From 14a576671de98bf3242975954ff42d98a94db182 Mon Sep 17 00:00:00 2001 From: Evan Hu Date: Tue, 5 May 2026 00:35:04 +0900 Subject: [PATCH] ci: trigger registry-worker refresh on push to main MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Without this, dashboard / daemon see content changes only after the next 02:00 UTC cron tick (up to ~24h delay). The action POSTs to stats.librefang.ai/api/registry/refresh with a bearer token shared with the worker secret of the same name; until both secrets exist on their respective sides, the endpoint returns 503 and the action fails loud — no silent half-deploy. Filters on directories the worker actually reads (plugins/, agents/, skills/, hands/, channels/, providers/, workflows/, mcp/) so README edits don't burn worker invocations. Known limitation: the worker rebuild walks ~40+ GitHub Contents API subrequests, which on Workers Free truncates partway through and leaves some categories empty. This action fires the right path; the underlying budget fix (Workers Paid, or pre-building the index in this repo) is tracked separately. --- .github/workflows/refresh-cache.yml | 46 +++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 .github/workflows/refresh-cache.yml diff --git a/.github/workflows/refresh-cache.yml b/.github/workflows/refresh-cache.yml new file mode 100644 index 0000000..51d3f72 --- /dev/null +++ b/.github/workflows/refresh-cache.yml @@ -0,0 +1,46 @@ +name: Refresh registry-worker cache + +# Triggers the registry-worker to rebuild its D1 cache and re-sign the +# plugins index right after content changes — without this, dashboard / +# daemon would have to wait for the next 02:00 UTC cron tick. +# +# Auth: REGISTRY_REFRESH_TOKEN (repo secret) is matched against the +# REGISTRY_REFRESH_TOKEN worker secret in librefang-registry. Until both +# are set, the worker endpoint returns 503. + +on: + push: + branches: [main] + paths: + - 'plugins/**' + - 'agents/**' + - 'skills/**' + - 'hands/**' + - 'channels/**' + - 'providers/**' + - 'workflows/**' + - 'mcp/**' + workflow_dispatch: # manual trigger for ops + +jobs: + refresh: + runs-on: ubuntu-latest + steps: + - name: Trigger worker refresh + env: + REGISTRY_REFRESH_TOKEN: ${{ secrets.REGISTRY_REFRESH_TOKEN }} + run: | + if [ -z "$REGISTRY_REFRESH_TOKEN" ]; then + echo "::error::REGISTRY_REFRESH_TOKEN secret is not set on this repo" + exit 1 + fi + response=$(curl -fsS -X POST \ + -H "Authorization: Bearer $REGISTRY_REFRESH_TOKEN" \ + -w "\nHTTP_CODE:%{http_code}" \ + https://stats.librefang.ai/api/registry/refresh) + echo "$response" + code=$(echo "$response" | grep -oE 'HTTP_CODE:[0-9]+' | cut -d: -f2) + if [ "$code" != "200" ]; then + echo "::error::worker returned $code" + exit 1 + fi