Skip to content

feat: stage main builds and promote reviewed releases to production - #86

Merged
WillieCubed merged 3 commits into
mainfrom
codex/staging-promotion
Oct 4, 2026
Merged

WillieCubed merged 3 commits into
mainfrom
codex/staging-promotion

Conversation

@WillieCubed

@WillieCubed WillieCubed commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

TL;DR

Merging to main now updates a protected staging site at preview.lasvegasfortransit.org, and the public site changes only when a maintainer promotes a specific reviewed release through the new Promote website release workflow.

Overview of Changes

Every main build, including the twice-daily calendar refresh, runs pnpm check and saves a release artifact. The artifact records its commit, Actions run ID, and a SHA-256 hash for every file. The same artifact is deployed to the lvbt-website-preview Worker behind Cloudflare Access. The workflow checks that anonymous requests are refused and that authenticated pages render before it activates that version on the staging domain.

Promotion takes the run ID of a successful main Deploy staging run. It rejects pull request, failed, and foreign runs. It then downloads that run's artifact and verifies every file. It uploads the compiled Worker and assets with production bindings without rebuilding, so a newer staging build cannot change the release being promoted. After the browser contract checks pass, it activates that exact Worker version. Both environments serve /lvbt-release.json, so reviewers and the workflow can confirm which release a host is serving.

Staging and preview responses are sent with X-Robots-Tag: noindex and Cache-Control: private, no-store, and analytics stay off on every preview hostname. Automated HTTP and Playwright checks send the Access service token only to the preview origin and never follow a redirect with it. The Cloudflare Pages PR preview workflow is removed so in-progress work is no longer published without protection. Same-repository PRs keep their protected Worker previews.

Live verification now accepts the organization's page title and Cloudflare's noindex header on versioned Workers URLs; custom staging still requires noindex, nofollow, noarchive. Astro, MDX, and the analytics integration are declared as build dependencies because they do not ship in the production Worker. The unchanged production dependency audit passes without advisory exceptions.

The trade-off is that production content, including calendar updates, stays at the last promoted release until someone reviews staging and promotes a newer run. To roll back, promote an earlier run while its artifact is retained (90 days), or use wrangler rollback with a recorded version.

Follow-ups

  • Preview Access setup is complete: the existing staff policy and a dedicated CI Service Auth policy protect only lvbt-website-preview; the GitHub environment contains both verification secrets. The service token expires October 3, 2027.
  • Confirm on live staging that anonymous visitors are refused and the served release matches the run's summary, then complete a first production promotion

🤖 Generated with Claude Code

Merging to main no longer changes the public website. Each main build,
including the scheduled calendar refresh, is validated and saved as a
release artifact that records its commit, Actions run ID, and the
SHA-256 hash of every file. That release is deployed to
preview.lasvegasfortransit.org, which sits behind Cloudflare Access.

The new "Promote website release" workflow publishes a release only
when a maintainer dispatches it with the ID of a successful main
"Deploy staging" run. It rejects pull request, failed, and foreign
runs, verifies every saved file, uploads the same compiled Worker and
assets with production bindings without rebuilding, runs the browser
contract checks, and then activates that exact Worker version. Each
deployment serves /lvbt-release.json so staging and production can be
checked against the selected release.

Preview responses carry noindex and private, no-store headers, and
analytics stay off on preview hostnames. Automated checks send the
Access service token only to the preview origin and never follow a
redirect with it.

Pull requests no longer get unprotected Cloudflare Pages previews;
same-repository pull requests keep their protected Worker previews.
Staging needs CF_ACCESS_CLIENT_ID and CF_ACCESS_CLIENT_SECRET in the
worker-preview environment and an Access policy on the
lvbt-website-preview Worker before its custom domain is attached.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Release verification accepts the organization name in the live title
and Cloudflare's noindex header on versioned Worker URLs. Custom staging
domains still require the full privacy header, authentication, and
rendering checks.

Co-authored-by: Codex <noreply@openai.com>
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Astro, MDX, and the analytics integration run during the static build
and do not ship in the production Worker. Declare them as development
dependencies so the production audit reflects the deployed runtime.

Co-authored-by: Codex <noreply@openai.com>
@WillieCubed
WillieCubed merged commit 8f019d9 into main Oct 4, 2026
16 checks passed
@WillieCubed
WillieCubed deleted the codex/staging-promotion branch October 4, 2026 01:03

This branch was successfully deployed

1 active deployment
worker-preview — e7a6d33c Deployed Oct 4, 2026 by WillieCubed via Worker preview #113
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant