Skip to content
// Notes

The deploy fix that never ran

From Stellar Drift

The Stellar Drift deploy failed one day with "Your local changes to the following files would be overwritten by merge". It was fixed the same day: git pull became fetch plus reset --hard, so a modified working tree could never block a release again. Five days later the deploy failed again, with exactly the same error text.

The fix had been in the repository the whole time. It had simply never run. Forge does not execute .forge/deploy.sh — it executes whatever is pasted into a textarea on its site settings page, and the two had drifted apart. The script's own header said it was kept in the repo rather than "living only in a textarea on a web page that nobody diffs", which described the problem precisely without doing anything about it.

What makes this one dangerous is that it is silent from outside. The game keeps serving the last good release, so the site looks healthy, and every deploy after the first fails identically until somebody resets the tree by hand. Nothing tells you. It reads exactly like a week in which nobody pushed.

The textarea now holds four lines: fetch, reset, and exec .forge/deploy.sh. After that the repository is the only source of truth, and the deploy picks up its own changes on every run. Editing the script needs no visit to Forge; only editing those four lines does, and they have no reason to change.

The part worth carrying to every other project: anywhere a control lives in a hosting provider's web form rather than in version control — deploy scripts, environment variables, branch settings, scheduled jobs — assume it has drifted. The copy in the repository is evidence of what somebody intended. It is not evidence of what is running.

// Open for work

Want something like this, built to your own brief?

Fast, accessible, and built to last — no page builders, no template you'll outgrow in a year. Tell me what you need and the contact form goes straight to my inbox.