Commit f4e3c3b
authored
Build PR previews without maintainer approval (#1806)
Fork previews currently pause each fork update in
`fork-preview-protection` until a maintainer approves the environment
deployment. This creates repeated approval requests, delays contributor
feedback, and fills the Actions UI with waiting jobs.
**This change removes the preview-specific maintainer approval step.**
Every PR builds RDoc in a read-only workflow that has no secrets. A
trusted `workflow_run` matches the `_site` artifact to the current PR
head and rejects non-static Pages controls.
```mermaid
sequenceDiagram
actor Author as PR author
participant PR as Pull request
participant Build as Build PR Preview<br/>Untrusted, no secrets
participant Artifact as GitHub artifact store
participant Deploy as Deploy PR Preview<br/>Trusted
participant Cloudflare as Cloudflare Pages
Author->>PR: Open, update, or reopen the PR
PR->>Build: Start pull_request workflow
Build->>Build: Checkout PR code at the exact head SHA
Build->>Build: Setup Ruby
Build->>Build: Build site into _site
alt The build produces an artifact
Build->>Artifact: Upload preview site for one day
else The build fails before upload
Note over Build,Artifact: No preview artifact is available
end
Build-->>Deploy: workflow_run completed, success or failure
Deploy->>Deploy: Resolve current pull request and artifact
Deploy->>PR: Match one open PR to the exact head SHA
Deploy->>Artifact: Match one artifact from this exact run
alt The PR, SHA, or artifact is not current and valid
Deploy--xDeploy: Stop before Cloudflare secrets
else The candidate is current
Artifact-->>Deploy: Download preview site
Deploy->>Deploy: Validate preview site as safe static files
Deploy->>PR: Confirm pull request head again
alt The site is invalid or the PR head changed
Deploy--xDeploy: Stop before deployment
else The site is safe and the PR is current
Deploy->>Deploy: Prepare trusted Wrangler directory
Note over Deploy,Cloudflare: Cloudflare secrets are supplied only for this call
Deploy->>Cloudflare: Deploy to the PR-number-preview branch
Cloudflare-->>Deploy: Return an HTTPS pages.dev URL
Deploy->>PR: Update preview comment after one final head and URL check
Note over PR: Reuse one marked comment with the preview URL and commit SHA
end
end
```
Contributors now receive an updated preview after each commit that
produces a preview artifact. Per-PR concurrency cancels older work, and
one bot comment points to the latest successful preview. Maintainers no
longer open individual environment deployments or receive repeated
preview approval requests.
The trusted workflow exposes the Cloudflare token only to the deployment
step. It does not download the PR repository or run PR code. GitHub's
separate public-fork policy can still hold workflows from contributors
who are new to GitHub. Existing PRs can retain the old MATZBOT comment
once. Later deployments update only the new GitHub Actions comment.1 parent d2107e0 commit f4e3c3b
3 files changed
Lines changed: 395 additions & 148 deletions
0 commit comments