Skip to content

fix: make Cloudflare binding config portable - #2

Merged
petergstfsn merged 3 commits into
mainfrom
codex/d1-native-storage
Sep 20, 2026
Merged

petergstfsn merged 3 commits into
mainfrom
codex/d1-native-storage

Conversation

@petergstfsn

Copy link
Copy Markdown

Summary

  • remove the placeholder D1 UUID so Wrangler can provision or inherit the named codra-db binding for the connected Cloudflare account
  • remove stale account-specific APP_KV IDs so Workers Builds can provision or inherit that binding

Build failure

PR #1's build command succeeded, but its preview upload initially failed because the root-level Workers Builds command could not discover apps/worker/wrangler.jsonc. The Workers Builds version command is now configured as:

npx wrangler versions upload --config apps/worker/wrangler.jsonc

That exposed the stale KV namespace ID, which this PR fixes.

Validation

  • npm run build
  • npm run typecheck
  • npx wrangler versions upload --dry-run --config apps/worker/wrangler.jsonc
  • git diff --check

No Worker deployment or remote D1 migration was run.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
codra 74e3ddd Sep 20 2026, 06:14 PM

@petergstfsn

Copy link
Copy Markdown
Author

Hosted Workers Build reached the corrected config and successfully provisioned/inherited the portable bindings. It then stopped before version creation on the intentional secrets.required guard because these runtime secrets are absent in the connected Cloudflare account: APP_PRIVATE_KEY, CF_ACCOUNT_ID, CF_API_TOKEN, GITHUB_APP_ID, GITHUB_APP_WEBHOOK_SECRET, GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET, and LLM_CONFIG_ENCRYPTION_KEY.

Build: https://dash.cloudflare.com/747b74cbd7d019dd7aeecb2c24a4bf10/workers/services/view/codra/production/builds/42435217-c8d4-4a78-9026-6d354603c758

No Worker version was deployed and no remote D1 migration was run. The required-secret guard has intentionally not been weakened.

@petergstfsn

Copy link
Copy Markdown
Author

Final build-fix update (head 74e3ddd):

  • Original PR feat: replace Hyperdrive Postgres with Cloudflare D1 #1 Workers build failure: Missing entry-point to Worker script or to assets directory. The Workers Builds Version command was running from the repository root; it now uses npx wrangler versions upload --config apps/worker/wrangler.jsonc.
  • After automatic resource provisioning, the next exact failure was a namespace with this account ID and title already exists [code: 10014] for codra-app-kv. This PR now pins the provisioned KV namespace ID and D1 database ID, avoiding an attempted duplicate.
  • Required secrets were reduced to the six bindings actually required at startup; optional Cloudflare API credentials remain optional.
  • Local verification passed: npm run build, npm run typecheck, npx wrangler versions upload --dry-run --config apps/worker/wrangler.jsonc, and git diff --check.
  • Hosted Cloudflare Workers build passed for this exact head: https://dash.cloudflare.com/747b74cbd7d019dd7aeecb2c24a4bf10/workers/services/view/codra/production/builds/ea045165-6d51-4c57-ab90-db6f509db186

No Worker version was deployed and no remote D1 migrations were run.

@petergstfsn
petergstfsn merged commit bf13f7b into main Sep 20, 2026
5 of 6 checks passed
@petergstfsn

Copy link
Copy Markdown
Author

Deploy-stage follow-up:

The pasted Cloudflare run completed npm run build successfully, then failed because the configured deploy command was still npx wrangler deploy from the monorepo root. Wrangler reported: The Cloudflare application detection logic has been run in the root of a workspace instead of targeting a specific project.

Cloudflare Workers Builds is now configured with:

npx wrangler deploy --config apps/worker/wrangler.jsonc

Validated locally with the matching non-mutating command:

npx wrangler deploy --dry-run --config apps/worker/wrangler.jsonc

The dry-run resolved the pinned KV, D1, Queue, Workflow, AI, and Assets bindings and exited successfully. npm run build, npm run typecheck, and git diff --check also pass. No deployment was retried and no remote D1 migrations were run.

@petergstfsn

Copy link
Copy Markdown
Author

Final production-state check after the failed automatic deploy:

  • The Cloudflare Workers Builds deploy command is saved as npx wrangler deploy --config apps/worker/wrangler.jsonc.
  • Merged origin/main is bf13f7b0c5403ce90c7c613465fa0f20a79748a7 and contains the pinned D1/KV configuration.
  • A read-only Wrangler check confirms the failed run did not replace the active deployment; the merged D1 change is not active yet.
  • The matching deploy command passes locally with --dry-run.

I did not retry production deployment or run remote D1 migrations, preserving the explicit task boundary.

@petergstfsn

Copy link
Copy Markdown
Author

Production deployment completed after explicit authorization:

No remote D1 migrations were run.

@petergstfsn

Copy link
Copy Markdown
Author

Production follow-up completed.

  • Exact failed Workers build error from the supplied log: The Cloudflare application detection logic has been run in the root of a workspace instead of targeting a specific project. The build then ended with Failed: error occurred while running deploy command.
  • The merged PR fixed the workspace-targeting/config portability issue; Cloudflare Workers Builds now succeeds.
  • Production D1 migration 0001_initial.sql was applied once. There are no pending migrations, the expected schema exists, and PRAGMA foreign_key_check returned no rows.
  • The dashboard recovered from HTTP 500 and loads production data normally.
  • Cloudflare Access and the existing managed-challenge rule now exempt only codra.esau.app/webhook; an invalid GitHub-shaped request reaches the Worker and is rejected by application signature validation.
  • Created the replacement private org-owned GitHub App codra-esau-org (App ID 5012954), installed only on esaueng/codra, and updated the Worker App ID, private key, and webhook secret.
  • GitHub webhook redelivery now returns HTTP 202, and Codra repository sync lists esaueng/codra as enabled.
  • Final Worker deployment is version 9765e248-a23c-4624-a895-3705ef75d36e at 100% traffic.
  • Follow-up config PR fix: align Worker with org GitHub App #3 records the replacement app slug/bot identity in source: fix: align Worker with org GitHub App #3

No additional D1 migrations were run after the initial authorized migration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant