fix(site): run the DNS preview in a direct job so it gets an OIDC token #227

Merged
ryangr0 merged 1 commit from ryangr0/dns-preview-direct-job into development 2026-10-04 16:13:43 +00:00 AGit
Owner

The first run after #222 failed with no OIDC token endpoint (run 950). Forgejo 15 does not pass enable-openid-connect to the jobs it expands from a reusable workflow, whether it is set on the caller or on the inner job. Release signing gets its token because its job is declared directly.

  • on_dns_change.yml now runs a single direct job:
    1. checkout;
    2. the openbao-read action from webgrip/workflows v2.8.0 on role ci-unfold, reading the read-only token;
    3. dnscontrol check;
    4. preview, or --expect-no-changes on the daily schedule.
  • The job still never pushes. The deploy guide and the policy test follow.

Tested:

  • scripts/workflow-policy.test.cjs: 22/22.
  • mise run docs-check: passes.
  • A local dnscontrol preview with the minted unfoldhq-dev-ro token succeeds (rc 0, 8 corrections).

Not tested: the OIDC exchange itself; it runs on the first push after merge.

The preview shows that the live zone has 5 MX records and an SPF TXT for Namecheap email forwarding that the config doesn't declare. Applying the config would delete them. That decision is separate from this PR.

🤖 Generated with Claude Code

The first run after #222 failed with `no OIDC token endpoint` ([run 950](https://forgejo.webgrip.dev/webgrip/unfold/actions/runs/950)). Forgejo 15 does not pass `enable-openid-connect` to the jobs it expands from a reusable workflow, whether it is set on the caller or on the inner job. Release signing gets its token because its job is declared directly. - `on_dns_change.yml` now runs a single direct job: 1. checkout; 2. the `openbao-read` action from `webgrip/workflows` v2.8.0 on role `ci-unfold`, reading the read-only token; 3. `dnscontrol check`; 4. preview, or `--expect-no-changes` on the daily schedule. - The job still never pushes. The deploy guide and the policy test follow. **Tested:** - `scripts/workflow-policy.test.cjs`: 22/22. - `mise run docs-check`: passes. - A local `dnscontrol preview` with the minted `unfoldhq-dev-ro` token succeeds (rc 0, 8 corrections). **Not tested:** the OIDC exchange itself; it runs on the first push after merge. The preview shows that the live zone has 5 MX records and an SPF TXT for Namecheap email forwarding that the config doesn't declare. Applying the config would delete them. That decision is separate from this PR. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(site): run the DNS preview in a direct job so it gets an OIDC token
Some checks failed
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 32s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 22s
[Workflow] On Pull Request / checks (pull_request) Successful in 7m59s
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
92ecf1e928
The first run after #222 failed with "no OIDC token endpoint": Forgejo
15 does not pass enable-openid-connect to the jobs it expands from a
reusable workflow, set on either side. Release signing works because
its job is declared directly. on_dns_change.yml now runs one job of
its own: checkout, webgrip/workflows openbao-read v2.8.0 on ci-unfold,
then dnscontrol check and preview, or drift on the schedule.

A local preview with the minted read-only token succeeds and lists
the expected corrections.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ryangr0 merged commit b5e198a314 into development 2026-10-04 16:13:43 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!227
No description provided.