From f9fb6f2c565a1ab2e8daaa74c842f1085aa89331 Mon Sep 17 00:00:00 2001 From: Ashish Jullia Date: Fri, 25 Sep 2026 16:05:58 -0400 Subject: [PATCH] Open the shell when a Cloudflare account token cannot list memberships. wrangler whoami always calls that API, so startup no longer uses it. Wrangler commands use CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID from the Portunus project. --- Readme.md | 4 ++-- script.sh | 12 ++++++++---- 2 files changed, 10 insertions(+), 6 deletions(-) diff --git a/Readme.md b/Readme.md index c7cad22..cfa6660 100644 --- a/Readme.md +++ b/Readme.md @@ -67,6 +67,6 @@ mfa 123456 ## Cloudflare CLI -Wrangler is installed in the image. `dev /` authenticates it when that Portunus project sets `CLOUDFLARE_API_TOKEN`. Wrangler reads that variable itself. An optional `CLOUDFLARE_ACCOUNT_ID` on the same project is passed through the same way. +Wrangler is installed in the image. `dev /` leaves `CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID` in the environment when that Portunus project sets them. Wrangler reads both itself. -Startup runs `wrangler whoami`. A token that Cloudflare rejects stops the container. A project without `CLOUDFLARE_API_TOKEN` still opens a shell, and Wrangler commands in that shell are not authenticated. `dev` with no project does not load Portunus, so it does not authenticate Wrangler either. +Startup does not call `wrangler whoami`. That command lists account memberships, and an account API token cannot do that even when `CLOUDFLARE_ACCOUNT_ID` is set. A bad token fails the Wrangler command you run. A project without `CLOUDFLARE_API_TOKEN` still opens a shell, and Wrangler commands in that shell are not authenticated. `dev` with no project does not load Portunus, so it does not authenticate Wrangler either. diff --git a/script.sh b/script.sh index 623e248..6fcea9c 100644 --- a/script.sh +++ b/script.sh @@ -129,11 +129,15 @@ EOF echo "GH_CLI_TOKEN is not set. Skipping GitHub CLI authentication." fi - # Wrangler reads CLOUDFLARE_API_TOKEN from the environment. Portunus exports it - # when this project defines it. Run whoami outside /work so it cannot write into the mounted project. + # Wrangler reads these from the environment. whoami always lists memberships, which + # an account API token cannot do, so startup does not call it. if [ -n "${CLOUDFLARE_API_TOKEN:-}" ]; then - echo "Authenticating Cloudflare CLI..." - ( cd /tmp && CI=true WRANGLER_SEND_METRICS=false wrangler whoami ) || error_exit "Failed to authenticate the Cloudflare CLI. Check CLOUDFLARE_API_TOKEN on this Portunus project." + if [ -n "${CLOUDFLARE_ACCOUNT_ID:-}" ]; then + echo "Cloudflare CLI will use CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID from this Portunus project." + else + echo "Cloudflare CLI will use CLOUDFLARE_API_TOKEN from this Portunus project." + echo "Set CLOUDFLARE_ACCOUNT_ID on this project when a Wrangler command needs an account." + fi else echo "CLOUDFLARE_API_TOKEN is not set. Skipping Cloudflare CLI authentication." fi