You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit fa7fd65
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: CHANGELOG.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,6 +2,10 @@
2
2
3
3
## Unreleased
4
4
5
+
### Umami proxy provision
6
+
-**Deploy the Worker before binding `UMAMI_ORIGIN`.** wrangler-action’s `secrets:` input ran `secret bulk` first, which fails when the Worker does not exist yet — `wrangler.jsonc` still listed the `/s/*` route, so git looked provisioned while nothing was uploaded. CI now deploys, then `secret put`.
7
+
- PRs that touch the proxy run unit tests + `wrangler deploy --dry-run`; only `main` / `workflow_dispatch` deploy.
8
+
5
9
### CI verify on push (stacked-run walker)
6
10
-**`know-code verify --from <oid>`** walks `from..HEAD`, splits by `Know-Code-Verified` hash, and checks each run as a historical tree-pair (parent-of-first tree → last non-merge). Trailerless merges attach to the run but are not the hash tip, so a GitHub merge commit still matches after `main` moved. Linear commits without a trailer fail closed. One-non-merge runs also accept the empty-tree (index) hash of that feature tip.
7
11
-**Workflow + `init --workflow` + composite action** trigger on `push` to the base branch and pass `github.event.before`. PR verify is unchanged (`head.sha`, no `--from`). All-zeros `before` skips the walk.
|`CLOUDFLARE_API_TOKEN`|Token with Workers Scripts Edit + Workers Routes Edit on this account|
33
+
|`CLOUDFLARE_API_TOKEN`|Account-scoped token with **Workers Scripts Edit** (uploads the Worker) and **Workers Routes Edit** (attaches `/s/*`). Routes Edit alone leaves the route defined and the script missing.|
29
34
|`CLOUDFLARE_ACCOUNT_ID`| Cloudflare account ID |
30
35
|`UMAMI_ORIGIN`|`https://<your-umami-host>` (no trailing slash) |
31
36
32
37
First deploy: **Actions → umami-proxy → Run workflow**. Later pushes to
33
38
`infra/umami-proxy/**` on `main` deploy automatically
34
-
(`.github/workflows/umami-proxy.yml`). The action syncs `UMAMI_ORIGIN` as a
35
-
Worker secret on each run.
39
+
(`.github/workflows/umami-proxy.yml`). The workflow **deploys the Worker,
40
+
then** binds `UMAMI_ORIGIN`. Putting the secret first fails when the Worker
41
+
does not exist yet.
36
42
37
-
Manual fallback:
43
+
Manual fallback (same order):
38
44
39
45
```bash
40
-
npx wrangler secret put UMAMI_ORIGIN
41
46
npx wrangler deploy
47
+
npx wrangler secret put UMAMI_ORIGIN
42
48
```
43
49
44
50
5.**Docs build.** Repo variable `UMAMI_WEBSITE_ID` (Settings → Secrets and
0 commit comments