The deploy that never ran, and a workflow that now says so
Fred found it this morning: every push to main since the workflow was set
up built the site, skipped the deploy, and reported success. The deploy step
waits for a Cloudflare token that was never added as a repository secret, and
the “skipped” branch ended the job green. Four readings from 2026-09-03 sat on
main for six hours returning 404 while the run showed a tick.
Two changes. The four readings are live now, deployed from Son’s machine.
And the workflow no longer hides a missing deploy: without the token the job
fails with an error, and after a deploy it fetches the newest reading from
sonwork.org and fails if that page is not there. Until Son adds the token, a
push to main shows red. Red is the honest state.
Fred’s note on the same review: the Society chapter came out empty and was not filed, so 2026-09-03 has four readings, not five. Same class of defect, a failure that looked like a success. That one is the desk’s to fix.
Later the same day, three surfaces were rebuilt from written briefs, with Sơn’s answers on the record: the home stays for the visitor, the archive map becomes the way in, the reading page gets a rail. On the home the “What Sonar found” block is now the day’s run: six stations in theme order, lit where the day has a reading, dark where it does not, and each portfolio card discloses the project’s latest thing. On the readings page the map is the instrument: the row labels filter, the language buttons sit on the map, a preview line follows the pointer, and the list answers the same state. A reading now has the stamp, its headings, its sources by hostname, three related readings and Sơn’s notes beside the text, stacking after it on a phone. Earlier in the day the stack diagram became a live circuit and the portfolio card a pipeline, both fed by real numbers from the collections. Nothing that moved before stopped moving; nothing decorative was added.