storefront-worker: get the publish token from the gateway over a service binding - #225
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Reviewer's guide (collapsed on small PRs)Reviewer's GuideDocumentation now describes the centralized deployment flow for Sequence diagram for centralized GitHub token provisioningsequenceDiagram
participant Workflow as CentralDeployWorkflow
participant Worker as StorefrontWorker
participant GitHub as GitHubRepository
Workflow->>Worker: Deploy Worker
Workflow->>Worker: Forward GH_TOKEN as GITHUB_PUBLISH_TOKEN
Worker->>GitHub: POST /packages using GITHUB_PUBLISH_TOKEN
GitHub-->>Worker: Contents and pull request access
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
…ice binding POST /packages now asks HereLiesAz/workflows' gateway Worker for a GitHub token through the GITHUB_TOKENS service binding (RepositoryTokens entrypoint): a one-hour App installation token narrowed to HereLiesAz/azphalt with contents and pull-requests write. It is fetched only after the package verifies; a failed mint answers 503. The Worker keeps no GitHub secret; a fixed GITHUB_PUBLISH_TOKEN stays as an override for self-hosted deploys. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
8890aa0 to
da52070
Compare
|
Two checks fail on this PR, and neither comes from it:
Sourcery's reviewer's guide describes this PR's first version, which forwarded Generated by Claude Code |
There was a problem hiding this comment.
Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 1 day and 16 hours by commenting @sourcery-ai review. Upgrade to get a review now.
Summary
POST /packagesno longer needs a GitHub secret. It asks HereLiesAz/workflows' gateway Worker for a token over a Cloudflare service binding.wrangler.jsonc:services: [{ binding: "GITHUB_TOKENS", service: "workflows", entrypoint: "RepositoryTokens" }].src/publish.ts:GITHUB_TOKENS.azphaltPublishToken()for a one-hour App installation token limited toHereLiesAz/azphalt(contents and pull-requests write).503 unavailable.GITHUB_PUBLISH_TOKENstill wins, as an override for deployments without the gateway. With neither, the endpoint answers501, as before.Merge order: after HereLiesAz/workflows#82, which adds the
RepositoryTokensentrypoint. Until that deploys, the binding has nothing to call, so publishes answer503.Validation
503.typecheckpasses.wrangler dev(real workerd). The binding reached the gateway's entrypoint and the gateway called GitHub; its App error came back as503.🤖 Generated with Claude Code
https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv