Site: roro9stack.net phase 1 (home, Install with a browser flasher, Downloads), and a CI split for site changes #61

Merged
twisla merged 6 commits from site into main 2026-10-06 16:33:07 +00:00
Showing only changes of commit a0939bf741 - Show all commits
+6 -5
View File
@@ -9,8 +9,8 @@ The home page was designed on a canvas in a Claude chat (a dark and a light them
## What was found while planning (2026-10-06)
- `roro9stack.net` already points at the server that hosts Gitea. Plain HTTP redirects to HTTPS; HTTPS has no certificate yet, which is the server's side to set up.
- **Release downloads from Gitea carry no CORS header,** so a browser flasher can't fetch the factory image from there. The site has to serve it itself.
- Zola can read JSON from a URL at build time (`load_data`), so the home page's "latest version" can come from the Gitea API. It cannot copy a remote binary into the site.
- **Release downloads from Gitea carry no CORS header,** so a browser can't fetch the factory image from another origin as things are. Gitea is behind Caddy, which can add the header (below).
- Zola can read JSON from a URL at build time (`load_data`), so the home page's "latest version" can come from the Gitea API.
- There is no Gitea wiki: the design's "Wiki" links would 404.
- The blog is published by pulling its repository on the web server and running `zola build`. The site does the same.
@@ -23,7 +23,7 @@ The home page was designed on a canvas in a Claude chat (a dark and a light them
| Q177 | Domain: **roro9stack.net.** The blog stays at experiments.twis.la. |
| Q178 | **Publishing is the blog's way:** the web server pulls `main` and runs `zola build`; that part is the maintainer's. Changes reach `main` through pull requests as everywhere. **CI is split:** a dedicated `site` job builds the site (`zola build`) when `site/`, `docs/`, `README.md` or `CONTEXT.md` change, and the firmware tests and builds skip a change that touches nothing else. A change that touches both runs both. |
| Q179 | Phases, each its own pull request: **1.** the CI split, the home page, an Install page with the browser flasher, downloads and the changelog. **2.** a user guide page per App. **3.** how-tos and the FAQ. **4.** developer docs generated from the repository. |
| Q180 | **A browser flasher** (ESP Web Tools). Zola can't copy the factory image, so `site/fetch-release.sh` downloads the latest release's `factory.bin`, checks it against `SHA256SUMS`, and writes the manifest into `site/static/firmware/` (not committed). It runs before `zola build` on the server, and locally. Chrome or Edge on a desktop only; other browsers get the `esptool` steps. A new release shows on the site at the next build. |
| Q180 | **A browser flasher** (ESP Web Tools), **without copying the firmware.** Caddy, in front of Gitea, adds `Access-Control-Allow-Origin: https://roro9stack.net` (and `Vary: Origin`) to GET and HEAD on `/twisla/roro9stack/releases/download/*` and `/api/v1/repos/twisla/roro9stack/releases*`: both are public already. The Install page asks the API for the latest release in the browser, finds the asset ending `-factory.bin`, and gives ESP Web Tools a manifest built on the spot, so it offers a new release as soon as it exists, with no rebuild. The library is **vendored** into `site/static/` (Apache-2.0), not loaded from a CDN. The file's SHA-256 is shown on the page. Chrome or Edge on a desktop only; other browsers, and visitors without JavaScript, get the `esptool` steps on the same page. |
| Q181 | Docs for the latest version only. The changelog is the Gitea releases, read at build time. |
| Q182 | English only. |
| Q183 | The FAQ starts from real questions: the README, and issues labelled `kind/docs`. |
@@ -53,7 +53,8 @@ Changed before it ships:
- Pushing a change under `site/` runs the `site` job and not the firmware tests; a firmware change runs the firmware jobs and not the site's.
- The home page renders in both themes, at phone width, with the keyboard, and says nothing the firmware doesn't do.
- The latest version on the page is the latest release.
- The browser flasher installs the latest release on a Cardputer ADV from Chrome (tried by hand), and the `esptool` steps are on the same page.
- The browser flasher installs the latest release on a Cardputer ADV from Chrome (tried by hand), the page shows the file's SHA-256, and the `esptool` steps are on the same page.
- A release published after the site was built is the one the Install page offers.
- The page makes no request to another origin.
## Work breakdown
@@ -61,5 +62,5 @@ Changed before it ships:
1. **CI split:** a `site` workflow, path filters on the firmware workflow.
2. **The skeleton:** `site/` with the tokens, fonts, base template and the theme switch.
3. **The home page,** from the design, with the changes above.
4. **Install and downloads:** `fetch-release.sh`, the flasher, the `esptool` steps, the changelog.
4. **Install and downloads:** the flasher with its manifest built in the page, the `esptool` steps, the changelog. Needs the Caddy headers on the Gitea host (the maintainer's side); the page is tested against them once they're in.
5. **Checks,** recorded here.