← Files OpsTruthARCHIVED FILE

.github/workflows/deploy-cloudflare.yml

3.09 KB · Oct 2, 2026 · 00:31 UTC

↓ Download file

name: Deploy MCP to Cloudflare

on:
  workflow_dispatch:
  push:
    branches: [main]
    paths:
      - "src/**"
      - "scripts/generate-signing-key.mjs"
      - "wrangler.jsonc"
      - "package.json"
      - "evals/**"
      - ".github/workflows/deploy-cloudflare.yml"

permissions:
  contents: read

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
      - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
        with:
          node-version: 24
      - run: npm run check
      - name: Require Cloudflare deployment secrets
        env: &cloudflare-credentials
          CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
          CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
        run: |
          test -n "$CLOUDFLARE_API_TOKEN"
          test -n "$CLOUDFLARE_ACCOUNT_ID"
      - name: Require verifier GitHub App Worker secrets
        shell: bash
        env: *cloudflare-credentials
        run: |
          set -euo pipefail
          secret_list="$RUNNER_TEMP/opstruth-github-app-secret-list.json"
          trap 'rm -f "$secret_list"' EXIT
          npx --yes wrangler@4.127.0 secret list > "$secret_list"
          for required in OPSTRUTH_GITHUB_APP_ID OPSTRUTH_GITHUB_APP_INSTALLATION_ID OPSTRUTH_GITHUB_APP_PRIVATE_KEY_PEM; do
            if ! grep -Eq "\"name\"[[:space:]]*:[[:space:]]*\"$required\"" "$secret_list"; then
              echo "::error::Required verifier GitHub App Worker secret is not configured: $required"
              exit 1
            fi
          done
      - name: Deploy bootstrap Worker with commit identity
        env: *cloudflare-credentials
        run: npx --yes wrangler@4.127.0 deploy --var OPSTRUTH_BUILD_COMMIT:${GITHUB_SHA}
      - name: Provision stable evidence-signing key once
        shell: bash
        env: *cloudflare-credentials
        run: |
          set -euo pipefail
          secret_list="$RUNNER_TEMP/opstruth-secret-list.json"
          npx --yes wrangler@4.127.0 secret list > "$secret_list"
          if grep -q 'OPSTRUTH_RECEIPT_PRIVATE_KEY_PKCS8' "$secret_list" && grep -q 'OPSTRUTH_RECEIPT_PUBLIC_KEY_SPKI' "$secret_list"; then
            exit 0
          fi
          private_key="$RUNNER_TEMP/opstruth-private.pem"
          public_key="$RUNNER_TEMP/opstruth-public.pem"
          node scripts/generate-signing-key.mjs "$private_key" "$public_key"
          npx --yes wrangler@4.127.0 secret put OPSTRUTH_RECEIPT_PRIVATE_KEY_PKCS8 < "$private_key"
          npx --yes wrangler@4.127.0 secret put OPSTRUTH_RECEIPT_PUBLIC_KEY_SPKI < "$public_key"
          rm -f "$private_key" "$public_key" "$secret_list"
      - name: Deploy final Worker with stable commit identity
        env: *cloudflare-credentials
        run: npx --yes wrangler@4.127.0 deploy --var OPSTRUTH_BUILD_COMMIT:${GITHUB_SHA}
      - name: Smoke test production routes
        env:
          OPSTRUTH_EXPECTED_VERSION: 0.4.1
          OPSTRUTH_EXPECTED_COMMIT: ${{ github.sha }}
          OPSTRUTH_PRODUCTION_URL: https://mcp.opstruth.io
        run: npm run smoke:production

SHA-256: f5242076f54705539e067f448eec7705407a29e22a489da04428d8adba4ac0b3