Skip to content

docs(relay): document the account-token creation permission - #14995

Open
dannyclifford wants to merge 1 commit into
pingdotgg:mainfrom
dannyclifford:up/relay-deploy-token-docs
Open

dannyclifford wants to merge 1 commit into
pingdotgg:mainfrom
dannyclifford:up/relay-deploy-token-docs

Conversation

@dannyclifford

Copy link
Copy Markdown

Problem

The relay deployment guide omits the permission needed to create its account-owned runtime
token. The resulting authorization failure was previously
reported in #10652.

Change

Name the account-level permission, distinguish it from the user-level permission, and explain
why successful updates to an existing stage do not establish that a new stage can be deployed.

Scope and approval

Small documentation fix for a missing prerequisite of the existing deployment workflow,
submitted under the obvious-fix exception. No runtime behavior changes.

Verification

Manually ran alchemy deploy --stage prod on a separate Cloudflare account using Alchemy
2.0.0-beta.79 on macOS 26.6 arm64. The checkout was based on upstream de34391427, with
only PlanetScale sizing changed in src/db.ts to PS_5 without replicas; Worker and token
bindings were unchanged.

  • Without account-level token-edit permission: ApiToken failed with Unauthorized.
    This run also had unrelated PlanetScale billing failures.
  • After resolving billing and adding user-level API Tokens: Edit: database provisioning
    succeeded, but ApiToken still failed.
  • After adding account-level Account API Tokens: Edit: the token and Worker were created;
    deployment reported Done: 5 succeeded.

Traced token creation and reuse through the relay bindings and Alchemy's account-token
provider. Reuse was checked in source, not by a deployment test. The successful credential
retained user-level token-edit permission; this is not a complete or minimal permission audit.
No automated tests were run for this docs-only change.

Original draft: Claude Fable 5.1 in T3 Code.
Review and final wording: GPT-6-Astra (Codex) in T3 Code.

🤖 Generated with Claude Code

Document the account-level permission needed to create the relay's runtime
token. Explain why successful updates to an existing stage do not establish
that the deployment token can provision a new stage.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Oct 3, 2026
macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 3, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 0f19e34

Macroscope's review found this PR approvable — This PR only adds deployment-permission guidance to an existing relay README. It does not modify executable code, configuration, product defaults, or static-analysis behavior, so it has no runtime blast radius.

Notes:

  • Diff unchanged. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 3, 2026 — with ChatGPT Codex Connector
@macroscopeapp
macroscopeapp Bot dismissed their stale review October 3, 2026 03:39

Dismissing prior approval to re-evaluate 0f19e34

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f5fac401-4311-4aaf-82d6-d0ff8a748a8c
📥 Commits

Reviewing files that changed from the base of the PR and between 858b98b and 0f19e34.

📒 Files selected for processing (1)
  • infra/relay/README.md

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The relay deployment README now explains the Worker’s account-owned runtime token, the permission required to create it, and a possible Unauthorized response when deploying a new stage.

Changes

Relay deployment guidance

Layer / File(s) Summary
Runtime token requirements
infra/relay/README.md
The documentation describes the account-level permission required to create the runtime token, notes that user-level token permissions are insufficient, and explains that a new stage deployment may return Unauthorized.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to 0f19e

The permission guidance can merge with normal documentation checks; no actionable deployment risk has been established.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the documentation change: it adds the account-token creation permission to the relay docs.
Description check ✅ Passed The description covers the problem, change, scope and approval rationale, and verification. It also states the test limitations and permission-audit caveat.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:XS 0-9 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants