From fb085cab6d7af7e2cd2021088858eeb0970f7388 Mon Sep 17 00:00:00 2001 From: Jeremy Date: Mon, 28 Sep 2026 10:33:39 -0700 Subject: [PATCH] Deploy docs via official GitHub Pages actions instead of a PAT The Sphinx-docs deploy used peaceiris/actions-gh-pages with a DOCSITE_TOKEN secret that is no longer valid, so pushes to gh-pages failed with a git auth error and the site stopped updating. Switch to the built-in Pages pipeline (upload-pages-artifact + deploy-pages), which authenticates via the workflow's OIDC token and needs no PAT. --- .github/workflows/sphinx.yml | 42 +++++++++++++++++++++--------------- 1 file changed, 25 insertions(+), 17 deletions(-) diff --git a/.github/workflows/sphinx.yml b/.github/workflows/sphinx.yml index 78cc5d37..a69e9acd 100644 --- a/.github/workflows/sphinx.yml +++ b/.github/workflows/sphinx.yml @@ -7,8 +7,18 @@ on: - documentation-staging workflow_dispatch: +permissions: + contents: read + pages: write + id-token: write + +# Allow one concurrent deployment, cancel in-progress runs for the same ref. +concurrency: + group: "pages" + cancel-in-progress: false + jobs: - pages: + build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 @@ -24,20 +34,18 @@ jobs: - name: Build HTML run: python -m sphinx.cmd.build -M html docs/source docs/build - - name: Upload artifacts - uses: actions/upload-artifact@v4 - with: - name: html-docs - path: docs/build/html/ - - # - name: Deploy - # uses: sphinx-notes/pages@v3 - # with: - # publish: true - - - name: Deploy - uses: peaceiris/actions-gh-pages@v3 + - name: Upload Pages artifact + uses: actions/upload-pages-artifact@v3 with: - github_token: ${{ secrets.DOCSITE_TOKEN }} - publish_branch: gh-pages - publish_dir: docs/build/html + path: docs/build/html + + deploy: + needs: build + runs-on: ubuntu-latest + environment: + name: github-pages + url: ${{ steps.deployment.outputs.page_url }} + steps: + - name: Deploy to GitHub Pages + id: deployment + uses: actions/deploy-pages@v4