Skip to content

Purge Bunny CDN after successful docs deployments - #44

Merged
dskvr merged 1 commit into
masterfrom
feature/43-bunny-cache-purge
Sep 5, 2026
Merged

dskvr merged 1 commit into
masterfrom
feature/43-bunny-cache-purge

Conversation

@dskvr

@dskvr dskvr commented Sep 5, 2026

Copy link
Copy Markdown
Member

Docs deployments upload new files to Bunny Storage while the CDN can keep serving cached content. Deploy Docs now requests a full CDN Pull Zone purge after every file upload and deployment-manifest write succeeds. Invalid configuration fails before upload, and HTTP or transport failures fail the deployment.

The existing uploader gains opt-in --purge-cache; the workflow always enables it. The account key travels through stdin, curl config files and redirects are disabled, response bodies stay hidden, and waits/retries are bounded. Upload-only CLI use and the legacy Unix setup helper remain supported. CDN purges do not invalidate existing browser caches or guarantee immediate refresh on every edge.

Architecture layers: deployment/platform integration and CLI configuration. Updated docs: GitHub Actions setup, release guide, unreleased notes, and the GSD plan/verification summary. No dependency or native audio changes.

Configure these two new settings under Settings → Environments → docs-production before the next production deployment:

  • Environment secret BUNNY_API_KEY: the account API key from Bunny API Keys. Keep the existing BUNNY_ACCESS_KEY storage-zone password unchanged.
  • Environment variable BUNNY_PULL_ZONE_ID: the numeric CDN Pull Zone ID. The current loopwire.app response identifies zone 6140916; confirm that zone in the Bunny CDN dashboard, not the Storage dashboard.

The guarded pnpm setup:github command configures repository-level settings and its --check checks that scope only. Environment values override matching repository values.

Validation:

  • node scripts/test-docs-cache-purge.mjs passed after first reproducing the unsupported-option failure. Covers ordering, manifest failure, upload failure, dry run, preflight, int64 boundaries/leading zeros, prefix behavior, HTTP/network errors, and secret handling.
  • node scripts/test-setup-github-actions.mjs passed all 14 cases after confirming the new required-name regression failed first.
  • Independent real-curl loopback checks passed: successful purge, 503→204 retry with intact private header, rejected redirect, and hidden authentication-error body.
  • bash scripts/verify-scripts.sh, bash scripts/verify-github-workflows.sh, and bash scripts/verify-docs.sh passed.
  • Node/Bash syntax, actionlint, uploader ShellCheck, git diff --check, and added-line length checks passed.
  • pnpm lint passed workspace typechecks/Svelte checks with zero errors or warnings.
  • pnpm build:web && pnpm verify:site passed production Astro/VitePress builds and combined static-site verification.
  • git merge-tree --write-tree HEAD origin/ci/41-scope-workflows confirmed clean compatibility with pending Scope CI and deployment to affected files #42.

No live Bunny API call, credential change, or production deployment was performed. Production purge validation requires the operator-supplied settings above. Native app/audio tests were outside this deployment-only change.

Closes #43.

Enable a full Pull Zone purge in Deploy Docs only after every storage
upload and deployment-manifest write succeeds. Validate the separate
account key and zone ID before uploads, and preserve upload-only CLI use.
Guide operators through the new settings and document environment scope,
recovery, and browser-cache limits alongside regression coverage.

Constraint: Bunny's CDN management API requires an account API key distinct from the storage-zone password.
Rejected: Add a separate purge entrypoint | the existing uploader preserves ordering and current CI path coverage.
Confidence: high
Scope-risk: moderate
Directive: Keep purge after all upload/manifest writes; never pass the account key in curl arguments or logs.
Tested: Purge regressions, 14 setup cases, full script suite, docs/workflow contracts, syntax, actionlint, ShellCheck.
Tested: Real-curl loopback success, transient retry, redirect rejection, and hidden authentication errors.
Tested: Workspace lint/typechecks, production web builds, and combined static-site verification.
Not-tested: Live Bunny purge or a workflow run with operator-supplied new settings; no credentials were changed.
Related: #43
@dskvr
dskvr merged commit 741e7c5 into master Sep 5, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Purge Bunny CDN cache after successful docs deployment

1 participant