Skip to content

Commit 7a2b39b

Browse files
committed
Disable public Worker preview URLs
1 parent 8882061 commit 7a2b39b

6 files changed

Lines changed: 9 additions & 80 deletions

File tree

‎.github/workflows/preview.yml‎

Lines changed: 0 additions & 72 deletions
This file was deleted.

‎CONTRIBUTING.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,7 @@ The single source of truth for the registries is `docs/quality-registries.toml`.
9797

9898
## Secrets and deploy configuration
9999

100-
Deployment uses repository secrets: `CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID` (Preview workflow), plus optional `PBE_SMOKE_BYPASS_SECRET` so deploy smoke tests can run edited-code POSTs past the Turnstile challenge. Runtime Worker secrets (`TURNSTILE_SECRET_KEY`, `TURNSTILE_CLEARANCE_SECRET`, `PBE_SMOKE_BYPASS_SECRET`) are managed with `wrangler secret put`; see `docs/turnstile-runner-protection-spec.md`.
100+
Production deployment is manual through an authenticated Wrangler session with `make deploy`; public `workers.dev` and version preview URLs are disabled. Runtime Worker secrets (`TURNSTILE_SECRET_KEY`, `TURNSTILE_CLEARANCE_SECRET`, `PBE_SMOKE_BYPASS_SECRET`) are managed with `wrangler secret put`; see `docs/turnstile-runner-protection-spec.md`.
101101

102102
Generated output is prevented from drifting before merge: install the local hooks with `scripts/install-git-hooks.sh`, and keep `main` protected so pull requests require the `verify` status check to pass against the current base. CI enforces the same `make check-generated` contract for contributors without local hooks.
103103

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -228,7 +228,7 @@ Use the active Cloudflare-supported Python version.
228228

229229
## Cloudflare notes
230230

231-
- `wrangler.jsonc` enables `python_workers` and `python_dedicated_snapshot`.
231+
- `wrangler.jsonc` enables `python_workers` and `python_dedicated_snapshot` while disabling both public `workers.dev` and version preview URLs.
232232
- The parent Worker uses a `LOADER` Worker Loader binding.
233233
- Dynamic Worker IDs include Python version, example slug, and submitted code hash.
234234
- Dynamic Workers run with `globalOutbound: null` and tight CPU/subrequest limits.

‎docs/turnstile-runner-protection-spec.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -404,8 +404,8 @@ this rule, record its zone, rule ID, plan, expression, characteristics,
404404
threshold/period, mitigation/action, deployment date, and a controlled 429
405405
Security Events result in the release record. `wrangler.jsonc` deploys the
406406
Worker only; it cannot declare or verify zone WAF rate-limiting rules. The
407-
production configuration disables `workers.dev` so the custom-domain WAF rule
408-
is not bypassed by a public fallback hostname.
407+
production configuration disables `workers.dev` and version preview URLs so the
408+
custom-domain WAF rule is not bypassed by a public fallback hostname.
409409

410410
Cloudflare Dashboard:
411411

‎tests/test_app.py‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -432,9 +432,10 @@ def test_generated_drift_is_blocked_before_commit_and_merge(self):
432432
self.assertIn("make verify", verify_workflow)
433433
self.assertIn("uv sync --locked --all-groups", verify_workflow)
434434
self.assertIn("npm ci --ignore-scripts", verify_workflow)
435-
preview_workflow = (ROOT / ".github" / "workflows" / "preview.yml").read_text()
436-
self.assertIn("uv sync --locked --all-groups", preview_workflow)
437-
self.assertIn("npm exec -- wrangler whoami", preview_workflow)
435+
self.assertFalse((ROOT / ".github" / "workflows" / "preview.yml").exists())
436+
wrangler_config = (ROOT / "wrangler.jsonc").read_text()
437+
self.assertIn('"workers_dev": false', wrangler_config)
438+
self.assertIn('"preview_urls": false', wrangler_config)
438439
package = json.loads((ROOT / "package.json").read_text())
439440
lock = json.loads((ROOT / "package-lock.json").read_text())
440441
self.assertEqual(package["devDependencies"]["wrangler"], "4.110.0")

‎wrangler.jsonc‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
"python_dedicated_snapshot"
99
],
1010
"workers_dev": false,
11-
"preview_urls": true,
11+
"preview_urls": false,
1212
"routes": [
1313
{
1414
"pattern": "www.pythonbyexample.dev",

0 commit comments

Comments
 (0)