Skip to content

Commit f4e3c3b

Browse files
authored
Build PR previews without maintainer approval (#1806)
Fork previews currently pause each fork update in `fork-preview-protection` until a maintainer approves the environment deployment. This creates repeated approval requests, delays contributor feedback, and fills the Actions UI with waiting jobs. **This change removes the preview-specific maintainer approval step.** Every PR builds RDoc in a read-only workflow that has no secrets. A trusted `workflow_run` matches the `_site` artifact to the current PR head and rejects non-static Pages controls. ```mermaid sequenceDiagram actor Author as PR author participant PR as Pull request participant Build as Build PR Preview<br/>Untrusted, no secrets participant Artifact as GitHub artifact store participant Deploy as Deploy PR Preview<br/>Trusted participant Cloudflare as Cloudflare Pages Author->>PR: Open, update, or reopen the PR PR->>Build: Start pull_request workflow Build->>Build: Checkout PR code at the exact head SHA Build->>Build: Setup Ruby Build->>Build: Build site into _site alt The build produces an artifact Build->>Artifact: Upload preview site for one day else The build fails before upload Note over Build,Artifact: No preview artifact is available end Build-->>Deploy: workflow_run completed, success or failure Deploy->>Deploy: Resolve current pull request and artifact Deploy->>PR: Match one open PR to the exact head SHA Deploy->>Artifact: Match one artifact from this exact run alt The PR, SHA, or artifact is not current and valid Deploy--xDeploy: Stop before Cloudflare secrets else The candidate is current Artifact-->>Deploy: Download preview site Deploy->>Deploy: Validate preview site as safe static files Deploy->>PR: Confirm pull request head again alt The site is invalid or the PR head changed Deploy--xDeploy: Stop before deployment else The site is safe and the PR is current Deploy->>Deploy: Prepare trusted Wrangler directory Note over Deploy,Cloudflare: Cloudflare secrets are supplied only for this call Deploy->>Cloudflare: Deploy to the PR-number-preview branch Cloudflare-->>Deploy: Return an HTTPS pages.dev URL Deploy->>PR: Update preview comment after one final head and URL check Note over PR: Reuse one marked comment with the preview URL and commit SHA end end ``` Contributors now receive an updated preview after each commit that produces a preview artifact. Per-PR concurrency cancels older work, and one bot comment points to the latest successful preview. Maintainers no longer open individual environment deployments or receive repeated preview approval requests. The trusted workflow exposes the Cloudflare token only to the deployment step. It does not download the PR repository or run PR code. GitHub's separate public-fork policy can still hold workflows from contributors who are new to GitHub. Existing PRs can retain the old MATZBOT comment once. Later deployments update only the new GitHub Actions comment.
1 parent d2107e0 commit f4e3c3b

3 files changed

Lines changed: 395 additions & 148 deletions

File tree

0 commit comments

Comments
 (0)