Skip to content

Document harper deploy setup=true provider=github-actions, and how a workflow uses a trust policy - #722

Open
dawsontoth wants to merge 5 commits into
mainfrom
docs/deploy-setup-github-actions
Open

dawsontoth wants to merge 5 commits into
mainfrom
docs/deploy-setup-github-actions

Conversation

@dawsontoth

@dawsontoth dawsontoth commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Documents harper deploy setup=true provider=github-actions (HarperFast/harper#3127), the one-command setup for GitHub Actions deploys that HarperFast/create-harper#147's deploy:setup-ci runs. It also makes plain how a workflow uses a trust policy once it exists: nothing names it, and every harper command in the job authenticates through it when four conditions hold.

Depends-on: HarperFast/harper#3127

For the human reviewer

  1. Requirement: the "using it in a workflow" section. You asked for it to be easy to see that harper deploy, and any other harper command in a correctly set-up job, authenticates by itself once a policy exists. It is now a subsection of Workload identity listing the four conditions, with a one-job excerpt, and the operations reference and CI guide point at it. It says that authentication is not authorization: what each command may do is the policy's user's role.
  2. The CI guide keeps its hand-written, tag-triggered policy. The setup command pins one branch, which a tag-triggered workflow can't match, so the guide only points at the command in a tip for branch-triggered workflows (create-harper's), and says its role lacks the guide's get_deployment.
  3. The residual race is documented, not hidden. commands.md says setup re-checks just before writing the policy but a concurrent super user can still have it overwritten, matching the decision in Set up GitHub Actions deploys with harper deploy setup=true provider=github-actions harper#3127.

Changes

Verification

  • npm run format:check and npm run build pass.
  • Each claim about the setup was checked against bin/deploySetupGithubActions.ts on the Set up GitHub Actions deploys with harper deploy setup=true provider=github-actions harper#3127 branch, which was also run live against a local build (see that PR). The steps were rewritten after the Harper review rounds changed the behavior (the repository is now always looked up; the workflow check refuses a workflow with no environment).
  • Cross-model review: Codex, Gemini, Cursor and the Claude domain adjudicator, two rounds ending in a closing full round.

Related PRs: #713 overlaps

Complexity: easy

🤖 Generated with Claude Code

Review-Coverage: authored=claude; ran=gemini,cursor-composer,codex,cursor-muse; adjudicated=domain; declined=cursor-grok,cursor-kimi; rounds=2; full=2 @ 3bf4f3d

Review-Attention: skim ~2m (decisions: setup-pins-one-branch, document-race-not-fix, rerun-rewrites-variable) @ 3bf4f3d

dawsontoth and others added 4 commits October 8, 2026 16:56
…a workflow uses a trust policy

- commands.md: a GitHub Actions deploys (OIDC) section for the new setup
  provider: what it checks and creates, that it only creates, its names, and
  how to revoke; `setup=true` mentions it
- authentication.md: a "Using it in a workflow" subsection that says plainly
  that nothing in a workflow names the policy, and every `harper` command in a
  job authenticates through it when four conditions hold, with a one-job excerpt
- operations.md and the CI guide point at both, and the guide notes the setup
  command suits branch-triggered workflows, not its tag-triggered ones
- 5.4 release notes: the new setup

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… looked up, and what the workflow check refuses

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
From the pre-push review:
- the CI guide's :::tip closing marker sat on the paragraph's last line, so the
  admonition never closed; it now has a line of its own
- "every harper command authenticates" now says each may do only what the
  policy's user's role allows, and the guide notes setup's role lacks the
  get_deployment the manual role adds
- condition 4 lists every credential that outranks the exchange, and links the
  precedence order
- commands.md says a missing workflow file leaves the whole check unverified,
  that a concurrent writer can still overwrite the policy, and what to do when
  setting the variable fails; every page names the role setup creates

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…say a rerun sets the variable again

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the documentation across several files to introduce and explain the new GitHub Actions OIDC deployment setup (harper deploy setup=true provider=github-actions) added in version 5.4.0. The review feedback highlights multiple instances where the component is incorrectly used within running prose or mid-sentence, advising the use of plain text instead to maintain consistent formatting.

Comment thread learn/developers/deploying-from-ci.mdx Outdated
Comment thread reference/cli/authentication.md Outdated
Comment thread reference/operations-api/operations.md Outdated
@github-actions
github-actions Bot temporarily deployed to pr-722 October 9, 2026 01:59 Inactive
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-722

This preview will update automatically when you push new commits.

…ge for headings

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-722

This preview will update automatically when you push new commits.

@dawsontoth
dawsontoth marked this pull request as ready for review October 9, 2026 02:34
@dawsontoth
dawsontoth requested a review from a team as a code owner October 9, 2026 02:34

This branch was successfully deployed

1 active deployment
pr-722 — 3519a9a0 Deployed Oct 9, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant