docs: Correct Cloudflare setup guidance - #165
Merged
Merged
Conversation
Guide account-owned deploy tokens through specific permissions and resource scopes. Use the shared apex Web Analytics property on both hostnames and describe the current preview credential boundary. Co-authored-by: Codex <noreply@openai.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
Make TransitMapper's Cloudflare setup instructions match the permissions and analytics configuration the team actually uses.
Overview of Changes
The CI token setup now lists the account and zone permissions used by deployment and explains that the current preview credential can also affect production. The production and preview runbooks name the account ownership and resource boundaries so operators can choose a token deliberately.
Analytics setup now points both the map and Labs at the shared apex Web Analytics property. Existing build inputs remain separate, so an operator enters the same shared token for each. The related security and operations guides use the same instructions.
Validation:
pnpm checkpassed on the committed branch.Follow-ups
Separate preview and production deployment credentials when the deployment workflow can enforce distinct permissions.