Deploy pipeline

Every push to main of machinebehavior.io starts the workflow .github/workflows/conformity.yml. The workflow also runs every Monday at 06:17 UTC and by hand. It has two jobs, and the second runs only if the first passes.

Job 1: conformity checks

  1. Check out main with full history.
  2. Run the conformity action against every published page (see Conformity gate).
  3. Commit conformity/latest.json and conformity/index.html as conformity-bot, with [skip ci] in the message, and push.
  4. Gate step: read the overall result; anything other than pass fails the job with "deploy blocked, previous build stays live".

Job 2: deploy to Pages

  1. Check out main again, after the bot commit.
  2. Refresh the map: run scripts/crawl_map.py against the live sites. The new map/graph.json replaces the committed one only if it has at least as many nodes and links. A partial crawl (for example Substack answering 403 to the runner) keeps the committed snapshot. This step may fail without failing the job, and its result is never committed.
  3. Upload the repository as the Pages artifact and deploy it.

The bot commit moves main after every run. Always git pull --rebase before pushing; a push without it is rejected. See Push rejected after a deploy.

What happens around a deploy

Check before you push

git pull --rebase
python3 .github/actions/conformity/run.py --root . --config conformity/site-tier.json \
  --requirements conformity/requirements.json --out conformity --dry-run

Push only when the dry run prints overall=pass. In scripts, compare the value; a grep for overall= succeeds on a failing run too.