Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .dev.vars.example
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,8 @@ GITHUB_WEBHOOK_SECRET=
CF_ACCESS_AUD=
# Your Cloudflare Access team domain, e.g. myteam.cloudflareaccess.com
CF_ACCESS_TEAM_DOMAIN=

# Local dev only — lets the dashboard bypass Access JWT verification when running locally.
# Set the same random string in dashboard/.dev.vars (or dashboard/.env).
# NEVER add this to wrangler.jsonc vars or set it as a wrangler secret.
DEV_BYPASS_SECRET=
54 changes: 54 additions & 0 deletions .github/workflows/deploy-dashboard.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
name: Deploy dashboard

on:
push:
branches: [main]
paths:
- 'dashboard/**'
- '.github/workflows/deploy-dashboard.yml'
pull_request:
paths:
- 'dashboard/**'
- '.github/workflows/deploy-dashboard.yml'

permissions:
contents: read

jobs:
deploy:
runs-on: ubuntu-latest
environment:
name: ${{ github.ref == 'refs/heads/main' && 'production' || 'preview' }}
url: ${{ steps.deploy.outputs.deployment-url }}
steps:
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
with:
node-version: '20'
cache: npm
cache-dependency-path: dashboard/package-lock.json

- name: Install dependencies
working-directory: dashboard
run: npm ci

- name: Install wrangler
run: npm install -g wrangler@^4

- name: Build
working-directory: dashboard
run: npm run build

- name: Deploy to Cloudflare Pages
id: deploy
working-directory: dashboard
run: |
OUTPUT=$(wrangler pages deploy \
${{ github.ref != 'refs/heads/main' && format('--branch {0}', github.head_ref || github.ref_name) || '' }})
echo "$OUTPUT"
URL=$(echo "$OUTPUT" | grep -oP 'https://[^\s]+\.pages\.dev[^\s]*' | tail -1)
echo "deployment-url=${URL}" >> "$GITHUB_OUTPUT"
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -4,5 +4,6 @@ node_modules/
.*.vars
!.*.vars.example
wrangler.jsonc
!dashboard/wrangler.jsonc
*.local
*.pem
14 changes: 14 additions & 0 deletions dashboard/.env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# For local development with `npm run dev` (Vite):
# Copy to .env
#
# For local development with `wrangler pages dev` (simulates Cloudflare runtime):
# Copy to .dev.vars

# URL of your deployed Worker (no trailing slash)
WORKER_URL=https://coverage-tracker.yourdomain.com

# Local dev only — must match DEV_BYPASS_SECRET in the Worker's .dev.vars.
# With this set, the dashboard passes X-Dev-Bypass to the local Worker so it
# skips Cloudflare Access JWT verification during local development.
# NEVER set this in production (Cloudflare Pages environment variables).
DEV_BYPASS_SECRET=
7 changes: 7 additions & 0 deletions dashboard/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
node_modules/
.svelte-kit/
build/
.env
.env.*
!.env.example
.dev.vars
Loading
Loading