Skip to content

docs: fix Access config, add Deploy to Cloudflare button, update deploy script - #26

Merged
tbjers merged 1 commit into
mainfrom
docs/access-config-and-deploy-button
Jun 27, 2026
Merged

tbjers merged 1 commit into
mainfrom
docs/access-config-and-deploy-button

Conversation

@tbjers

@tbjers tbjers commented Jun 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Access configuration: Replace the contradictory single-app instructions with the correct two-app model — an Allow application on the root domain (issues the CF_Authorization session cookie for the dashboard) plus a Bypass application scoped to /api (lets machine callers reach the Worker so in-code auth can run). Clarifies that WAF skip rules are for Bot Fight Mode only, which is a separate layer from Access.
  • Deploy to Cloudflare button: Added to README with a note that the button automates Worker + D1 provisioning but not the GitHub App / Zero Trust / secrets steps. package.json deploy script updated to run wrangler d1 migrations apply DB --remote before wrangler deploy so migrations are included in every deploy and in the button flow.
  • Stale references fixed: "Cloudflare Pages dashboard" → "dashboard (served as static assets by the Worker)"; Phase 3 Access description corrected in PROGRESS.md; WAF rule paths updated from old routes to current /api/ci/coverage and /api/webhooks/github.

Test plan

  • Verify the Deploy to Cloudflare button resolves correctly (click it, confirm it reaches the Cloudflare deploy UI with this repo pre-filled)
  • Confirm npm run deploy runs migrations before deploying (check output order)
  • Follow INSTALLATION.md Step 10 and create both Access applications; verify machine callers (CI OIDC) can reach /api/ci/coverage and browser users can reach /api/projects via the session cookie

🤖 Generated with Claude Code

…oy script

- INSTALLATION.md: replace contradictory single-app Access instructions with
  correct two-app model (Allow on root domain + Bypass on /api); clarify WAF
  skip rules are for Bot Fight Mode only (separate from Access); fix Step 3 to
  reflect that wrangler.jsonc is already committed without database_id by design;
  deploy step now uses `npm run deploy` which includes migrations
- README.md: add Deploy to Cloudflare button; fix stale "Cloudflare Pages"
  reference; update Phase 7 status to In progress
- PROGRESS.md: correct Phase 3 Access description; correct WAF rule paths and
  scope note; update Phase 7 checklist with completed items
- package.json: deploy script now runs `wrangler d1 migrations apply DB --remote`
  before `wrangler deploy` so D1 migrations apply on every deploy and the Deploy
  button flow gets them automatically
- .gitignore: add .claude/ to keep Claude Code project memory out of git

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@tbjers
tbjers merged commit 6d7dece into main Jun 27, 2026
3 checks passed
@tbjers
tbjers deleted the docs/access-config-and-deploy-button branch June 27, 2026 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant