Repository navigation
Document harper deploy setup=true provider=github-actions, and how a workflow uses a trust policy - #722
Document harper deploy setup=true provider=github-actions, and how a workflow uses a trust policy#722dawsontoth wants to merge 5 commits into
harper deploy setup=true provider=github-actions, and how a workflow uses a trust policy#722Conversation
…a workflow uses a trust policy - commands.md: a GitHub Actions deploys (OIDC) section for the new setup provider: what it checks and creates, that it only creates, its names, and how to revoke; `setup=true` mentions it - authentication.md: a "Using it in a workflow" subsection that says plainly that nothing in a workflow names the policy, and every `harper` command in a job authenticates through it when four conditions hold, with a one-job excerpt - operations.md and the CI guide point at both, and the guide notes the setup command suits branch-triggered workflows, not its tag-triggered ones - 5.4 release notes: the new setup Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… looked up, and what the workflow check refuses Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
From the pre-push review: - the CI guide's :::tip closing marker sat on the paragraph's last line, so the admonition never closed; it now has a line of its own - "every harper command authenticates" now says each may do only what the policy's user's role allows, and the guide notes setup's role lacks the get_deployment the manual role adds - condition 4 lists every credential that outranks the exchange, and links the precedence order - commands.md says a missing workflow file leaves the whole check unverified, that a concurrent writer can still overwrite the policy, and what to do when setting the variable fails; every page names the role setup creates Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…say a rerun sets the variable again Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Code Review
This pull request updates the documentation across several files to introduce and explain the new GitHub Actions OIDC deployment setup (harper deploy setup=true provider=github-actions) added in version 5.4.0. The review feedback highlights multiple instances where the component is incorrectly used within running prose or mid-sentence, advising the use of plain text instead to maintain consistent formatting.
🚀 Preview DeploymentYour preview deployment is ready! 🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-722 This preview will update automatically when you push new commits. |
…ge for headings Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
🚀 Preview DeploymentYour preview deployment is ready! 🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-722 This preview will update automatically when you push new commits. |
Documents
harper deploy setup=true provider=github-actions(HarperFast/harper#3127), the one-command setup for GitHub Actions deploys that HarperFast/create-harper#147'sdeploy:setup-ciruns. It also makes plain how a workflow uses a trust policy once it exists: nothing names it, and everyharpercommand in the job authenticates through it when four conditions hold.Depends-on: HarperFast/harper#3127
For the human reviewer
harper deploy, and any otherharpercommand in a correctly set-up job, authenticates by itself once a policy exists. It is now a subsection of Workload identity listing the four conditions, with a one-job excerpt, and the operations reference and CI guide point at it. It says that authentication is not authorization: what each command may do is the policy's user's role.get_deployment.commands.mdsays setup re-checks just before writing the policy but a concurrent super user can still have it overwritten, matching the decision in Set up GitHub Actions deploys withharper deploy setup=true provider=github-actionsharper#3127.Changes
reference/cli/commands.md: a GitHub Actions deploys (OIDC) section for the new provider, covering the repository lookup, the workflow check, the names, create-only, recovery when the variable can't be set, revocation and the branch-pin scope; thesetup=trueparameter mentions it.reference/cli/authentication.md: the one-command setup, and the "Using it in a workflow" subsection.reference/operations-api/operations.md: the OIDC section points at both.learn/developers/deploying-from-ci.mdx: the same pointer, and the tip.release-notes/v5-lincoln/5.4.md: the new setup, badged v5.4.0 like the rest.Verification
npm run format:checkandnpm run buildpass.bin/deploySetupGithubActions.tson the Set up GitHub Actions deploys withharper deploy setup=true provider=github-actionsharper#3127 branch, which was also run live against a local build (see that PR). The steps were rewritten after the Harper review rounds changed the behavior (the repository is now always looked up; the workflow check refuses a workflow with no environment).Related PRs: #713 overlaps
Complexity: easy
🤖 Generated with Claude Code
Review-Coverage: authored=claude; ran=gemini,cursor-composer,codex,cursor-muse; adjudicated=domain; declined=cursor-grok,cursor-kimi; rounds=2; full=2 @ 3bf4f3d
Review-Attention: skim ~2m (decisions: setup-pins-one-branch, document-race-not-fix, rerun-rewrites-variable) @ 3bf4f3d