This is the runnable example prepared for the CI/CD episode. It installs ReRune CLI 1.0.13, pulls published English/German translations into a clean directory, validates three application keys, builds a small static demo, and saves the exact build inputs. Manual runs can also deploy that same build to GitHub Pages.
Verified on September 22, 2026 against the live ReRune API and GitHub Actions. Run 1 stops at validation because saved is not published. After publishing that key, run 2 passes and deploys the live Chapter demo. Both runs use commit 68ee9052c9c2e40fcd97863153e168786f591a2c.
Copy the contents of this example directory to a dedicated demo repository, including .github/workflows/rerune-ci.yml. The workflow assumes these files live at the repository root and the default branch is main.
Use a ReRune demo project with English as its main language and German as its second language. Import seed/en/translation.json and seed/de/translation.json as flat i18next resources, then review and publish the three keys. The build pulls published values, not drafts. These files are synthetic examples, not captured service output.
Add a GitHub repository variable named RERUNE_PROJECT_ID with the project's 24-character ID. Add the personal API key as a GitHub repository secret named RERUNE_API_KEY. Its user needs membership in the project's organization; the read-only build does not require edit or publishing grants. Personal keys follow their user's access, rather than having per-key scopes.
The preparation script generates rerune.json using the project variable and a literal ${RERUNE_API_KEY} reference. The CLI resolves only that API-key reference. RERUNE_PROJECT_ID is consumed by our Python example, not a native CLI project override. rerune.json, .env, output files and last_sync are not committed or cached by this example.
The workflow runs on pushes to main and manual dispatches from main. It does not run on pull requests and does not receive a trigger merely because somebody publishes in ReRune. Use a manual run to rebuild after a translation-only change.
In the repository's Actions tab, choose ReRune translations and demo build, choose Run workflow, and leave Deploy the tested example off. Expect installation, configuration, pull, validation, build and artifact steps. Download the artifact and open en.html and de.html to inspect the built pages.
A successful pull prints no progress summary itself. The visible validation and build messages come from the example scripts. No authentication values are printed, passed as CLI flags, copied into the pages or included in artifacts.
For the failure recording, initially publish only welcome and save_book. The application already requires saved, which is not yet published in the dedicated demo project. The validator fails before build or deployment. Then add, translate, review and publish that demo key, and rerun. This is an application contract check, not a built-in ReRune validation command. Missing-placeholder behavior is also covered by the local synthetic test fixtures.
Enable GitHub Pages in the demo repository and set its publishing source to GitHub Actions. Configure the github-pages environment to allow main; add required reviewers if available for the repository and plan. The YAML names the environment but does not configure reviewer rules by itself.
Run the workflow manually with Deploy the tested example enabled. The deploy job waits for the build and deploys its Pages artifact. It does not pull again. Only that job receives pages: write and id-token: write. The build job has contents: read.
Deploy only synthetic demo content to this public-facing example. GitHub Pages availability and environment review features depend on repository visibility and plan.
.github/workflows/rerune-ci.yml: real Actions workflow, including optional Pages deployment.scripts/install-rerune.sh: Linux x86_64 installer pinned to 1.0.13, verifies archive and extracted binary hashes and adds the executable to later steps throughGITHUB_PATH.scripts/prepare-rerune.py: generates the project config with explicit language and filename settings, rejects nonempty output, and omits old sync state.scripts/check-translations.py: checks three required flat keys and their simple i18next{{name}}placeholders. This is not a general ICU or translation-quality validator.scripts/build-demo.py: builds the two demo pages and copies the exact pulled files and SHA-256 manifest intodist/.test-example.py: exercises configuration, successful validation, missing key/placeholder failures and output artifacts with synthetic fixtures. It does not call ReRune.
Run the local fixture tests with python3 test-example.py. The example also passed Bash syntax and Actionlint checks.
Only the three fixture strings are localized in this small application. The surrounding explanatory UI stays in English.
Pull merges files when local translation files exist, and local-only keys can survive. This example starts empty so old files cannot carry removed content into the build. Do not restore build/l10n or the mutated rerune.json from a cache. A new remote language also needs an explicit config/application update; pull does not discover languages automatically.
The CLI version and its bytes are pinned. Published translations and server codec behavior remain live inputs. Rebuilding the same Git commit later can produce different text. The artifact and its manifest record the exact files used in that run; pinning the CLI alone does not make the whole build reproducible.
Neither rerune push nor rerune publish is part of this build. Push updates drafts, may create missing configured languages, and merges using last_sync. Do not reuse this fresh-read recipe as a source-authoritative push job or invent a timestamp to force local values to win. Multi-language push can partially succeed remotely.
For an independently reviewed publication, the unattended command is:
rerune publish --all --project "$RERUNE_PROJECT_ID" \
--tag "$RELEASE_TAG" --yes --json > publish-result.jsonUse a separately protected workflow and a user with publishing permission. --all targets current ready drafts across the project, not the files in a CI artifact. For a smaller scope, replace --all with explicit repeated --key IDs. Keep JSON results even on failure because they can describe partial outcomes. Inspect skipped, warnings and unprocessed; exit 0 does not mean every draft changed.
Without --yes, unattended EOF can cancel publication with exit 0. A prior successful pull/build tests published text, so it cannot validate drafts that a later publication releases. No publication command is executed by this example.
- GitHub secrets
- GitHub Pages workflows
- Deployment environments
- ReRune installer
- ReRune 1.0.13 checksums
The recorded Pages run succeeded with two upstream Node.js 20 deprecation warnings from the official Pages actions and their bundled artifact action. GitHub forced those actions onto Node.js 24. The raw run logs retain these warnings.
The demo’s github-pages environment allows the main branch and has no required reviewer configured. Add your own review rule when appropriate. Workflow artifacts expire after 14 days; the deployed page remains available until changed or removed.