zudo-slack-notify

Type to search...

to open search from anywhere

Configure secrets and deploy

Generate the relay key, fill the operator store, push Worker secrets, and deploy.

Operator store

Credentials live outside the repository, in the operator store at $DROPBOX_ROOT/env/zudo-slack-notify/:

$DROPBOX_ROOT/env/zudo-slack-notify/
  credentials/
    worker.env    # what the Worker needs
    sender.env    # what a local sender needs

Generate the relay key

The relay key is a shared bearer secret: 32 to 256 printable ASCII characters with no spaces. Generate 64 hex characters:

openssl rand -hex 32

Fill worker.env

NOTIFY_API_KEY=<your-relay-key>
SLACK_BOT_TOKEN=xoxb-…
SLACK_TARGETS={"dev":"C0123456789","releases":"C0123456789"}
  • NOTIFY_API_KEY: the relay key.

  • SLACK_BOT_TOKEN: the xoxb- token from the Slack app.

  • SLACK_TARGETS: a JSON object mapping alias to channel ID. It is a secret, not a [vars] entry, because this repository is public and channel IDs stay out of git.

Fill sender.env

ZUDO_SLACK_NOTIFY_URL=https://zudo-slack-notify-app.zudolab.dev/v1/notify
ZUDO_SLACK_NOTIFY_API_KEY=<your-relay-key>

The sender file holds only the relay key and the URL. It never holds the Slack bot token.

Push the secrets

pnpm ops:push-secrets --dry-run   # validate shape, print names only
pnpm ops:push-secrets

The script validates each value's shape, then uploads only the non-empty ones in a single wrangler secret bulk. It prints key names and status only (NOTIFY_API_KEY: set), never values. It finds worker.env through $DROPBOX_ROOT; without that variable, pass --env-file <path>. See Secrets and rotation for the full behavior.

Deploy

Deploys run from GitHub Actions on push to main (deploy-app.yml for the API, deploy-doc.yml for the docs), or by manual workflow_dispatch. They need the repository secrets CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID. When either is absent, or the ref is not main, the run skips cleanly and stays green. See Development for the jobs. You can also deploy from app/ by hand:

cd app
pnpm exec wrangler deploy

CI never sets the Worker runtime secrets; that is what pnpm ops:push-secrets is for.

Fail closed until wired

Until all three secrets exist and are valid, POST /v1/notify answers 503 server_misconfigured before authentication and before any Slack request. GET /healthz still answers 200.

Revision History

CreatedUpdated