Skip to content

feat: add reusable Cloudflare Pages deploy and deploy-run resolver - #8

Merged
jmeridth merged 2 commits into
mainfrom
feat/cloudflare-pages-deploy
Sep 26, 2026
Merged

jmeridth merged 2 commits into
mainfrom
feat/cloudflare-pages-deploy

Conversation

@jmeridth

@jmeridth jmeridth commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

What/Why

Add cloudflare-pages-deploy.yaml, which deploys a built static site from an artifact to Cloudflare Pages inside a GitHub environment, and resolve-deploy-run.yaml, which finds the deploy run to promote and outputs its commit. hugo-ci.yaml gains a ref input so promote can rebuild that commit. Neither new workflow builds anything, so both work for any site; a caller composes them with its own build job.

Proof it works

  • A calling repo ran this branch end to end: a staging deploy (build, then deploy) and a production promote (resolve, rebuild, deploy). Both succeeded and the sites return 200.
  • The first staging run showed that environment secrets reach the called deploy job only when the caller uses secrets: inherit. The docs and workflow comment now say so.

Risk + AI role

Medium. These workflows deploy to production for callers. Claude Opus 5.5 wrote them.

Review focus

  • Callers pass secrets: inherit, which zizmor flags. The docs explain why and recommend restricting each environment to main, so a pushed branch can't run a modified workflow with the environment's secrets.
  • resolve-deploy-run refuses runs that aren't successful runs of the named deploy workflow on the expected branch.

cloudflare-pages-deploy deploys any built artifact; resolve-deploy-run outputs the commit to promote; hugo-ci gains a ref input.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth jmeridth added the mark-ready-when-ready Auto-mark this draft PR ready for review once checks pass label Sep 26, 2026
@jmeridth jmeridth self-assigned this Sep 26, 2026
@github-actions github-actions Bot added the feature New feature or request label Sep 26, 2026
@github-actions
github-actions Bot marked this pull request as ready for review September 26, 2026 17:22
@github-actions github-actions Bot removed the mark-ready-when-ready Auto-mark this draft PR ready for review once checks pass label Sep 26, 2026
@jmeridth jmeridth added the release Create a release when this PR merges label Sep 26, 2026
Environment secrets reach a reusable workflow's job only when the caller inherits secrets. Also recommend restricting environments to main.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth
jmeridth merged commit 36ec452 into main Sep 26, 2026
5 checks passed
@jmeridth
jmeridth deleted the feat/cloudflare-pages-deploy branch September 26, 2026 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature New feature or request release Create a release when this PR merges

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant