You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit ce16330
Browse filesBrowse the repository at this point in the historyBrowse files
Run previews in a separate reviewer-gated environment
Point preview.yml at a new `preview` environment and document that all
deploy credentials live as environment secrets in `production` (main-only)
and `preview` (required reviewers), with nothing at repository level.
Repository secrets resolve for any workflow on any branch, so write access
alone was enough to read the org-owner token by pushing a workflow file.
Copy file name to clipboardExpand all lines: README.md
+22-5Lines changed: 22 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -73,7 +73,7 @@ The PR's `pulumi preview` comment shows the repository create. Once merged, the
73
73
### One-time setup
74
74
75
75
1. In the Cloudflare dashboard for the **MCP Domain Account**, create a token dedicated to Access policy role management. Give it a descriptive name so it does not read as a generic API token, e.g. `mcp-access: Access policy role management`, and scope it to only **Account → Access: Apps and Policies → Edit** on the MCP Domain Account. Do not reuse this token for anything else.
76
-
2. Add it as the GitHub Actions secret `CLOUDFLARE_ROLE_MANAGEMENT_TOKEN` in the `production`environment (repository settings → Environments → production). The deploy workflow passes it to Pulumi as `cloudflare:roleManagementToken`. Until the secret exists, the Cloudflare module logs "Cloudflare integration disabled: roleManagementToken not configured" and creates nothing, so previews stay green.
76
+
2. Add it as the GitHub Actions secret `CLOUDFLARE_ROLE_MANAGEMENT_TOKEN` in both the `production`and `preview` environments (repository settings → Environments; see [Required GitHub Secrets](#required-github-secrets-for-cicd)). The deploy workflow passes it to Pulumi as `cloudflare:roleManagementToken`. Until the secret exists, the Cloudflare module logs "Cloudflare integration disabled: roleManagementToken not configured" and creates nothing, so previews stay green.
77
77
3. The account ID and GitHub identity-provider ID are non-secret and live in [`Pulumi.prod.yaml`](Pulumi.prod.yaml).
78
78
4.**Adopting the existing policy.** Pulumi's `import` resource option only succeeds when the program's inputs match the live resource, so adoption is two deploys:
79
79
- With `cloudflare:importExistingPolicies: "true"` in `Pulumi.prod.yaml`, the first deploy imports the existing `Maintainers` policy (by its `cloudflarePolicyId`) as-is, ignoring its rule lists.
@@ -131,7 +131,14 @@ Pre-requisites:
131
131
132
132
### Required GitHub Secrets (for CI/CD)
133
133
134
-
The following secrets must be configured in GitHub Actions for automated deployments:
134
+
Deploy credentials are **environment secrets**, not repository secrets. A repository-level Actions secret resolves for any workflow on any branch, so anyone with write access to this repository could read one by pushing a workflow file. Environment secrets resolve only for jobs that declare the environment, and each environment controls which refs may use it:
|`production`|[`deploy.yml`](.github/workflows/deploy.yml) on `main`| Deployment branches: `main` only. No reviewers, so merges deploy without a manual step. |
139
+
|`preview`|[`preview.yml`](.github/workflows/preview.yml) on PRs | Any branch. Required reviewers: `core-maintainers` (self-review allowed), so each preview run waits for one approval under **Review deployments**. |
140
+
141
+
Both environments hold the same set of secrets. Keep no copy at repository level (repository settings → Secrets and variables → Actions should list only `NPM_READ_TOKEN`, a read-only npm token used by the package drift check).
135
142
136
143
-**`GCP_PROD_SERVICE_ACCOUNT_KEY`**: GCP service account key
137
144
- Used to authenticate with Google Cloud Storage for Pulumi state (`gs://mcp-access-prod-pulumi-state`)
@@ -142,9 +149,17 @@ The following secrets must be configured in GitHub Actions for automated deploym
142
149
- Used to decrypt encrypted values in Pulumi stack configuration
143
150
- Keep this secure - if lost, you cannot decrypt your Pulumi state
144
151
145
-
-**`CLOUDFLARE_ROLE_MANAGEMENT_TOKEN`** (optional, `production` environment): Cloudflare token dedicated to Access policy role management, scoped only to **Account → Access: Apps and Policies → Edit** on the MCP Domain Account (not a general-purpose API token)
152
+
-**`PULUMI_GITHUB_TOKEN`**: GitHub token with organization owner rights, exported as `GITHUB_TOKEN` for the Pulumi GitHub provider (teams, memberships, repositories, org settings). The most sensitive credential here.
153
+
154
+
-**`DISCORD_BOT_TOKEN`** and **`DISCORD_GUILD_ID`**: Discord bot credentials for role sync ([`src/discord.ts`](src/discord.ts)). Optional; the Discord module is skipped when either is unset.
155
+
156
+
-**`ORG_BILLING_EMAIL`**: billing contact applied to the GitHub organization settings (`githubBillingEmail`, required by `src/github.ts`).
157
+
158
+
-**`CLOUDFLARE_ROLE_MANAGEMENT_TOKEN`** (optional): Cloudflare token dedicated to Access policy role management, scoped only to **Account → Access: Apps and Policies → Edit** on the MCP Domain Account (not a general-purpose API token)
146
159
- Used to manage the Cloudflare Access policy for `securityroom.modelcontextprotocol.io` (see [Cloudflare Access (security-room)](#cloudflare-access-security-room))
147
160
161
+
Rotating a secret means updating it in both environments.
162
+
148
163
## Initial Setup
149
164
150
165
If setting up this infrastructure for the first time:
pulumi config set --secret github:token "ghp_your_github_token_here"
202
217
```
203
218
204
-
### 3. Configure GitHub Actions Secrets
219
+
### 3. Configure GitHub Actions Environments and Secrets
205
220
206
-
Add the CI/CD secrets to GitHub Actions (repository settings → Secrets and variables → Actions):
221
+
Create the `production` and `preview` environments as described in [Required GitHub Secrets](#required-github-secrets-for-cicd) (repository settings → Environments), then add the secrets to **both**:
207
222
208
223
-`GCP_PROD_SERVICE_ACCOUNT_KEY`: Content of `sa-key.json`
209
224
-`PULUMI_PROD_PASSPHRASE`: The passphrase you set above
225
+
-`PULUMI_GITHUB_TOKEN`: A GitHub token with organization owner rights
226
+
-`ORG_BILLING_EMAIL`: The organization billing contact
0 commit comments