Build a multi-tenant EdgeOne GitHub App - #1
Conversation
Add verified GitHub App setup, isolated EdgeOne connections, D1-backed deployment state, GitHub Checks and Deployments synchronization, lifecycle cleanup, CI, tests, and operator documentation. Co-authored-by: Codex <codex@openai.com>
Use GitHub's supported installation listing flow, recover quickly from canceled EdgeOne deliveries, persist remote IDs during processing, and document the verified operator settings. Co-authored-by: Codex <codex@openai.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 798698d41f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| return githubDeploymentId; | ||
| }; | ||
|
|
||
| [state.checkRunId, state.githubDeploymentId] = await Promise.all([checkRun(), deployment()]); |
There was a problem hiding this comment.
Keep the claim until both parallel writes settle
When either GitHub operation rejects while the other remains in flight, Promise.all rejects immediately and the catch block releases the deployment claim without waiting for the sibling operation. An EdgeOne retry can then start before that sibling has persisted its newly created Check Run or Deployment ID, causing a second remote object to be created. Wait for both operations to settle before releasing the claim while still propagating any failure.
Useful? React with 👍 / 👎.
| eventType: string, | ||
| ): Promise<boolean> { | ||
| const now = Date.now(); | ||
| const staleBefore = now - 10 * 1000; |
There was a problem hiding this comment.
Do not expire active claims after ten seconds
If processing GitHub and D1 requests takes more than ten seconds, a second delivery can overwrite the still-active claim and perform the same GitHub writes concurrently. For deliveries with the same event type, the original request can then also clear the newer claim because completion is keyed only by that type, admitting further duplicates. Use a lease comfortably longer than the maximum processing window or add ownership tokens and lease renewal.
Useful? React with 👍 / 👎.
Summary
Security
Validation
pnpm test(12 tests)pnpm typecheckpnpm typegen:checkpnpm deploy:dry/healthsmoke testRollout note
This PR does not deploy a Worker or modify the existing single-tenant GitHub App. A new public GitHub App and production Cloudflare resources should be created from
docs/operator-setup.mdafter review.