Skip to content

WI-062: Put the site on a URL

WI-062: Put the site on a URL

WI-061 builds and serves locally. This puts it on the internet.

Direct upload with wrangler, matching WI-022 and the docs deploy: the dashboard’s Git integration needs an OAuth grant an agent cannot make, and it puts the deploy configuration outside version control.

There is no hand-written wrangler config. @astrojs/cloudflare generates dist/server/wrangler.json at build time, so there is nothing to drift.

The smoke test is the point

wrangler deploy proves an upload succeeded and nothing else. WI-061 shipped a build that succeeded and 500’d on every request, so the workflow checks the site does what it exists to do:

  • the home page returns 200
  • a game page returns 200 — a home page that renders while every game page fails is exactly what happened locally
  • <h1>Catan</h1> is in the HTML, because a client-rendered shell forfeits the only reason this app exists (ADR-0009)
  • the structured data is there
  • a missing game is a 404, not a 200 with an empty page

Definition of done

  • The site deploys from main on a change under apps/web.
  • The smoke test fails the workflow if a game page does not render server-side.
  • A missing game 404s.
  • The URL is recorded on the status page.
  • No Cloudflare resource is provisioned for something nothing uses.

Verification

Terminal window
gh workflow run "Deploy web"
curl -sS https://<url>/games/catan | grep '<h1>'

The SESSION binding, answered by deploying

It provisions. The first deploy uploaded cleanly and then failed:

A request to the Cloudflare API (/accounts/***/storage/kv/namespaces) failed.
Authentication error [code: 10000]

wrangler tries to create the namespace, and the deploy token has no Workers KV permission.

Two ways out: widen the token so it can provision a namespace nothing reads, or stop asking for a resource nothing uses. scripts/strip-session-binding.mjs runs after the build and removes the binding from the generated config — smaller change, smaller blast radius, and no new permission on a token that deploys the API too.

It refuses to strip if the site actually uses a session, in which case the binding is load-bearing and the right fix is the token. Verified: with the binding gone, the home page, a game page and a 404 all behave exactly as before.