commit 9dd7bfbec1b796e29c4ea9a4bf4076296f90ab64
parent 62eda574272ef6f3aab3d8468fda90652fa80edf
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Mon, 28 Sep 2026 06:12:56 +0100
Drop GitHub Pages, GitLab Pages and Vercel; Cloudflare is the only host
The site is served from Cloudflare Workers at cheatsheet.daemon-sec.xyz.
The other three targets were redundant, and two of them published the same
build to URLs nobody used.
- delete .github/workflows/deploy.yml, .gitlab-ci.yml and vercel.json
- astro.config.mjs: `site` was the Vercel hostname, which fed the sitemap
and every canonical URL. Point it at the live custom domain instead.
- sync-mirrors.yml dispatched deploy.yml after a sync, so removing that
workflow would have failed every future sync run. Drop the step, and the
`actions: write` permission it was the only reason for.
- README: document `npm run deploy:workers` as the single deploy path, and
state plainly that it is manual — pushing to main now publishes nothing.
Deploys are manual by design here; there is no CI deploy to replace.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat:
7 files changed, 18 insertions(+), 94 deletions(-)
diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml
@@ -1,46 +0,0 @@
-name: Deploy to GitHub Pages
-
-on:
- push:
- branches: [main]
- workflow_dispatch:
-
-permissions:
- contents: read
- pages: write
- id-token: write
-
-concurrency:
- group: pages
- cancel-in-progress: true
-
-jobs:
- build:
- runs-on: ubuntu-latest
- steps:
- - name: Checkout
- uses: actions/checkout@v4
- - name: Setup Node
- uses: actions/setup-node@v4
- with:
- node-version: 22
- cache: npm
- - name: Install
- run: npm ci
- - name: Build (Astro + Pagefind)
- run: npm run build
- - name: Upload artifact
- uses: actions/upload-pages-artifact@v3
- with:
- path: dist
-
- deploy:
- needs: build
- runs-on: ubuntu-latest
- environment:
- name: github-pages
- url: ${{ steps.deployment.outputs.page_url }}
- steps:
- - name: Deploy
- id: deployment
- uses: actions/deploy-pages@v4
diff --git a/.github/workflows/sync-mirrors.yml b/.github/workflows/sync-mirrors.yml
@@ -12,7 +12,6 @@ on:
permissions:
contents: write
- actions: write # to dispatch deploy.yml — see "Deploy" below
concurrency:
group: sync-mirrors
@@ -43,13 +42,6 @@ jobs:
id: push
run: scripts/sync-mirrors.sh --push
- # A push made with GITHUB_TOKEN deliberately does not trigger other
- # workflows, so deploy.yml's `on: push` will not fire for the commits
- # above and GitHub Pages would go stale. workflow_dispatch is the
- # documented exception to that rule, so ask for the deploy explicitly.
- # (Vercel builds from its own GitHub App webhook and is unaffected.)
- - name: Deploy the synced content
- if: steps.push.outputs.changed == 'true'
- env:
- GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- run: gh workflow run deploy.yml --ref main
+ # No deploy step: Cloudflare Workers is the only host and it deploys
+ # manually via `npm run deploy:workers`. A sync lands commits on main and
+ # nothing more, so synced content goes live at the next manual deploy.
diff --git a/.gitignore b/.gitignore
@@ -11,7 +11,6 @@ candidates.json
/public/pagefind/
# Playwright MCP scratch output (page snapshots, extension crx)
.playwright-mcp/
-.vercel
.env*
# fetch-ired.py research scratch, if ever pointed back inside the repo
.ired-cache/
diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml
@@ -1,20 +0,0 @@
-# GitLab Pages mirror of the cheatsheet vault.
-# The primary host is Cloudflare Workers (npm run deploy:workers); this job
-# publishes the same static build to <project>.gitlab.io on every push to main.
-image: node:22
-
-pages:
- stage: deploy
- cache:
- key:
- files: [package-lock.json]
- paths: [.npm/]
- script:
- - npm ci --cache .npm --prefer-offline
- - npm run build
- - rm -rf public && mv dist public
- artifacts:
- paths: [public]
- expire_in: 1 week
- rules:
- - if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
diff --git a/README.md b/README.md
@@ -49,9 +49,15 @@ npm run preview # preview the production build
## Deploy
-Pushing to `main` triggers `.github/workflows/deploy.yml`, which builds the site
-and publishes `dist/` to GitHub Pages. Enable Pages once under
-**Settings → Pages → Source: GitHub Actions**.
+Cloudflare Workers is the only host. It serves `cheatsheet.daemon-sec.xyz`,
+configured in `wrangler.jsonc`, and deploys are **manual**:
+
+```bash
+npm run deploy:workers # build + .assetsignore + wrangler deploy
+```
+
+There is no CI deploy. Pushing to `main` publishes nothing on its own, so a
+content change is live only once someone runs the command above.
## Content structure
@@ -101,10 +107,8 @@ workflow**. Only trees that actually moved get a commit. There is no review
gate, so `npm run build` and `node --test` are the safety net: a sync that
breaks either fails and never lands.
-Because a push made with `GITHUB_TOKEN` does not trigger other workflows, the
-workflow dispatches `deploy.yml` itself once the script has pushed. A `--push`
-from your own machine needs no such help, since your own credentials trigger it
-normally. Vercel is unaffected either way, as it builds from its own webhook.
+The sync only lands commits; it does not publish. Because deploys are manual,
+run `npm run deploy:workers` after a sync to put the new upstream content live.
## Legal
diff --git a/astro.config.mjs b/astro.config.mjs
@@ -165,9 +165,11 @@ function rehypeDropCap() {
}
}
-// Deployed to Vercel at the domain root — no base path.
+// Deployed to Cloudflare Workers at the domain root — no base path.
+// `site` feeds the sitemap and canonical URLs, so it must be the live custom
+// domain from wrangler.jsonc, not a platform-generated hostname.
export default defineConfig({
- site: 'https://daemon-sec-cheatsheet.vercel.app',
+ site: 'https://cheatsheet.daemon-sec.xyz',
trailingSlash: 'ignore',
integrations: [mdx(), sitemap()],
markdown: {
diff --git a/vercel.json b/vercel.json
@@ -1,7 +0,0 @@
-{
- "$schema": "https://openapi.vercel.sh/vercel.json",
- "framework": "astro",
- "buildCommand": "npm run build",
- "outputDirectory": "dist",
- "installCommand": "npm ci"
-}