Conversation
Member
Author
|
Disclaimer: This works for a custom Astro build of the docs (https://clickhouse-docs.vercel.app/docs). It's not actually triggering a Mintlify deploy. The two sites are visually and functionally identical though so we can use this for now as a work around for Mintlify's short-comings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a reusable remote documentation preview workflow. A constrained
pull_request_targetcaller pins that pull request's exact head SHA and directly creates a Vercel deployment of trusted Nimbusmainin theconnect-previewCustom Environment.A maintainer can get a docs preview by adding the
docs-previewlabel - this is done both to save unnecessary preview builds and to ensure there's a gate on what code gets run. JS can run inside of MDX so there is a security concern there:I have taken care to separate out MDX processing from the part of the build process which fetches the docs content from remote sources. The label acts as gate keeping mainly for community PRs.
The Actions workflow never checks out or executes pull-request content and never passes a GitHub credential into Vercel. During the build, Vercel Connect exchanges the deployment OIDC identity for a short-lived
contents:readtoken scoped to the selected source repository. The workflow waits for completion, cancels superseded deployments, and posts a sticky preview link on the source pull request.Callers receive
VERCEL_TOKEN,VERCEL_ORG_ID, andVERCEL_PROJECT_IDthrough organization Actions secrets. A copy-paste caller and configuration documentation are included. Each caller can use the nativepathsfilter to select which changes are eligible, for exampledocs/**. A new PR commit requires a new label event, so approval remains bound to the SHA selected when the label was added.Changelog category (leave one):
Changelog entry (a user-readable short description of the changes that goes into CHANGELOG.md):
Not for changelog.
Registering a remote source
Before installing the caller, add an entry to
remotes.jsoninClickHouse/mintlify-docs-dev. Setnameto the value passed asremote_name,repoto the source repository,pathto its documentation directory, andmountto its destination relative to/docs. Addassetsmappings andprivate: truewhen required. Do not pin a branch in the registry: production reads the source's default branch, while an approved preview supplies the exact pull-request SHA.