You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
github-attach screenshot.png --alt "Settings after the change"
21
23
```
22
24
23
-
The token file contains only the raw token, with no variable name or quotes.
25
+
The `token` file contains only the raw upload token. The `url` file contains the Worker origin, such as `https://github-pr-attachments.example.workers.dev`. Neither file uses variable names or quotes. `npm run setup` creates both files automatically.
The repository `.env` must remain uncommitted. This repository ignores `.env` and `.env.*` by default; copy the same rules into repositories that do not already ignore them. Use `.env.example` for placeholder documentation only—never put a real token in it.
42
44
43
-
`GITHUB_ATTACHMENTS_URL` can be set only in the process environment and otherwise defaults to `https://github-pr-attachments.none23.workers.dev`. Repository `.env` cannot redirect a user-level token to another service. The user token file is not parsed as shell code, and repository `.env` files are read as data rather than sourced.
45
+
The service URL resolves separately:
46
+
47
+
| Priority | Location | Scope |
48
+
| ---: | --- | --- |
49
+
| 1 |`GITHUB_ATTACHMENTS_URL` in the process environment | Current process override |
Repository `.env` cannot redirect a user-level token to another service. User profile files and repository `.env` are parsed as data, never sourced as shell code.
44
54
45
55
The CLI prints only Markdown by default:
46
56
@@ -104,31 +114,63 @@ npm run dev
104
114
105
115
`npm run check` runs Biome, generated binding drift checks, strict TypeScript checks, Workers-runtime integration tests, and the CLI integration test.
106
116
107
-
## Initial deployment
117
+
## Deploy your own service
108
118
109
-
Authenticate Wrangler first:
119
+
Each deployment has one Worker, one upload token, and one statically bound R2 bucket. Upload requests cannot choose or override the bucket.
120
+
121
+
Install dependencies, then create a least-privilege Cloudflare API token with these account permissions:
122
+
123
+
- Workers Scripts: Edit
124
+
- Workers R2 Storage: Edit
125
+
- Account Settings: Read
126
+
127
+
Limit it to the target account. A short expiration and client-IP restriction further reduce its blast radius when appropriate. Save it outside Git:
Generate a random token, save it somewhere private, and set the Worker secret through Wrangler's interactive prompt:
154
+
To reuse an existing private bucket, omit `--create-bucket`:
125
155
126
156
```bash
127
-
npx wrangler secret put UPLOAD_TOKEN
128
-
npm run deploy
157
+
npm run setup -- \
158
+
--worker github-pr-attachments-yourname \
159
+
--bucket your-existing-private-bucket \
160
+
--prefix github-pr-attachments-yourname/objects/
129
161
```
130
162
131
-
Never commit `.dev.vars`, bearer tokens, or generated credential files.
163
+
The setup command:
164
+
165
+
1. Verifies or creates the named bucket.
166
+
2. Adds a prefix-scoped R2 lifecycle rule.
167
+
3. Generates `wrangler.user.jsonc` with the selected Worker, bucket, prefix, and retention.
168
+
4. Generates a 256-bit upload token and deploys it as a Worker secret.
169
+
5. waits for `/healthz`, then writes the user-level `url` and `token` profile.
170
+
171
+
The default prefix is `<worker-name>/objects/`; the default retention is 180 days. Use `--prefix` and `--retention-days` to change them. Prefixes let multiple deployments safely share one bucket, provided every deployment uses a distinct prefix. `wrangler.user.jsonc`, `.env*`, `.dev.vars`, and `.github-attachments/` are ignored by Git.
172
+
173
+
The Cloudflare API token is needed only for provisioning and later redeployment. Remove or revoke it after setup if the machine should retain upload access but not deployment access. The user-level `token` is deliberately separate: it can upload through this service but cannot administer Cloudflare.
0 commit comments