrangler.jsonc, wrangler.jsonc
Both build commands add --ignore-workspace to the frozen-lockfile install and invoke the local Vite binary instead of pnpm exec vite. The main configuration checks that dist/public/index.html is nonempty.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to eda17

The Worker builds retain access to the root Vite dependency and check for generated client output. No concrete deployment risk is identified, so the change appears ready to merge.

Security Architecture Review

Security architecture risk: 🔵 Low · up to eda17

The changes are confined to deployment builds and add a check before deployment. No change to Worker permissions, secrets, or runtime bindings was found, but production rollout behavior has not been verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The changed commands affect the deployment build paths rather than adding a Worker request entrypoint. Any effect on a deployed Worker depends on a build completing and deployment proceeding.

Trust Boundaries and Controls

  • observed — Each build command checks for a nonempty generated index after Vite succeeds. This checks artifact presence, not artifact freshness, integrity, or provider-side deployment outcome.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: preventing the build command from resolving to the home workspace.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@claude

claude Bot commented Sep 19, 2026

Copy link
Copy Markdown

Review: fix(deploy): stop the build command resolving to the home workspace

Solid, narrowly-scoped fix for a real deploy blocker. A few notes:

Correctness

  • The root cause diagnosis checks out: a stray ~/pnpm-workspace.yaml on the Workers Builds host makes pnpm treat the home dir as the workspace root once it walks up past this repo, and cwd: ".." in deploy/system-wrangler.jsonc doesn't escape that since the stray file is above that dir too.
  • --ignore-workspace on pnpm install combined with dropping pnpm exec in favor of ./node_modules/.bin/vite is the right fix — pnpm exec has no --ignore-workspace/--no-workspace-root-check equivalent, so calling the binary directly out of node_modules/.bin (populated by the same install) sidesteps it entirely. This repo has no pnpm-workspace.yaml of its own, so --ignore-workspace has no side effects on the local install — it only defeats the ancestor file. vite is a direct devDependency in package.json, so pnpm will symlink it into node_modules/.bin for both configs since cwd resolves to the repo root in both cases (deploy/system-wrangler.jsonc via cwd: "..", wrangler.jsonc implicitly since it already lives at the root).
  • Both wrangler.jsonc (Workers Builds path) and deploy/system-wrangler.jsonc (--config path) got the same treatment, which is correct since both carried the identical broken command.

Minor / non-blocking

  • The build command string is now duplicated across two files with no shared source of truth — this is a pre-existing pattern (lots of other config is already duplicated between these two files), not a new problem introduced here, but a candidate for future consolidation if config drift becomes an issue (the PR description already flags compatibility_date/observability as pre-existing drift between the two).
  • No CI job appears to exercise the Workers Builds path (.github/workflows/*.yml only run pnpm install/pnpm exec vitest, not this build command), so this change is effectively unverifiable in CI — the author's manual repro ("ran the exact new command in the repo root... built in 7.01s") is the only verification. Reasonable for a config-only fix, but worth confirming once more with an actual wrangler deploy post-merge to make sure the Workers Builds host behaves the same as the manual repro.

Security / test coverage: N/A — build-tooling config only, no app code paths touched.

Looks good to merge once a real deploy confirms it end-to-end.

A separated adversarial review flagged that the previous revision could deploy
successfully while serving an empty or stale dist/public: wrangler runs the build
command, but nothing asserted the command actually produced a bundle. A silent
empty build is worse than a failed one — the deploy reports success and the site
breaks.

`&& test -s dist/public/index.html` closes it. Verified both directions: exits 0
on a real build, non-zero when index.html is truncated to empty.

The review's other blocking findings were checked against primary sources and did
not hold:

- `--ignore-workspace` does not change dependency resolution here. There is no
  pnpm-workspace.yaml in this repo, so the flag is a no-op wherever no workspace
  file sits above the checkout — which is every environment except the local one
  it was added to fix.
- The relative binary path is correct in both configs. deploy/system-wrangler.jsonc
  sets `cwd: ".."` and wrangler.jsonc sets no cwd (so cwd is its own directory);
  both resolve to the repo root, where node_modules/.bin lives.
- Exit codes do propagate through the `&&` chain — observed directly: the failing
  install aborted the deploy rather than continuing to upload.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W2qFSSKdbsxo7AS8Buo247
@claude

claude Bot commented Sep 28, 2026

Copy link
Copy Markdown

Review of #174. The change is small and looks correct.

What I checked

  • --ignore-workspace on pnpm install stops pnpm walking up to /home/ubuntu/pnpm-workspace.yaml. Calling ./node_modules/.bin/vite directly sidesteps the pnpm exec flag problem you described.
  • Both configs get the same command, so they don't drift further.
  • I haven't run the build myself. I'm relying on your verification.

Suggestions

  1. Undocumented change: the diff appends && test -s dist/public/index.html, and the PR description doesn't mention it. It's a useful guard because it fails the deploy if the build emits nothing. Please add a line about it to the description. Check that index.html really lands at the root of dist/public, which depends on the Vite root being client/. You said the build wrote dist/public, but not that this file was there.
  2. Working directory: deploy/system-wrangler.jsonc sets cwd: "..", while wrangler.jsonc sets none. The relative ./node_modules/.bin/vite therefore depends on wrangler running from the repo root in the Workers Builds path. That is probably true today. A comment, or an explicit cwd, would make it less fragile.
  3. Root cause: --ignore-workspace treats the symptom on this machine. Removing the stray /home/ubuntu/pnpm-workspace.yaml would fix it for every other pnpm command run from this repo. It's fine to keep the flag as a safeguard.
  4. Portability: ./node_modules/.bin/vite and test assume a POSIX shell. That's fine for Linux CI and Workers Builds, but it would break for anyone running npm run deploy from Windows.
  5. Follow-up: the compatibility_date and observability drift between the two configs is pre-existing and out of scope here. I'd still open an issue for it.

No security or performance concerns. There are no tests to add, because this is deploy config. The build check you ran is the right verification.

Approve, with the description tweak from item 1.

🤖 Generated with Claude Code

@chitcommit
chitcommit merged commit cefe04c into main Sep 28, 2026
12 checks passed
@chitcommit
chitcommit deleted the fix/deploy-ignore-workspace branch September 28, 2026 23:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant