Repository navigation
ci: skip the broker deploy when CLOUDFLARE_API_TOKEN is not set - #2116
asasemahmed wants to merge 1 commit into
Conversation
deploy-composio-broker runs on every push to main, but without the CLOUDFLARE_API_TOKEN secret wrangler aborts and the run ends red, so a missing secret looks like a broken main. Check the token in a first step and run the remaining steps only when it is present; otherwise emit a warning annotation saying the broker was not deployed. The job-level condition, its dependency on control-plane and its absence from the merge gate are unchanged, and the self-test now pins the guard. Refs milind-soni#1914
|
@asasemahmed is attempting to deploy a commit to the SupaMaus Team on Vercel. A member of the Team first needs to authorize it. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 4 remain after this review. 📝 WalkthroughWalkthroughThe broker deployment job checks whether ChangesBroker deployment
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Without the Cloudflare token, broker deployment is visibly skipped without blocking the documented CI gate; with the token, the existing deploy path runs. No repository evidence indicates a material merge risk. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change preserves the existing deployment prerequisites and does not visibly expand deployment authority. Missing credentials prevent deployment rather than bypassing authentication. Live token permissions, deployed state, and recovery after interrupted deployments remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What changed
deploy-composio-brokerstarts with atokenstep that records whetherCLOUDFLARE_API_TOKENis set. Checkout, pnpm, Node, install and the wrangler deploy run only when it is. Without it, the job succeeds with a warning annotation: "CLOUDFLARE_API_TOKEN is not set, so the broker Worker was not deployed."scripts/ci-workflow.test.tspins this: the first step is the token check, and every later step waits on its output. The job'sneeds, itsif, and its absence from the merge gate are untouched.Why
The #2074 deploy job now runs on main, but the repo has no
CLOUDFLARE_API_TOKENsecret, so the latest main run fails at wrangler with "it's necessary to set a CLOUDFLARE_API_TOKEN environment variable". A missing secret then shows up as a red main commit, and the same would happen on any fork. A skipped deploy with a visible warning keeps main readable while the token is still to be created. Once the secret exists, behavior is exactly what #2074 intended.Refs #1914 (the code is merged; the deploy still needs the token).
How it was verified
pnpm exec vitest run scripts/ci-scope.test.ts scripts/ci-workflow.test.ts scripts/testing/verification-docs.test.ts: 59 passed (the exact command the static job runs).Screenshots (UI changes)
N/A
Checklist
pnpm typecheckandpnpm testpass locallydist-server/edits (it's build output)shell: true/ cmd.exe string-buildingSummary by CodeRabbit