Purge Bunny CDN after successful docs deployments - #44
Merged
Merged
Conversation
Enable a full Pull Zone purge in Deploy Docs only after every storage upload and deployment-manifest write succeeds. Validate the separate account key and zone ID before uploads, and preserve upload-only CLI use. Guide operators through the new settings and document environment scope, recovery, and browser-cache limits alongside regression coverage. Constraint: Bunny's CDN management API requires an account API key distinct from the storage-zone password. Rejected: Add a separate purge entrypoint | the existing uploader preserves ordering and current CI path coverage. Confidence: high Scope-risk: moderate Directive: Keep purge after all upload/manifest writes; never pass the account key in curl arguments or logs. Tested: Purge regressions, 14 setup cases, full script suite, docs/workflow contracts, syntax, actionlint, ShellCheck. Tested: Real-curl loopback success, transient retry, redirect rejection, and hidden authentication errors. Tested: Workspace lint/typechecks, production web builds, and combined static-site verification. Not-tested: Live Bunny purge or a workflow run with operator-supplied new settings; no credentials were changed. Related: #43
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Docs deployments upload new files to Bunny Storage while the CDN can keep serving cached content. Deploy Docs now requests a full CDN Pull Zone purge after every file upload and deployment-manifest write succeeds. Invalid configuration fails before upload, and HTTP or transport failures fail the deployment.
The existing uploader gains opt-in
--purge-cache; the workflow always enables it. The account key travels through stdin, curl config files and redirects are disabled, response bodies stay hidden, and waits/retries are bounded. Upload-only CLI use and the legacy Unix setup helper remain supported. CDN purges do not invalidate existing browser caches or guarantee immediate refresh on every edge.Architecture layers: deployment/platform integration and CLI configuration. Updated docs: GitHub Actions setup, release guide, unreleased notes, and the GSD plan/verification summary. No dependency or native audio changes.
Configure these two new settings under Settings → Environments → docs-production before the next production deployment:
BUNNY_API_KEY: the account API key from Bunny API Keys. Keep the existingBUNNY_ACCESS_KEYstorage-zone password unchanged.BUNNY_PULL_ZONE_ID: the numeric CDN Pull Zone ID. The currentloopwire.appresponse identifies zone6140916; confirm that zone in the Bunny CDN dashboard, not the Storage dashboard.The guarded
pnpm setup:githubcommand configures repository-level settings and its--checkchecks that scope only. Environment values override matching repository values.Validation:
node scripts/test-docs-cache-purge.mjspassed after first reproducing the unsupported-option failure. Covers ordering, manifest failure, upload failure, dry run, preflight, int64 boundaries/leading zeros, prefix behavior, HTTP/network errors, and secret handling.node scripts/test-setup-github-actions.mjspassed all 14 cases after confirming the new required-name regression failed first.bash scripts/verify-scripts.sh,bash scripts/verify-github-workflows.sh, andbash scripts/verify-docs.shpassed.git diff --check, and added-line length checks passed.pnpm lintpassed workspace typechecks/Svelte checks with zero errors or warnings.pnpm build:web && pnpm verify:sitepassed production Astro/VitePress builds and combined static-site verification.git merge-tree --write-tree HEAD origin/ci/41-scope-workflowsconfirmed clean compatibility with pending Scope CI and deployment to affected files #42.No live Bunny API call, credential change, or production deployment was performed. Production purge validation requires the operator-supplied settings above. Native app/audio tests were outside this deployment-only change.
Closes #43.