Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions Readme.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,6 @@ mfa 123456

## Cloudflare CLI

Wrangler is installed in the image. `dev <project>/<stage>` authenticates it when that Portunus project sets `CLOUDFLARE_API_TOKEN`. Wrangler reads that variable itself. An optional `CLOUDFLARE_ACCOUNT_ID` on the same project is passed through the same way.
Wrangler is installed in the image. `dev <project>/<stage>` leaves `CLOUDFLARE_API_TOKEN` and `CLOUDFLARE_ACCOUNT_ID` in the environment when that Portunus project sets them. Wrangler reads both itself.

Startup runs `wrangler whoami`. A token that Cloudflare rejects stops the container. A project without `CLOUDFLARE_API_TOKEN` still opens a shell, and Wrangler commands in that shell are not authenticated. `dev` with no project does not load Portunus, so it does not authenticate Wrangler either.
Startup does not call `wrangler whoami`. That command lists account memberships, and an account API token cannot do that even when `CLOUDFLARE_ACCOUNT_ID` is set. A bad token fails the Wrangler command you run. A project without `CLOUDFLARE_API_TOKEN` still opens a shell, and Wrangler commands in that shell are not authenticated. `dev` with no project does not load Portunus, so it does not authenticate Wrangler either.
12 changes: 8 additions & 4 deletions script.sh
Original file line number Diff line number Diff line change
Expand Up @@ -129,11 +129,15 @@ EOF
echo "GH_CLI_TOKEN is not set. Skipping GitHub CLI authentication."
fi

# Wrangler reads CLOUDFLARE_API_TOKEN from the environment. Portunus exports it
# when this project defines it. Run whoami outside /work so it cannot write into the mounted project.
# Wrangler reads these from the environment. whoami always lists memberships, which
# an account API token cannot do, so startup does not call it.
if [ -n "${CLOUDFLARE_API_TOKEN:-}" ]; then
echo "Authenticating Cloudflare CLI..."
( cd /tmp && CI=true WRANGLER_SEND_METRICS=false wrangler whoami ) || error_exit "Failed to authenticate the Cloudflare CLI. Check CLOUDFLARE_API_TOKEN on this Portunus project."
if [ -n "${CLOUDFLARE_ACCOUNT_ID:-}" ]; then
echo "Cloudflare CLI will use CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID from this Portunus project."
else
echo "Cloudflare CLI will use CLOUDFLARE_API_TOKEN from this Portunus project."
echo "Set CLOUDFLARE_ACCOUNT_ID on this project when a Wrangler command needs an account."
fi
else
echo "CLOUDFLARE_API_TOKEN is not set. Skipping Cloudflare CLI authentication."
fi
Expand Down
Loading