Skip to content

Gateway Worker: RepositoryTokens entrypoint mints narrowed tokens for sibling Workers - #82

Merged
HereLiesAz merged 1 commit into
mainfrom
claude/amazing-fermi-3o92qn
Sep 27, 2026
Merged

HereLiesAz merged 1 commit into
mainfrom
claude/amazing-fermi-3o92qn

Conversation

@HereLiesAz

@HereLiesAz HereLiesAz commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

This replaces this PR's first approach, which forwarded GH_TOKEN into the store Worker. That change has been dropped from the branch.

The gateway Worker already holds the GitHub App (GH_APP_ID, GH_PRIVATE_KEY). It now also exposes RepositoryTokens, a WorkerEntrypoint that is reachable only over a Cloudflare service binding. There is no HTTP route, so nothing on the internet can call it.

  • azphaltPublishToken() mints an App installation token limited to HereLiesAz/azphalt, with contents: write and pull_requests: write. It is valid for about an hour and cached until five minutes before expiry. azphalt-store's POST /packages calls it through its GITHUB_TOKENS binding (storefront-worker: get the publish token from the gateway over a service binding azphalt#225).
  • Token minting is factored into mintInstallationToken(env, request). The existing full-installation path (githubInstallationToken) behaves exactly as before.

Needs: the App must grant Contents and Pull requests read/write, and be installed on azphalt. If it doesn't, GitHub refuses the narrowed token with a 422, and azphalt's publish answers 503.

Merge order: merge this first. azphalt#225 binds to the RepositoryTokens entrypoint.

Validation

  • node --check worker/src/index.js passes.
  • Ran both Workers in one wrangler dev session (real workerd), with a throwaway App key and id. The store's POST /packages reached RepositoryTokens over the binding, the gateway signed an App JWT and called GitHub, and GitHub's rejection of the fake App id came back through RPC. The store answered 503, as designed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv

Summary by Sourcery

Provide azphalt storefront workers with narrowly scoped GitHub publishing credentials through the Cloudflare Worker gateway.

New Features:

  • Expose a service-binding API that provides azphalt with short-lived, repository-scoped GitHub installation tokens for publishing packages and opening pull requests.

Enhancements:

  • Refactor GitHub installation-token minting to support narrowed repository and permission scopes while retaining existing gateway token behavior.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
workflows 0694f62 Commit Preview URL

Branch Preview URL
Sep 27 2026, 05:20 AM

@sourcery-ai

sourcery-ai Bot commented Sep 27, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This change wires the already-required central GH_TOKEN through the Cloudflare Worker deployment as GITHUB_PUBLISH_TOKEN, and enables only azphalt’s storefront profile to provision it using the existing Worker-secret bulk upload step. Review the secret naming/mapping and the intentionally broader token blast radius, while confirming other profiles remain unaffected.

Sequence diagram for forwarding GH_TOKEN to the azphalt Worker

sequenceDiagram
    participant GitHubActions
    participant DeployWorkflow
    participant Wrangler
    participant AzphaltWorker
    participant GitHubAPI

    GitHubActions->>DeployWorkflow: Read secrets.GH_TOKEN
    DeployWorkflow->>Wrangler: FORWARD_GITHUB_PUBLISH_TOKEN
    Wrangler->>AzphaltWorker: wrangler secret bulk
    AzphaltWorker->>GitHubAPI: POST /packages using GITHUB_PUBLISH_TOKEN
    GitHubAPI-->>AzphaltWorker: Review pull request result
Loading

File-Level Changes

Change Details Files
Forward the central GitHub token into the deploy-time Worker secret configuration.
  • Expose secrets.GH_TOKEN as FORWARD_GITHUB_PUBLISH_TOKEN in the deployment environment.
  • Rely on the existing GH_TOKEN preflight requirement rather than adding new validation.
.github/workflows/cloudflare-worker-deploy.yml
Opt the azphalt storefront profile into receiving the GitHub publishing secret.
  • Add GITHUB_PUBLISH_TOKEN to the profile’s worker_secrets list.
  • Use the existing post-deploy wrangler secret bulk flow to provision the secret; leave other profiles unchanged.
scripts/semantic_catalog.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

… sibling Workers

A WorkerEntrypoint reachable only over a Cloudflare service binding (no
public route). azphaltPublishToken() mints an App installation token
limited to HereLiesAz/azphalt with contents and pull-requests write, for
azphalt-store's POST /packages, cached until five minutes before expiry.
Token minting is factored into mintInstallationToken(env, request) so the
existing full-installation token path is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
@HereLiesAz
HereLiesAz force-pushed the claude/amazing-fermi-3o92qn branch from ddde48c to 0694f62 Compare September 27, 2026 05:20
@HereLiesAz HereLiesAz changed the title Cloudflare Worker Deploy: forward GH_TOKEN as GITHUB_PUBLISH_TOKEN for azphalt's storefront Gateway Worker: RepositoryTokens entrypoint mints narrowed tokens for sibling Workers Sep 27, 2026
@HereLiesAz
HereLiesAz marked this pull request as ready for review September 27, 2026 05:35

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 16 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@HereLiesAz
HereLiesAz merged commit 6360f68 into main Sep 27, 2026
4 checks passed
@HereLiesAz
HereLiesAz deleted the claude/amazing-fermi-3o92qn branch September 27, 2026 05:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants