Skip to content

Proposal for fork-safe preview strategy - #32

Merged
rhingo merged 3 commits into
aplbrain:mainfrom
CodyCBakerPhD:claude/preview-separate-repo
Sep 25, 2026
Merged

rhingo merged 3 commits into
aplbrain:mainfrom
CodyCBakerPhD:claude/preview-separate-repo

Conversation

@CodyCBakerPhD

@CodyCBakerPhD CodyCBakerPhD commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Which does not alter the current deployment strategy

Requires an admin on this repo to create a new repo and mint a fine-grain token as described in the instructions: https://github.com/aplbrain/BBQS-EMBER-docs/pull/32/changes#diff-fc2a310fcfedfefb0046def697f932def80cbb1e78c689bc0af3c8eab3e33eceR60-R79

Alternative to the gh-pages migration: keep this repository's GitHub
Pages setup on the Actions source and publish previews into a dedicated
previews repository instead, using pr-preview-action's deploy-repository
input with a fine-grained token.

deploy-pages.yaml is unchanged, so the production deploy path and the
custom domain are untouched and no Pages settings change is needed.
Preview content is served from a different origin than the production
docs, so unreviewed contributor HTML never shares an origin with
docs.emberarchive.org.

Fork support uses the same trust boundary as the other variant: the
untrusted build runs read-only in check-docs.yaml and hands the built
site to preview.yaml via an artifact; preview.yaml (workflow_run) and
preview-cleanup.yaml (pull_request_target) can read the deploy token but
never check out or execute pull request code. SECURITY.md records the
invariants and how to scope the token.

Both preview workflows no-op until PREVIEW_REPOSITORY is set, so this is
safe to merge before the previews repository exists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015KZdA347fHh4xxpdHkVwxQ
Remove fork-preview.yaml, the opt-in workflow letting contributors host a
preview from their own fork. The upstream pipeline now covers fork pull
requests, so the fallback was redundant setup for contributors to learn.

Remove preview-cleanup.yaml, which deleted a preview when its pull
request closed. This was the only pull_request_target workflow, so the
repository no longer uses that trigger at all.

Previews are consequently never removed automatically, including those
from closed or rejected pull requests. They sit on their own origin so
they cannot affect the production docs, but the previews repository now
needs periodic pruning. Document that in DEVELOPMENT.md and record the
consequence in SECURITY.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015KZdA347fHh4xxpdHkVwxQ
The artifact only needs to survive long enough for preview.yaml to
consume it, but a one-day window means a failed preview deploy can no
longer be re-run from the original build by the time anyone looks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015KZdA347fHh4xxpdHkVwxQ

@NEStock NEStock left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for setting this up!
this looks good ton me. I've also completed steps 1-3 described in 'One-time setup'.

@CodyCBakerPhD

Copy link
Copy Markdown
Contributor Author

@NEStock Oky doky, if we trust and follow the rest of the steps we would need to merge this, update the branch #30, and ensure the gh-pages branch exists on the other repo, then complete step 5 and the rest should hopefully work without a hitch

🤞

@rhingo
rhingo merged commit 0bf755a into aplbrain:main Sep 25, 2026
3 checks passed
@CodyCBakerPhD
CodyCBakerPhD deleted the claude/preview-separate-repo branch September 25, 2026 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants