Skip to content

feat: serve www and docs from Cloudflare Workers - #364

Merged
simonvanlierde merged 3 commits into
mainfrom
feat/sites-on-workers
Sep 28, 2026
Merged

simonvanlierde merged 3 commits into
mainfrom
feat/sites-on-workers

Conversation

@simonvanlierde

Copy link
Copy Markdown
Contributor

The landing page and docs move off the deploy hosts onto Cloudflare Workers static assets, deployed from CI on every release and weekly, so they stay up independently of the host and the landing hero refreshes without a release. Stacked on #362.

  • infra/cloudflare binds their hostnames as Workers Custom Domains and writes the Worker names into the GitHub Environments
  • the security and cache headers move from the Caddyfiles into a generated _headers file, with the existing header tests ported to it
  • the www and docs images, Caddyfiles, compose services and smoke tests are removed; their Dockerfiles keep the dev target

Base automatically changed from feat/ghcr-deploy-images to main September 28, 2026 15:32
- deploy-sites.yml builds both sites and deploys them to Workers static assets on
  every release, weekly from the latest release, and by hand per environment
- infra/cloudflare binds their hostnames as Workers Custom Domains instead of
  tunnel routes, and writes the Worker names and account id into the GitHub
  Environments
- an Astro integration per site writes the `_headers` file that replaces the
  Caddyfile; the header tests move onto it
- drop the www and docs production images, Caddyfiles, compose services and
  smoke tests; their Dockerfiles keep only the dev target
… headers

- the staging Environment requires a reviewer, since its Workers token is
  account-wide and could deploy prod's Workers; infra/cloudflare refuses
  to apply staging without one
- deploy-sites serializes per Worker instead of per calling workflow, and
  the weekly run skips releases that predate the Workers deploy
- scripts/check_site_headers.sh serves the built site under wrangler dev
  before each deploy and checks its headers, 404 page and method handling
- the cutover runbook writes the Environment variables before Deploy Sites
  needs them; the install guide drops the removed tunnel targets and
  covers hosting the sites without Cloudflare
- images-verify checks only the images that are still published
- the dev stage is now the whole image, so it needs its own non-root USER;
  node owns the sources, the site directory and node_modules for Vite's cache
- start astro directly: `pnpm exec` re-verified the lockfile and installed
  the whole workspace on every container start
@simonvanlierde
simonvanlierde merged commit 2d906e6 into main Sep 28, 2026
23 checks passed
@simonvanlierde
simonvanlierde deleted the feat/sites-on-workers branch September 28, 2026 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant