Repository navigation
Conversation
Staging and production now share scripts/ci/deploy.ts, which validates the GitHub run identity, runs operator setup for every bound namespace, deploys the Worker once, asserts private R2, and checks each endpoint for the new deployment ID. The production target (scripts/ci/production.ts) binds rolldown/rolldown to the voidzero-remote-cache Worker. It deploys only from manual runs of this repository's main branch, so repositories created by Deploy to Cloudflare cannot run it. Staging keeps its own rules and fixtures, and the button deploy reuses the extracted endpoint polling. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Remote cache stagingCommit: Cloudflare deployment is disabled. Configure the repository secrets and variables described in the e2e plan, then set |
Production repositories now live in .github/production-repositories.jsonc, a namespace-to-repository map, so adding or removing one is a one-line edit. The production target reads and validates the list only when it deploys, and the test checks the committed file without depending on its entries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Each production deployment now enables every namespace listed in .github/production-repositories.jsonc and disables every other namespace, so removing an entry withdraws its repository. Only rows whose switches change are updated, because the changed_policy trigger bumps policy_version on any switch update and that stops in-flight uploads from publishing. The cache-wide deployment switches stay manual. The shared driver passes its operator IO to prepare hooks, so the staging and production hooks run against the same IO as the rest of the deployment. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a production deployment of the remote cache that a maintainer starts by hand, and moves the deploy logic that staging and production share into one script.
remote-cache-deploy.yml) still deploys on every PR and every push tomain. Its only workflow change ispnpm ci:deploy staging.remote-cache-production.yml, new) runs only onworkflow_dispatch. It runspnpm check,pnpm smoke, thenpnpm ci:deploy productionin aproductionenvironment.What changed
scripts/ci/deploy.ts(new) is the shared driver.runContextvalidates the GitHub run identity.deployTarget:operator setupfor every bound namespace, with the deploy deferred andDEPLOYMENT_IDinjected;preparehook;reportDeploymentwrites theurloutput and a step summary..github/production-repositories.jsonc(new) is the production repository list, a map of cache namespace to publicowner/repo. It starts withrolldown→rolldown/rolldown. Adding or removing a repository is a one-line edit.scripts/ci/production.ts(new) names the production Worker, D1 and R2 (voidzero-remote-cache), and reads and validates the repository list when it deploys. On each deploy it enables every listed namespace and disables every other one. It refuses:workflow_dispatch;refs/heads/main;scripts/ci.tskeeps the staging rules (-ciprefix, pinned subdomain, writes only on push to the default branch). It now callsrunContextanddeployTarget, and staging's extra steps (scope-ownership guard,other/manualscopes, policy recovery) are itspreparehook. The commands are nowdeploy staging,deploy production, andtest.scripts/deploy.ts: extractedwaitForDeploymentandnamespaceEnabledfor reuse. The button deploy's behavior is unchanged.Docs: a "Production deployment" section in
docs/e2e-plan.md, linked from the README.Reviewer notes
e2eendpoint for the new deployment ID.NAMESPACESis now built from the scopes stored in D1. The ownership guard limits those to the samee2e,otherandmanual.CLOUDFLARE_*repository secrets, and internal PR staging runs receive them. A production-only token can be added later as aproductionenvironment secret without workflow changes. Consider adding required reviewers to that environment.pnpm operator policychange lasts only until the next deploy. Only rows whose switches change are updated, because thechanged_policytrigger bumpspolicy_versionand stops in-flight uploads. The cache-widepnpm operator deploymentswitches stay manual and act as the emergency stop. To roll back, re-run an earlier production run.docs/e2e-plan.mdhas no recorded results. Follow-up options: a CI job that runspnpm deployagainst resources provisioned by ID, plus the manual exercise.After merge
mainstaging run passes, start production:gh workflow run remote-cache-production.yml --ref main.Testing
pnpm checkpasses.pnpm smoke: 37/37 tests pass and the bundle dry run succeeds.test/ci.test.ts:runContextvalidation;preparerun first;pnpm ci:deploy productionlocally with push, copied-repo and feature-branch contexts. Each is rejected before contacting Cloudflare, and a valid context stops at the missing credentials.🤖 Generated with Claude Code