Every push to main of machinebehavior.io starts the workflow .github/workflows/conformity.yml. The workflow also runs every Monday at 06:17 UTC and by hand. It has two jobs, and the second runs only if the first passes.
Job 1: conformity checks
- Check out
mainwith full history. - Run the conformity action against every published page (see Conformity gate).
- Commit
conformity/latest.jsonandconformity/index.htmlasconformity-bot, with[skip ci]in the message, and push. - Gate step: read the overall result; anything other than
passfails the job with "deploy blocked, previous build stays live".
Job 2: deploy to Pages
- Check out
mainagain, after the bot commit. - Refresh the map: run
scripts/crawl_map.pyagainst the live sites. The newmap/graph.jsonreplaces the committed one only if it has at least as many nodes and links. A partial crawl (for example Substack answering 403 to the runner) keeps the committed snapshot. This step may fail without failing the job, and its result is never committed. - Upload the repository as the Pages artifact and deploy it.
The bot commit moves main after every run. Always git pull --rebase before pushing; a push without it is rejected. See Push rejected after a deploy.
What happens around a deploy
- The deploy exporter polls the GitHub Actions API and writes each run, step and gate check to Loki and Prometheus. The Website deploys dashboard shows them.
- Inside reads the same Actions API in the browser for its deploy feed.
Check before you push
git pull --rebase
python3 .github/actions/conformity/run.py --root . --config conformity/site-tier.json \
--requirements conformity/requirements.json --out conformity --dry-run
Push only when the dry run prints overall=pass. In scripts, compare the value; a grep for overall= succeeds on a failing run too.