seahaven-site/.github/workflows/deploy.yaml
Adam Moussa 5ee640074c
Migrate to thin Eleventy build + a11y/SEO/perf/CI hardening (#20)
* chore(build): add Eleventy scaffold

Thin Eleventy build (v3.1.6, pinned) — passthrough-copies assets/,
robots.txt, sitemap.xml; outputs flat HTML to _site/. _data/site.json
holds site-wide constants; _data/images.json maps image keys to
src+width+height for the {% image %} shortcode (CLS fix). Output stays
flat HTML served from the same S3 bucket + CloudFront.

* refactor(templates): base layout, partials, shared JS, CSS extraction

- _includes/base.njk + nav/mobile-menu/footer partials reproduce the
  shared chrome once (was hand-duplicated across 13 pages). Adds a
  skip-link and <main> landmark (WCAG 2.4.1), aria-expanded/role=dialog
  hooks on the menu, and a {% year %} shortcode replacing document.write.
- assets/js/nav.js: extracted sticky-nav + accessible mobile-menu dialog
  (focus trap, Escape, focus return) + rAF-throttled hero parallax.
- assets/js/form.js: Basin AJAX submit with an accessible status region.
- assets/css/*.css: per-page inline <style> extracted into page CSS files
  (home/about/services/careers/jobs/contact/social/legal/404); skip-link
  + :focus-visible added to main.css.
- index.njk: homepage converted as the reference page.

* fix(css): make hero-bg url root-relative after extraction

Inline CSS used a document-relative url('assets/...') that resolves
correctly from / but breaks once moved into /assets/css/home.css.
Rewrite to /assets/images/.

* refactor(pages): convert 12 pages to Eleventy templates

Convert about, services, careers (listing + 3 jobs), contact, social-
accountability, privacy-policy, terms-of-service, eula, and 404 from
standalone HTML to .njk against base.njk. Each page now carries only
front-matter (title/description/SEO) + its <main> content; shared head/
nav/footer/scripts come from the layout. JobPosting + LocalBusiness
JSON-LD preserved. Images use the {% image %} shortcode (width/height).
Contact gets an accessible #form-status region. form.js generalized to
wire BOTH the contact form and the .apply-form job application forms
(was contact-only), preserving each submit button's own label.

* fix(a11y): footer contrast to WCAG AA + scope services .form-group

Raise footer text colors (footer-bottom/col/brand/social/contact) and
darken --text-muted so muted text clears 4.5:1 on the dark footer and
warm-gray surfaces. Scope services' flex .form-group override to
.contact-form .form-group so it can't leak to the global rule.

* perf(seo): og-cover image, webp logos, hero preload

Add a real 1200x630 og-cover.jpg (was a 153x49 favicon) wired site-wide
via base.njk og:image/twitter:image. Convert nav/footer logos to webp
(nav 58KB->22KB); PNGs kept as passthrough so old URLs still resolve.
Preload the LCP hero image on the homepage (fetchpriority=high). All
<img> carry width/height via the image shortcode (CLS).

* ci(deploy): build-then-sync, cache headers, safe concurrency

Rename main.yml -> deploy.yaml (org convention). Build with Eleventy
(npm ci && npm run build) and sync _site/ instead of the repo root, so
only built output ships (no source/templates/node_modules). Split
Cache-Control (1-day assets, no-cache HTML) and keep /* invalidation
since filenames are not yet fingerprinted. concurrency cancel-in-progress
false so a deploy is never cut mid sync. ci.yaml validates _site/ via
ci-static build mode.

* docs: README for the Eleventy build and structure

* fix(security): wire services form, guard build, harden deploy

Fable build-review findings:
- BLOCK: services puts .contact-form on the <form> itself (contact uses a
  wrapper div), so form.js selector '.contact-form form' never matched it
  — the services lead form submitted natively with an empty reCAPTCHA
  token. Selector now also matches form.contact-form.
- Guard the build before the --delete S3 sync: require index/contact/404
  and >=40 files, so a silently-empty build can never wipe the live bucket.
- npm ci --ignore-scripts on deploy (build verified to pass) to shrink the
  supply-chain window on the OIDC-credentialed runner.
- Escape quotes in the image shortcode alt text.
2026-06-12 17:02:06 -04:00

77 lines
2.6 KiB
YAML

name: Deploy
on:
push:
branches:
- main
permissions:
id-token: write # Required for OIDC
contents: read # Allows checkout of repo
# Never cancel a deploy mid-flight: cancelling between the S3 sync and the
# CloudFront invalidation (or mid `--delete`) would leave the bucket in a
# half-updated state. Queue instead.
concurrency:
group: deploy-${{ github.ref }}
cancel-in-progress: false
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Set up Node
uses: actions/setup-node@v6
with:
node-version: "24"
cache: npm
- name: Build site
run: |
npm ci --ignore-scripts
npm run build
# Fail closed: never let a silently-empty build reach the --delete sync.
test -f _site/index.html
test -f _site/contact/index.html
test -f _site/404.html
count=$(find _site -type f | wc -l)
if [ "$count" -lt 40 ]; then
echo "::error::build produced only $count files (expected >= 40); aborting deploy"
exit 1
fi
echo "Build OK: $count files."
- name: Configure AWS credentials using OIDC
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy_seahavensite
aws-region: us-east-1
- name: Sync build output to S3
run: |
# 1) Static assets — 1-day browser cache (no filename fingerprinting yet,
# so do NOT go immutable). CloudFront /* invalidation below keeps the
# edge fresh; this only affects returning visitors' browser cache.
aws s3 sync _site/ s3://seahaven.com --no-progress \
--exclude "*.html" --exclude "*.xml" --exclude "*.txt" \
--cache-control "public, max-age=86400"
# 2) HTML / sitemap / robots — always revalidate so a deploy is seen immediately.
aws s3 sync _site/ s3://seahaven.com --no-progress \
--exclude "*" --include "*.html" --include "*.xml" --include "*.txt" \
--cache-control "no-cache"
# 3) Prune files removed from the build. This pass sets no metadata, so
# it skips already-uploaded objects (preserving the Cache-Control set
# above) and only deletes objects no longer present in _site/.
aws s3 sync _site/ s3://seahaven.com --no-progress --delete
- name: Invalidate CloudFront cache
run: |
aws cloudfront create-invalidation \
--distribution-id EYK41AG0PO6XU \
--paths "/*"