daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 9dd7bfbec1b796e29c4ea9a4bf4076296f90ab64
parent 62eda574272ef6f3aab3d8468fda90652fa80edf
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Mon, 28 Sep 2026 06:12:56 +0100

Drop GitHub Pages, GitLab Pages and Vercel; Cloudflare is the only host

The site is served from Cloudflare Workers at cheatsheet.daemon-sec.xyz.
The other three targets were redundant, and two of them published the same
build to URLs nobody used.

- delete .github/workflows/deploy.yml, .gitlab-ci.yml and vercel.json
- astro.config.mjs: `site` was the Vercel hostname, which fed the sitemap
  and every canonical URL. Point it at the live custom domain instead.
- sync-mirrors.yml dispatched deploy.yml after a sync, so removing that
  workflow would have failed every future sync run. Drop the step, and the
  `actions: write` permission it was the only reason for.
- README: document `npm run deploy:workers` as the single deploy path, and
  state plainly that it is manual — pushing to main now publishes nothing.

Deploys are manual by design here; there is no CI deploy to replace.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Diffstat:
D.github/workflows/deploy.yml | 46----------------------------------------------
M.github/workflows/sync-mirrors.yml | 14+++-----------
M.gitignore | 1-
D.gitlab-ci.yml | 20--------------------
MREADME.md | 18+++++++++++-------
Mastro.config.mjs | 6++++--
Dvercel.json | 7-------
7 files changed, 18 insertions(+), 94 deletions(-)

diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml @@ -1,46 +0,0 @@ -name: Deploy to GitHub Pages - -on: - push: - branches: [main] - workflow_dispatch: - -permissions: - contents: read - pages: write - id-token: write - -concurrency: - group: pages - cancel-in-progress: true - -jobs: - build: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@v4 - - name: Setup Node - uses: actions/setup-node@v4 - with: - node-version: 22 - cache: npm - - name: Install - run: npm ci - - name: Build (Astro + Pagefind) - run: npm run build - - name: Upload artifact - uses: actions/upload-pages-artifact@v3 - with: - path: dist - - deploy: - needs: build - runs-on: ubuntu-latest - environment: - name: github-pages - url: ${{ steps.deployment.outputs.page_url }} - steps: - - name: Deploy - id: deployment - uses: actions/deploy-pages@v4 diff --git a/.github/workflows/sync-mirrors.yml b/.github/workflows/sync-mirrors.yml @@ -12,7 +12,6 @@ on: permissions: contents: write - actions: write # to dispatch deploy.yml — see "Deploy" below concurrency: group: sync-mirrors @@ -43,13 +42,6 @@ jobs: id: push run: scripts/sync-mirrors.sh --push - # A push made with GITHUB_TOKEN deliberately does not trigger other - # workflows, so deploy.yml's `on: push` will not fire for the commits - # above and GitHub Pages would go stale. workflow_dispatch is the - # documented exception to that rule, so ask for the deploy explicitly. - # (Vercel builds from its own GitHub App webhook and is unaffected.) - - name: Deploy the synced content - if: steps.push.outputs.changed == 'true' - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: gh workflow run deploy.yml --ref main + # No deploy step: Cloudflare Workers is the only host and it deploys + # manually via `npm run deploy:workers`. A sync lands commits on main and + # nothing more, so synced content goes live at the next manual deploy. diff --git a/.gitignore b/.gitignore @@ -11,7 +11,6 @@ candidates.json /public/pagefind/ # Playwright MCP scratch output (page snapshots, extension crx) .playwright-mcp/ -.vercel .env* # fetch-ired.py research scratch, if ever pointed back inside the repo .ired-cache/ diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml @@ -1,20 +0,0 @@ -# GitLab Pages mirror of the cheatsheet vault. -# The primary host is Cloudflare Workers (npm run deploy:workers); this job -# publishes the same static build to <project>.gitlab.io on every push to main. -image: node:22 - -pages: - stage: deploy - cache: - key: - files: [package-lock.json] - paths: [.npm/] - script: - - npm ci --cache .npm --prefer-offline - - npm run build - - rm -rf public && mv dist public - artifacts: - paths: [public] - expire_in: 1 week - rules: - - if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH diff --git a/README.md b/README.md @@ -49,9 +49,15 @@ npm run preview # preview the production build ## Deploy -Pushing to `main` triggers `.github/workflows/deploy.yml`, which builds the site -and publishes `dist/` to GitHub Pages. Enable Pages once under -**Settings → Pages → Source: GitHub Actions**. +Cloudflare Workers is the only host. It serves `cheatsheet.daemon-sec.xyz`, +configured in `wrangler.jsonc`, and deploys are **manual**: + +```bash +npm run deploy:workers # build + .assetsignore + wrangler deploy +``` + +There is no CI deploy. Pushing to `main` publishes nothing on its own, so a +content change is live only once someone runs the command above. ## Content structure @@ -101,10 +107,8 @@ workflow**. Only trees that actually moved get a commit. There is no review gate, so `npm run build` and `node --test` are the safety net: a sync that breaks either fails and never lands. -Because a push made with `GITHUB_TOKEN` does not trigger other workflows, the -workflow dispatches `deploy.yml` itself once the script has pushed. A `--push` -from your own machine needs no such help, since your own credentials trigger it -normally. Vercel is unaffected either way, as it builds from its own webhook. +The sync only lands commits; it does not publish. Because deploys are manual, +run `npm run deploy:workers` after a sync to put the new upstream content live. ## Legal diff --git a/astro.config.mjs b/astro.config.mjs @@ -165,9 +165,11 @@ function rehypeDropCap() { } } -// Deployed to Vercel at the domain root — no base path. +// Deployed to Cloudflare Workers at the domain root — no base path. +// `site` feeds the sitemap and canonical URLs, so it must be the live custom +// domain from wrangler.jsonc, not a platform-generated hostname. export default defineConfig({ - site: 'https://daemon-sec-cheatsheet.vercel.app', + site: 'https://cheatsheet.daemon-sec.xyz', trailingSlash: 'ignore', integrations: [mdx(), sitemap()], markdown: { diff --git a/vercel.json b/vercel.json @@ -1,7 +0,0 @@ -{ - "$schema": "https://openapi.vercel.sh/vercel.json", - "framework": "astro", - "buildCommand": "npm run build", - "outputDirectory": "dist", - "installCommand": "npm ci" -}