Skip to content

feat(repo): deploy the site from one command - #50

Merged
systemfsoftware-maker merged 20 commits into
lake1/nix-sandboxfrom
lake1/deploy
Oct 7, 2026
Merged

systemfsoftware-maker merged 20 commits into
lake1/nix-sandboxfrom
lake1/deploy

Conversation

@systemfsoftware-maker

@systemfsoftware-maker systemfsoftware-maker commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Lake 1, U12, stacked on #52. Trimmed per Kiro's 2026-10-06 ruling: no deployed-trace journey, no hard-coded domain.

  • pnpm run deploy deploys the Worker with Alchemy to the adopter's own Cloudflare account; the stage is ALCHEMY_STAGE (default prod). pnpm run destroy refuses to run without an explicit stage. Bare pnpm deploy is pnpm's built-in command, so the README says pnpm run deploy.
  • bin/cloud runs both inside the sandbox, the one place the Cloudflare credentials enter it, allowed to reach only api.cloudflare.com and *.workers.dev (alchemy's state store), with telemetry off.
  • alchemy.run.ts: prod and pr-<N> keep state in Cloudflare.state(); every other stage, pnpm dev included, keeps Alchemy.localState() and needs no credentials. A production domain is adopter configuration: SITE_DOMAIN, read on the prod stage only. The stack outputs url and workerName.
  • README "Deploy" section; AGENTS.md: the template holds no credentials, and a job that needs one carries if: ${{ !github.event.repository.is_template }}.

Removed by the trim: the deployed-trace journey and its Workers Observability fixture, @distilled.cloud/cloudflare, the cf-ray field, and endgame.systemfsoftware.com.

Gate at 4747829

$ pnpm check:ci
checkci=1        # only check:sfs-sources, inherited from #52; format, 8/8 turbo tasks, build and the sandbox proofs pass
$ pnpm journeys
journeys=0

Not exercised here: a real deploy. The template has no credentials by design; the first one runs in an adopter's copy.

@systemfsoftware-maker
systemfsoftware-maker added this pull request to stack #34 October 6, 2026 06:35
@systemfsoftware-maker
systemfsoftware-maker force-pushed the lake1/deploy branch 2 times, most recently from d6b2448 to 37d80bd Compare October 6, 2026 07:09
systemfsoftware-maker added a commit that referenced this pull request Oct 6, 2026
…and QA evidence

Findings for #43, #45, #49, #50 and #51 from ce-code-review (8 lenses, validator), the verifier's probes of every P0/P1 including those the merge dropped, and the real-browser, local-Tempo and live-preview QA. Nothing applied; each finding waits for a ruling
@systemfsoftware-maker
systemfsoftware-maker force-pushed the lake1/csp branch 2 times, most recently from 7ac68a4 to a8a92e1 Compare October 6, 2026 12:17
@systemfsoftware-maker
systemfsoftware-maker force-pushed the lake1/deploy branch 2 times, most recently from b6d0f68 to a10eba6 Compare October 6, 2026 16:00
@systemfsoftware-maker
systemfsoftware-maker removed this pull request from stack #34 October 6, 2026 16:04
@systemfsoftware-maker
systemfsoftware-maker changed the base branch from lake1/csp to lake1/nix-sandbox October 6, 2026 16:04
@systemfsoftware-maker
systemfsoftware-maker force-pushed the lake1/deploy branch 2 times, most recently from c62f54b to d96b565 Compare October 6, 2026 17:28
@systemfsoftware-maker
systemfsoftware-maker added this pull request to stack #54 October 6, 2026 19:52
@systemfsoftware-maker
systemfsoftware-maker removed this pull request from stack #54 October 6, 2026 21:56
@systemfsoftware-maker
systemfsoftware-maker added this pull request to stack #59 October 6, 2026 21:57
@systemfsoftware-maker
systemfsoftware-maker removed this pull request from stack #59 October 6, 2026 22:13
@systemfsoftware-maker
systemfsoftware-maker added this pull request to stack #61 October 6, 2026 22:13
pnpm run deploy deploys the Worker with Alchemy to the adopter's own Cloudflare account through bin/cloud, the one place Cloudflare credentials enter the sandbox; cloud stages keep their state in Cloudflare. A production domain is adopter configuration: SITE_DOMAIN, read by alchemy.run.ts on the prod stage. The template holds no credentials
@kiro-systemf
kiro-systemf Bot removed this pull request from stack #61 October 7, 2026 15:41
@systemfsoftware-maker
systemfsoftware-maker merged commit 7857171 into lake1/nix-sandbox Oct 7, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant