Skip to content

Publish Worker secrets with the deploy (--secrets-file), fixing 10215 on release deploys - #48

Open
2xburnt wants to merge 3 commits into
mainfrom
work/burntbot/secrets-file-deploy-20260928T221849Z
Open

2xburnt wants to merge 3 commits into
mainfrom
work/burntbot/secrets-file-deploy-20260928T221849Z

Conversation

@2xburnt

@2xburnt 2xburnt commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Worker secrets now go out with the deploy (wrangler deploy --secrets-file) and no longer through a separate wrangler secret bulk step before it.

Why: secret bulk edits the Worker's latest version. Cloudflare rejects that with [code: 10215] Secret edit failed … the latest version of your Worker isn't currently deployed whenever the latest version is an undeployed 0% upload. Under single topology, the PR and push-main flows leave exactly that behind every time, so the next release deploy of any consumer that declares workerSecrets fails. standard/chain consumers with previewReleaseOnMain: true hit the same thing on the release target.

Reproduced 2026-09-28 on a throwaway Worker on the burnt account (since deleted), wrangler 4.120.1:

  • wrangler deploy (v1), then wrangler versions upload (v2 at 0%), then wrangler secret bulk s.json → 10215.
  • Same state, but wrangler deploy --secrets-file s.json instead → succeeds. A second deploy with a different file also succeeds, and the secrets accumulate (additive, as wrangler deploy --help says).

First affected consumer: node-monitor#14 (workerSecrets: [TELEGRAM_BOT_TOKEN, TELEGRAM_CHAT_ID]). Its PR preview is already the Worker's latest, undeployed version, so without this its first release deploy would fail closed.

  • cloudflare-version.yml:
    • Removed the Publish Worker secrets step.
    • Upload or deploy Worker version appends --secrets-file $RUNNER_TEMP/worker-secrets.json when Collect Worker secrets succeeded. That step runs only on deploy with a non-empty list, so previews never get the flag. The expression keeps the cond && value || '' shape.
    • A new Remove Worker secrets file step (always()) deletes the file.
    • Collect Worker secrets is unchanged, so the trust split holds: jq has the secrets and no credential, and the SHA-pinned action has the credential and no consumer binary.
  • tests/workflows.test.mjs: the secret bulk test is replaced by one asserting there is no separate publish step, that the pinned deploy carries --secrets-file behind the collect outcome, and that secret bulk appears nowhere in the workflow. It fails on main.
  • AGENTS.md "Worker secrets": updated the mechanism and the reason for skipping previews, added the 10215 rationale, and stated the wrangler floor.
  • Pins: cloudflare-pr.yml, cloudflare-main.yml and cloudflare-release.yml pin cloudflare-version.yml at the fix commit bdb6a6c with # v1.7.1. cloudflare-version.yml has no internal pins of its own, so the fix commit is self-consistent. required-quality.yml and the .burnt-workflows refs stay at v1.7.0 because no script changed.

Wrangler floor: --secrets-file first appears in wrangler 4.74.0 (deploy --help on 4.73.0 has no such flag; 4.74.0 does). Consumers that declare workerSecrets, checked against their lockfiles:

The pinned wrangler-action defaults to wrangler 4 (latest) when a consumer does not depend on wrangler itself.

After merge, cut v1.7.1. Its Upgrading notes must name the 4.74.0 floor.

Floor exceptions (floor-guard test-made-easier, tests/workflows.test.mjs):

  • assert.match(publish.uses, …wrangler-action@<sha>…) removed: the Publish Worker secrets step is gone. The same assertion now runs on the deploy step (deploy.uses), along with its workingDirectory check, and a new assertion requires the old step to be absent.
  • assert.match(publish.command …, /secret bulk/) removed: inverted on purpose. secret bulk must now appear nowhere in cloudflare-version.yml.

Checks: pnpm run check (prettier, node --test 87/87, actionlint).

Part of DO-503

wrangler secret bulk edits the Worker's latest version and fails with
Cloudflare error 10215 when that version is an undeployed 0% upload.
Every single-topology PR and push-main flow leaves one behind, so the
release deploy after it failed. Pass the collected file to the deploy
as --secrets-file instead, which creates the version with the secrets
(wrangler 4.74.0 or newer), and remove the file afterwards.
cloudflare-version.yml has no internal pins of its own, so the fix
commit is already self-consistent. required-quality.yml and the
.burnt-workflows refs stay at v1.7.0: no script changed.
Copilot AI balanced review requested due to automatic review settings September 28, 2026 22:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Copilot AI review requested due to automatic review settings September 28, 2026 22:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@2xburnt
2xburnt marked this pull request as ready for review September 28, 2026 22:26
@2xburnt
2xburnt requested a review from a team September 28, 2026 22:26
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T22:29:22.430083Z 051ebc9 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants