Gateway Worker: RepositoryTokens entrypoint mints narrowed tokens for sibling Workers - #82
Merged
Merged
Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
workflows | 0694f62 | Commit Preview URL Branch Preview URL |
Sep 27 2026, 05:20 AM |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThis change wires the already-required central Sequence diagram for forwarding GH_TOKEN to the azphalt WorkersequenceDiagram
participant GitHubActions
participant DeployWorkflow
participant Wrangler
participant AzphaltWorker
participant GitHubAPI
GitHubActions->>DeployWorkflow: Read secrets.GH_TOKEN
DeployWorkflow->>Wrangler: FORWARD_GITHUB_PUBLISH_TOKEN
Wrangler->>AzphaltWorker: wrangler secret bulk
AzphaltWorker->>GitHubAPI: POST /packages using GITHUB_PUBLISH_TOKEN
GitHubAPI-->>AzphaltWorker: Review pull request result
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
… sibling Workers A WorkerEntrypoint reachable only over a Cloudflare service binding (no public route). azphaltPublishToken() mints an App installation token limited to HereLiesAz/azphalt with contents and pull-requests write, for azphalt-store's POST /packages, cached until five minutes before expiry. Token minting is factored into mintInstallationToken(env, request) so the existing full-installation token path is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
HereLiesAz
force-pushed
the
claude/amazing-fermi-3o92qn
branch
from
September 27, 2026 05:20
ddde48c to
0694f62
Compare
HereLiesAz
marked this pull request as ready for review
September 27, 2026 05:35
There was a problem hiding this comment.
Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 1 day and 16 hours by commenting @sourcery-ai review. Upgrade to get a review now.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This replaces this PR's first approach, which forwarded
GH_TOKENinto the store Worker. That change has been dropped from the branch.The gateway Worker already holds the GitHub App (
GH_APP_ID,GH_PRIVATE_KEY). It now also exposesRepositoryTokens, aWorkerEntrypointthat is reachable only over a Cloudflare service binding. There is no HTTP route, so nothing on the internet can call it.azphaltPublishToken()mints an App installation token limited toHereLiesAz/azphalt, withcontents: writeandpull_requests: write. It is valid for about an hour and cached until five minutes before expiry. azphalt-store'sPOST /packagescalls it through itsGITHUB_TOKENSbinding (storefront-worker: get the publish token from the gateway over a service binding azphalt#225).mintInstallationToken(env, request). The existing full-installation path (githubInstallationToken) behaves exactly as before.Needs: the App must grant Contents and Pull requests read/write, and be installed on
azphalt. If it doesn't, GitHub refuses the narrowed token with a 422, and azphalt's publish answers503.Merge order: merge this first. azphalt#225 binds to the
RepositoryTokensentrypoint.Validation
node --check worker/src/index.jspasses.wrangler devsession (real workerd), with a throwaway App key and id. The store'sPOST /packagesreachedRepositoryTokensover the binding, the gateway signed an App JWT and called GitHub, and GitHub's rejection of the fake App id came back through RPC. The store answered503, as designed.🤖 Generated with Claude Code
https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
Summary by Sourcery
Provide azphalt storefront workers with narrowly scoped GitHub publishing credentials through the Cloudflare Worker gateway.
New Features:
Enhancements: