mirror of
https://github.com/heygen-com/hyperframes.git
synced 2026-09-03 12:54:29 +00:00
* feat(gcp-cloud-run): add Google Cloud Run + Workflows distributed render adapter Adds @hyperframes/gcp-cloud-run, the GCP counterpart to @hyperframes/aws-lambda (issue #932). The OSS distributed primitives (plan, renderChunk x N, assemble) are unchanged; this package is the storage/compute/orchestration glue. Package: Cloud Run handler (one image, three actions), runs under bun; GCS transport; in-image chrome-headless-shell resolver; client SDK (renderToCloudRun, getRenderProgress, deploySite, computeRenderCost); Dockerfile; Cloud Workflows definition; Terraform module; CLI cloudrun deploy|sites|render|render-batch|progress|destroy with --output-resolution and --strict-variables; 62 unit tests + docs + live smoke script. Shared extraction (removes ~640 lines of adapter duplication): move the cloud-agnostic config validator + content-hash into producer/distributed; both adapters import them. Validated end-to-end on GCP at 37.4 dB PSNR vs baseline. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(cli): resolve @hyperframes/gcp-cloud-run in the CLI build + root build The CLI bundle (esbuild) couldn't resolve `@hyperframes/gcp-cloud-run/sdk`, failing Build/Typecheck/CLI-smoke (and the perf/windows/regression jobs that build first). Mirror the aws-lambda handling: mark the gcp adapter + its /sdk subpath external in tsup.config.ts with a source alias, and add gcp-cloud-run to the root `build` filter so its dist exists for publish + runtime. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(ci): copy gcp-cloud-run manifest in Dockerfile.test for frozen install The regression test image runs `bun install --frozen-lockfile` after copying each workspace package.json individually. The CLI now depends on @hyperframes/gcp-cloud-run (workspace:*), so the frozen install fails to resolve it unless its manifest is present. Add the COPY line. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(cli): add machine-sizing flags to `cloudrun deploy` Closes the parity gap with `lambda deploy` (which exposes --memory etc.). `cloudrun deploy` now threads --cpu, --memory, --max-instances, and --timeout into the Terraform apply; omitted flags keep the module defaults (4 vCPU / 16Gi / 100 instances / 3600s). For finer control, apply the module directly. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(gcp-cloud-run): address PR review (security, waste, limits, alerts) - server.ts: bucket-allowlist guard no longer fails open silently. Unset env logs a one-time WARNING; "*" is an explicit opt-out; otherwise it enforces. - server.ts: stop double-shipping audio.aac. It already rides in the plan tarball every consumer downloads, so drop the redundant standalone upload (plan) + re-download/overwrite (assemble); assemble reads it from the untar, falling back to a supplied AudioGcsUri for compat. - server.ts: chunk extension via path.extname() instead of slice(lastIndexOf). - workflow.yaml: clamp parallel concurrency_limit to math.min(chunkCount, 20) — Cloud Workflows hard-caps concurrent iterations at 20. - Dockerfile: pin bun (bun-v1.3.9) so an interop change can't silently break the image rebuild. - terraform: add min_instances var (default 0); add a workflow-failure alert (finished_execution_count status=FAILED) alongside the request-count one. - costAccounting: document that displayCost excludes GCS storage/egress. Verified against the actual APIs: @google-cloud/workflows@4.4.0 ICreateExecutionRequest has no executionId (so the idempotency-token suggestion isn't available in this client); Workflows concurrency cap is 20; failure metric is workflows.googleapis.com/finished_execution_count (status label). 174 adapter tests pass, fallow/oxlint/oxfmt/terraform clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(gcp-cloud-run): address round-2 review — error code + CFR forwarding - workflow.yaml: rename the zero-chunk failure code PLAN_TOO_LARGE → PLAN_PRODUCED_ZERO_CHUNKS. The old code implied a size-ceiling breach (the opposite cause), misleading anyone triaging the alert. - workflow.yaml: forward Config.cfr to the assemble step (`Cfr: ${("cfr" in config) and config.cfr}`). It was read by the handler but never sent, so exact-CFR was silently off for every Cloud Run render. Uses the same `in`-operator guard already proven in the retryable predicate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(release): include gcp-cloud-run in set-version PACKAGES list set-version.ts (driven by release:prepare) bumps an explicit package list to the shared version on each release. gcp-cloud-run was wired into the build + publish.yml but missing here, so a release would leave it at a stale version and publish.yml would push the wrong version. Add it so the new package version-bumps + publishes in lockstep with the others. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
188 lines
6.9 KiB
YAML
188 lines
6.9 KiB
YAML
name: Publish to npm
|
|
|
|
permissions: {}
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
pull_request:
|
|
types: [closed]
|
|
branches: [main]
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: "Version to publish (e.g. 0.4.11). Tag v<version> must already exist."
|
|
required: true
|
|
type: string
|
|
|
|
jobs:
|
|
publish:
|
|
name: Publish
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
environment: npm-publish
|
|
permissions:
|
|
contents: write
|
|
id-token: write
|
|
# Run on tag push, manual dispatch, OR when a release/* PR is merged
|
|
if: >-
|
|
github.event_name == 'push' ||
|
|
github.event_name == 'workflow_dispatch' ||
|
|
(github.event.pull_request.merged == true &&
|
|
startsWith(github.event.pull_request.head.ref, 'release/v'))
|
|
steps:
|
|
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
|
|
with:
|
|
fetch-depth: 0
|
|
# On manual dispatch, check out the existing tag so we publish the
|
|
# exact commit that was tagged — not whatever is currently on main.
|
|
ref: >-
|
|
${{ github.event_name == 'workflow_dispatch'
|
|
&& format('refs/tags/v{0}', inputs.version)
|
|
|| github.ref }}
|
|
|
|
- name: Resolve version
|
|
id: version
|
|
env:
|
|
EVENT_NAME: ${{ github.event_name }}
|
|
INPUT_VERSION: ${{ inputs.version }}
|
|
PR_HEAD_REF: ${{ github.event.pull_request.head.ref }}
|
|
run: |
|
|
if [ "$EVENT_NAME" = "push" ]; then
|
|
VERSION="${GITHUB_REF_NAME#v}"
|
|
elif [ "$EVENT_NAME" = "workflow_dispatch" ]; then
|
|
VERSION="${INPUT_VERSION}"
|
|
VERSION="${VERSION#v}"
|
|
else
|
|
BRANCH="${PR_HEAD_REF}"
|
|
VERSION="${BRANCH#release/v}"
|
|
fi
|
|
echo "version=${VERSION}" >> "$GITHUB_OUTPUT"
|
|
|
|
# Detect pre-release tag (e.g. 0.1.16-alpha.1 → alpha, 0.1.16-beta.2 → beta)
|
|
if [[ "$VERSION" =~ -([a-zA-Z]+) ]]; then
|
|
DIST_TAG="${BASH_REMATCH[1]}"
|
|
echo "prerelease=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
DIST_TAG="latest"
|
|
echo "prerelease=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
echo "dist_tag=${DIST_TAG}" >> "$GITHUB_OUTPUT"
|
|
echo "Resolved version=${VERSION} dist_tag=${DIST_TAG}"
|
|
|
|
- name: Validate release channel
|
|
env:
|
|
VERSION: ${{ steps.version.outputs.version }}
|
|
DIST_TAG: ${{ steps.version.outputs.dist_tag }}
|
|
EVENT_NAME: ${{ github.event_name }}
|
|
PR_HEAD_REF: ${{ github.event.pull_request.head.ref }}
|
|
run: node scripts/validate-release-channel.mjs
|
|
|
|
- name: Create release tag
|
|
if: github.event_name == 'pull_request'
|
|
env:
|
|
VERSION: ${{ steps.version.outputs.version }}
|
|
run: |
|
|
git tag "v$VERSION"
|
|
git push origin "v$VERSION"
|
|
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
|
|
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
|
|
with:
|
|
node-version: 24
|
|
registry-url: "https://registry.npmjs.org"
|
|
- run: corepack enable
|
|
- run: corepack prepare pnpm@10.17.1 --activate
|
|
- run: bun install --frozen-lockfile
|
|
- run: bun run build
|
|
- run: bun run verify:packed-manifests
|
|
|
|
- name: Publish packages
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
VERSION: ${{ steps.version.outputs.version }}
|
|
DIST_TAG: ${{ steps.version.outputs.dist_tag }}
|
|
run: |
|
|
FAILED=0
|
|
|
|
publish_pkg() {
|
|
local filter="$1"
|
|
local name="$2"
|
|
|
|
# Check if this version is already published
|
|
if npm view "${name}@${VERSION}" version >/dev/null 2>&1; then
|
|
echo "⏭️ ${name}@${VERSION} already published — skipping"
|
|
return 0
|
|
fi
|
|
|
|
echo "📦 Publishing ${name}@${VERSION}..."
|
|
if pnpm --filter "$filter" publish --access public --no-git-checks --tag "$DIST_TAG"; then
|
|
echo "✅ ${name}@${VERSION} published"
|
|
else
|
|
echo "❌ ${name}@${VERSION} failed to publish"
|
|
FAILED=1
|
|
fi
|
|
}
|
|
|
|
publish_pkg "@hyperframes/core" "@hyperframes/core"
|
|
publish_pkg "@hyperframes/engine" "@hyperframes/engine"
|
|
publish_pkg "@hyperframes/player" "@hyperframes/player"
|
|
publish_pkg "@hyperframes/producer" "@hyperframes/producer"
|
|
publish_pkg "@hyperframes/shader-transitions" "@hyperframes/shader-transitions"
|
|
publish_pkg "@hyperframes/studio" "@hyperframes/studio"
|
|
publish_pkg "@hyperframes/aws-lambda" "@hyperframes/aws-lambda"
|
|
publish_pkg "@hyperframes/gcp-cloud-run" "@hyperframes/gcp-cloud-run"
|
|
|
|
# CLI is @hyperframes/cli in the monorepo but published as unscoped "hyperframes" on npm.
|
|
# Rewrite the name in package.json before publishing, then use npm publish directly
|
|
# since pnpm --filter won't match the rewritten name.
|
|
if npm view "hyperframes@${VERSION}" version >/dev/null 2>&1; then
|
|
echo "⏭️ hyperframes@${VERSION} already published — skipping"
|
|
else
|
|
node -e "
|
|
const fs = require('fs');
|
|
const p = 'packages/cli/package.json';
|
|
const pkg = JSON.parse(fs.readFileSync(p, 'utf8'));
|
|
pkg.name = 'hyperframes';
|
|
fs.writeFileSync(p, JSON.stringify(pkg, null, 2) + '\n');
|
|
"
|
|
echo "📦 Publishing hyperframes@${VERSION}..."
|
|
if (cd packages/cli && npm publish --access public --tag "$DIST_TAG"); then
|
|
echo "✅ hyperframes@${VERSION} published"
|
|
else
|
|
echo "❌ hyperframes@${VERSION} failed to publish"
|
|
FAILED=1
|
|
fi
|
|
fi
|
|
|
|
if [ "$FAILED" -ne 0 ]; then
|
|
echo "::error::One or more packages failed to publish"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Create GitHub Release
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
VERSION: ${{ steps.version.outputs.version }}
|
|
PRERELEASE: ${{ steps.version.outputs.prerelease }}
|
|
REPO: ${{ github.repository }}
|
|
run: |
|
|
NOTES_FILE="releases/v${VERSION}.md"
|
|
|
|
# Skip if release already exists (idempotent re-runs)
|
|
if gh release view "v${VERSION}" --repo "$REPO" >/dev/null 2>&1; then
|
|
echo "Release v${VERSION} already exists — skipping"
|
|
else
|
|
FLAGS=(--repo "$REPO" --title "v${VERSION}")
|
|
if [ -f "$NOTES_FILE" ]; then
|
|
FLAGS+=(--notes-file "$NOTES_FILE")
|
|
else
|
|
echo "No reviewed release notes found at $NOTES_FILE — using GitHub generated notes"
|
|
FLAGS+=(--generate-notes)
|
|
fi
|
|
if [ "$PRERELEASE" = "true" ]; then
|
|
FLAGS+=(--prerelease)
|
|
fi
|
|
gh release create "v${VERSION}" "${FLAGS[@]}"
|
|
fi
|