Configure secrets and deploy
Generate the relay key, fill the operator store, push Worker secrets, and deploy.
Operator store
Credentials live outside the repository, in the operator store at $DROPBOX_:
$DROPBOX_ROOT/env/zudo-slack-notify/
credentials/
worker.env # what the Worker needs
sender.env # what a local sender needsGenerate the relay key
The relay key is a shared bearer secret: 32 to 256 printable ASCII characters with no spaces. Generate 64 hex characters:
openssl rand -hex 32Fill worker.env
NOTIFY_API_KEY=<your-relay-key>
SLACK_BOT_TOKEN=xoxb-…
SLACK_TARGETS={"dev":"C0123456789","releases":"C0123456789"}NOTIFY_API_KEY: the relay key.SLACK_BOT_TOKEN: thexoxb-token from the Slack app.SLACK_TARGETS: a JSON object mapping alias to channel ID. It is a secret, not a[vars]entry, because this repository is public and channel IDs stay out of git.
Fill sender.env
ZUDO_SLACK_NOTIFY_URL=https://zudo-slack-notify-app.zudolab.dev/v1/notify
ZUDO_SLACK_NOTIFY_API_KEY=<your-relay-key>The sender file holds only the relay key and the URL. It never holds the Slack bot token.
Push the secrets
pnpm ops:push-secrets --dry-run # validate shape, print names only
pnpm ops:push-secretsThe script validates each value's shape, then uploads only the non-empty ones in a single wrangler secret bulk. It prints key names and status only (NOTIFY_API_KEY: set), never values. It finds worker.env through $DROPBOX_ROOT; without that variable, pass --env-file <path>. See Secrets and rotation for the full behavior.
Deploy
Deploys run from GitHub Actions on push to main (deploy-app.yml for the API, deploy-doc.yml for the docs), or by manual workflow_dispatch. They need the repository secrets CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID. When either is absent, or the ref is not main, the run skips cleanly and stays green. See Development for the jobs. You can also deploy from app/ by hand:
cd app
pnpm exec wrangler deployCI never sets the Worker runtime secrets; that is what pnpm ops:push-secrets is for.
Fail closed until wired
Until all three secrets exist and are valid, POST /v1/notify answers 503 server_misconfigured before authentication and before any Slack request. GET /healthz still answers 200.