Repository navigation
feat: stage main builds and promote reviewed releases to production - #86
Merged
Merged
Conversation
Merging to main no longer changes the public website. Each main build, including the scheduled calendar refresh, is validated and saved as a release artifact that records its commit, Actions run ID, and the SHA-256 hash of every file. That release is deployed to preview.lasvegasfortransit.org, which sits behind Cloudflare Access. The new "Promote website release" workflow publishes a release only when a maintainer dispatches it with the ID of a successful main "Deploy staging" run. It rejects pull request, failed, and foreign runs, verifies every saved file, uploads the same compiled Worker and assets with production bindings without rebuilding, runs the browser contract checks, and then activates that exact Worker version. Each deployment serves /lvbt-release.json so staging and production can be checked against the selected release. Preview responses carry noindex and private, no-store headers, and analytics stay off on preview hostnames. Automated checks send the Access service token only to the preview origin and never follow a redirect with it. Pull requests no longer get unprotected Cloudflare Pages previews; same-repository pull requests keep their protected Worker previews. Staging needs CF_ACCESS_CLIENT_ID and CF_ACCESS_CLIENT_SECRET in the worker-preview environment and an Access policy on the lvbt-website-preview Worker before its custom domain is attached. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
WillieCubed
had a problem deploying
to
worker-preview
October 2, 2026 17:57 — with
GitHub Actions
Failure
WillieCubed
had a problem deploying
to
worker-preview
October 4, 2026 00:43 — with
GitHub Actions
Failure
Release verification accepts the organization name in the live title and Cloudflare's noindex header on versioned Worker URLs. Custom staging domains still require the full privacy header, authentication, and rendering checks. Co-authored-by: Codex <noreply@openai.com>
Astro, MDX, and the analytics integration run during the static build and do not ship in the production Worker. Declare them as development dependencies so the production audit reflects the deployed runtime. Co-authored-by: Codex <noreply@openai.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
Merging to
mainnow updates a protected staging site atpreview.lasvegasfortransit.org, and the public site changes only when a maintainer promotes a specific reviewed release through the new Promote website release workflow.Overview of Changes
Every main build, including the twice-daily calendar refresh, runs
pnpm checkand saves a release artifact. The artifact records its commit, Actions run ID, and a SHA-256 hash for every file. The same artifact is deployed to thelvbt-website-previewWorker behind Cloudflare Access. The workflow checks that anonymous requests are refused and that authenticated pages render before it activates that version on the staging domain.Promotion takes the run ID of a successful main
Deploy stagingrun. It rejects pull request, failed, and foreign runs. It then downloads that run's artifact and verifies every file. It uploads the compiled Worker and assets with production bindings without rebuilding, so a newer staging build cannot change the release being promoted. After the browser contract checks pass, it activates that exact Worker version. Both environments serve/lvbt-release.json, so reviewers and the workflow can confirm which release a host is serving.Staging and preview responses are sent with
X-Robots-Tag: noindexandCache-Control: private, no-store, and analytics stay off on every preview hostname. Automated HTTP and Playwright checks send the Access service token only to the preview origin and never follow a redirect with it. The Cloudflare Pages PR preview workflow is removed so in-progress work is no longer published without protection. Same-repository PRs keep their protected Worker previews.Live verification now accepts the organization's page title and Cloudflare's
noindexheader on versioned Workers URLs; custom staging still requiresnoindex, nofollow, noarchive. Astro, MDX, and the analytics integration are declared as build dependencies because they do not ship in the production Worker. The unchanged production dependency audit passes without advisory exceptions.The trade-off is that production content, including calendar updates, stays at the last promoted release until someone reviews staging and promotes a newer run. To roll back, promote an earlier run while its artifact is retained (90 days), or use
wrangler rollbackwith a recorded version.Follow-ups
lvbt-website-preview; the GitHub environment contains both verification secrets. The service token expires October 3, 2027.🤖 Generated with Claude Code