Conversation
wrangler secret bulk edits the Worker's latest version and fails with Cloudflare error 10215 when that version is an undeployed 0% upload. Every single-topology PR and push-main flow leaves one behind, so the release deploy after it failed. Pass the collected file to the deploy as --secrets-file instead, which creates the version with the secrets (wrangler 4.74.0 or newer), and remove the file afterwards.
cloudflare-version.yml has no internal pins of its own, so the fix commit is already self-consistent. required-quality.yml and the .burnt-workflows refs stay at v1.7.0: no script changed.
2xburnt
marked this pull request as ready for review
September 28, 2026 22:26
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Worker secrets now go out with the deploy (
wrangler deploy --secrets-file) and no longer through a separatewrangler secret bulkstep before it.Why:
secret bulkedits the Worker's latest version. Cloudflare rejects that with[code: 10215] Secret edit failed … the latest version of your Worker isn't currently deployedwhenever the latest version is an undeployed 0% upload. Undersingletopology, the PR and push-main flows leave exactly that behind every time, so the next release deploy of any consumer that declaresworkerSecretsfails.standard/chainconsumers withpreviewReleaseOnMain: truehit the same thing on the release target.Reproduced 2026-09-28 on a throwaway Worker on the burnt account (since deleted), wrangler 4.120.1:
wrangler deploy(v1), thenwrangler versions upload(v2 at 0%), thenwrangler secret bulk s.json→ 10215.wrangler deploy --secrets-file s.jsoninstead → succeeds. A second deploy with a different file also succeeds, and the secrets accumulate (additive, aswrangler deploy --helpsays).First affected consumer: node-monitor#14 (
workerSecrets: [TELEGRAM_BOT_TOKEN, TELEGRAM_CHAT_ID]). Its PR preview is already the Worker's latest, undeployed version, so without this its first release deploy would fail closed.cloudflare-version.yml:Publish Worker secretsstep.Upload or deploy Worker versionappends--secrets-file $RUNNER_TEMP/worker-secrets.jsonwhenCollect Worker secretssucceeded. That step runs only ondeploywith a non-empty list, so previews never get the flag. The expression keeps thecond && value || ''shape.Remove Worker secrets filestep (always()) deletes the file.Collect Worker secretsis unchanged, so the trust split holds: jq has the secrets and no credential, and the SHA-pinned action has the credential and no consumer binary.tests/workflows.test.mjs: thesecret bulktest is replaced by one asserting there is no separate publish step, that the pinned deploy carries--secrets-filebehind the collect outcome, and thatsecret bulkappears nowhere in the workflow. It fails onmain.AGENTS.md"Worker secrets": updated the mechanism and the reason for skipping previews, added the 10215 rationale, and stated the wrangler floor.cloudflare-pr.yml,cloudflare-main.ymlandcloudflare-release.ymlpincloudflare-version.ymlat the fix commitbdb6a6cwith# v1.7.1.cloudflare-version.ymlhas no internal pins of its own, so the fix commit is self-consistent.required-quality.ymland the.burnt-workflowsrefs stay at v1.7.0 because no script changed.Wrangler floor:
--secrets-filefirst appears in wrangler 4.74.0 (deploy --helpon 4.73.0 has no such flag; 4.74.0 does). Consumers that declareworkerSecrets, checked against their lockfiles:workerSecrets: [], not affected, 4.120.1workerSecrets, 4.141.0The pinned
wrangler-actiondefaults to wrangler4(latest) when a consumer does not depend on wrangler itself.After merge, cut
v1.7.1. Its Upgrading notes must name the 4.74.0 floor.Floor exceptions (floor-guard
test-made-easier,tests/workflows.test.mjs):assert.match(publish.uses, …wrangler-action@<sha>…)removed: thePublish Worker secretsstep is gone. The same assertion now runs on the deploy step (deploy.uses), along with itsworkingDirectorycheck, and a new assertion requires the old step to be absent.assert.match(publish.command …, /secret bulk/)removed: inverted on purpose.secret bulkmust now appear nowhere incloudflare-version.yml.Checks:
pnpm run check(prettier,node --test87/87, actionlint).Part of DO-503