Skip to content

Fix preview environment cleanup token and naming - #202

Merged
kentcdodds merged 4 commits into
mainfrom
cursor/remove-unused-workflow-secrets
Apr 18, 2026
Merged

kentcdodds merged 4 commits into
mainfrom
cursor/remove-unused-workflow-secrets

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Apr 18, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • keep the GitHub preview-environment delete step on a dedicated repository secret token after verifying the default workflow token fails against the environment delete API
  • make the preview job environment name deterministic for manual branch previews instead of falling back to github.run_id
  • reuse the cleanup job's resolved preview name when deleting the GitHub environment so branch-targeted cleanup matches the environment created during deploy
  • remove the cleanup job's unused deployments: write permission

Verification

  • verified the current PR head workflow and checked the failed cleanup run log from run 24606236180
  • confirmed the failure was 403 Resource not accessible by integration for DELETE /repos/{owner}/{repo}/environments/{environment_name} when using github.token, with x-accepted-github-permissions: administration=write
  • confirmed the latest workflow parses as YAML with the local parser
  • ran npx prettier --check ".github/workflows/preview.yml"

Reviewer findings assessed

  • The token warning was valid for the current PR head because the branch had reverted to github.token; I kept the dedicated secret token for environment deletion.
  • The branch-preview environment naming warning was also valid; deploy and cleanup now resolve the same environment name deterministically.

Artifact:

Open in Web Open in Cursor 

Summary by CodeRabbit

  • Bug Fixes

    • Fixed an issue with preview environment naming to ensure reliable deployment tracking.
  • Chores

    • Improved GitHub Actions workflow configuration for more reliable cleanup and management of preview environments.

cursoragent and others added 2 commits April 18, 2026 13:36
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@coderabbitai

coderabbitai Bot commented Apr 18, 2026 •

Copy link
Copy Markdown

Warning

Rate limit exceeded

@cursor[bot] has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 27 minutes and 4 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 27 minutes and 4 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 432215ec-d4bc-4bc9-ac9c-e3e68b9af2bb

📥 Commits

Reviewing files that changed from the base of the PR and between b95fa09 and 010ee24.

📒 Files selected for processing (1)
  • .github/workflows/preview.yml
📝 Walkthrough

Walkthrough

Updated the preview workflow to fix invalid environment name interpolation, simplified YAML formatting, added explicit cleanup job permissions, and changed the cleanup step to always run using github.token instead of a custom secret.

Changes

Cohort / File(s) Summary
Preview Workflow Configuration
.github/workflows/preview.yml
Fixed environment name interpolation syntax; simplified multiline YAML scalars to single-line expressions. Enhanced cleanup job by adding explicit permissions block (contents: read, deployments: write), removing custom PREVIEW_ENVIRONMENT_GITHUB_TOKEN env var, and converting the environment deletion step to always execute with if: always() using github.token instead of the custom secret.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

Poem

🐰 A workflow once tangled in tokens so bright,
Now cleaned up and fixed with permissions just right,
No more secrets to guard, just the standard github.token,
The preview environments vanish—a deletion most potent! ✨

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Remove unused preview workflow secret' accurately and concisely summarizes the main change—removing a dedicated GitHub secret from the preview workflow and using the built-in GITHUB_TOKEN instead.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/remove-unused-workflow-secrets

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@kentcdodds
kentcdodds marked this pull request as ready for review April 18, 2026 13:47
@github-actions

github-actions Bot commented Apr 18, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-202.kentcdodds.workers.dev

Worker: kody-pr-202
D1: kody-pr-202-db
KV: kody-pr-202-oauth-kv

Mocks:

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/preview.yml:
- Around line 444-446: The workflow currently grants only "permissions:
contents: read" and "deployments: write" which cannot delete repository
environments; locate the permissions block and the job/step that calls the
DELETE /repos/{owner}/{repo}/environments/{environment_name} endpoint and either
(A) remove the environment-deletion step entirely, or (B) change the step to use
a personal access token or GitHub App with proper Environments: write scope
(e.g., reference a secret like secrets.GITHUB_PAT) instead of GITHUB_TOKEN;
update any step that references the environment deletion so it uses the
alternate token and ensure the permissions block remains compatible with that
approach.
- Around line 57-58: The preview environment naming and permissions are
incorrect: change the deploy job's environment name expression (currently
"preview-${{ github.event.pull_request.number || inputs.pr_number ||
github.run_id }}") to a deterministic branch identifier such as using
"inputs.preview_name || github.ref_name" so branch-triggered workflow_dispatch
doesn't create orphaned "preview-${{ github.run_id }}" environments, and update
the cleanup job to both request the correct permission scope by adding
"environments: write" to its permissions and ensure the cleanup logic uses the
exact same naming expression (or the inputs.preview_name || github.ref_name
expression) when calling DELETE
/repos/{owner}/{repo}/environments/{environment_name} so deletion succeeds.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: bc9e020a-ec36-4c04-aace-cb3133abeaaa

📥 Commits

Reviewing files that changed from the base of the PR and between 413721c and b95fa09.

📒 Files selected for processing (1)
  • .github/workflows/preview.yml

Comment on lines +57 to 58
name: preview-${{ github.event.pull_request.number || inputs.pr_number ||
github.run_id }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

# First, locate and examine the preview.yml workflow file
fd -t f "preview.yml" .github/

Repository: kentcdodds/kody

Length of output: 88


🏁 Script executed:

# Read the workflow file to examine the lines mentioned
wc -l .github/workflows/preview.yml

Repository: kentcdodds/kody

Length of output: 92


🏁 Script executed:

# Check lines 57-58 (deploy environment naming) and surrounding context
sed -n '50,70p' .github/workflows/preview.yml

Repository: kentcdodds/kody

Length of output: 712


🏁 Script executed:

# Check lines 599-603 (cleanup deletion logic)
sed -n '590,610p' .github/workflows/preview.yml

Repository: kentcdodds/kody

Length of output: 782


🏁 Script executed:

# Check the cleanup script to understand the condition
sed -n '440,460p' .github/workflows/preview.yml

Repository: kentcdodds/kody

Length of output: 651


🏁 Script executed:

# Get the full cleanup script context (lines 550-620)
sed -n '550,620p' .github/workflows/preview.yml

Repository: kentcdodds/kody

Length of output: 2617


🏁 Script executed:

# Also check what inputs are available and how target is used
sed -n '1,100p' .github/workflows/preview.yml

Repository: kentcdodds/kody

Length of output: 2726


🌐 Web query:

GitHub REST API DELETE /repos/environments permission scope required

💡 Result:

The required permission scope for the GitHub REST API DELETE /repos/{owner}/{repo}/environments/{environment_name} endpoint is the "repo" scope for OAuth app tokens and personal access tokens (classic). This applies particularly when using the endpoint with private repositories, but the documentation states it explicitly for this DELETE operation.

Citations:


🌐 Web query:

GitHub Actions GITHUB_TOKEN permissions deployments write delete environment

💡 Result:

The GITHUB_TOKEN in GitHub Actions workflows has configurable permissions via the 'permissions' key at workflow or job level. By default, it has read access to most scopes (contents: read, actions: read, etc.), but write permissions must be explicitly granted, such as deployments: write for creating/updating deployments and environments: write for managing environment configurations. For deployments: - GITHUB_TOKEN can create deployments when a job references an environment (automatic via GitHub Actions). - To explicitly grant: permissions: { deployments: write } For environments: - GITHUB_TOKEN supports read access by default. - For write/delete (e.g., API calls to create/update/delete environments), explicitly grant: permissions: { environments: write } - Note: Some advanced environment management may require a GitHub App token or PAT with repo/administration scope, as GITHUB_TOKEN (GitHub App installation token) lacks certain repository administration permissions like full environment CRUD via API. Example workflow snippet: jobs: deploy: permissions: deployments: write environments: write environment: production steps: - name: Deploy run: echo "Deploying..." Sources confirm GITHUB_TOKEN needs explicit write permissions for these scopes, and limitations exist for delete/create environments via standard GITHUB_TOKEN (requires alternatives for full control).

Citations:


Fix orphaned branch preview environments and add missing environment deletion permissions.

When workflow_dispatch is triggered with target=branch (the default), the deploy job creates preview-${github.run_id}, but the cleanup job intentionally skips GitHub environment deletion with the message "branch-targeted cleanups use a different naming scheme." This leaves an orphaned environment for each manual branch deployment.

Additionally, the cleanup job declares only deployments: write permission, but calling DELETE /repos/{owner}/{repo}/environments/{environment_name} requires either environments: write or the broader repo scope. The GITHUB_TOKEN used here lacks full environment management permissions for deletion via the REST API.

To fix this:

  1. Add environments: write permission to the cleanup job (minimum requirement for environment deletion)
  2. Update the deploy environment name to use a deterministic identifier for branch deployments (e.g., inputs.preview_name || github.ref_name), or explicitly implement branch-targeted deletion logic using the same naming expression in the cleanup script
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/preview.yml around lines 57 - 58, The preview environment
naming and permissions are incorrect: change the deploy job's environment name
expression (currently "preview-${{ github.event.pull_request.number ||
inputs.pr_number || github.run_id }}") to a deterministic branch identifier such
as using "inputs.preview_name || github.ref_name" so branch-triggered
workflow_dispatch doesn't create orphaned "preview-${{ github.run_id }}"
environments, and update the cleanup job to both request the correct permission
scope by adding "environments: write" to its permissions and ensure the cleanup
logic uses the exact same naming expression (or the inputs.preview_name ||
github.ref_name expression) when calling DELETE
/repos/{owner}/{repo}/environments/{environment_name} so deletion succeeds.

Comment thread .github/workflows/preview.yml
Comment thread .github/workflows/preview.yml
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Cleanup step still references removed secret, never runs
    • Switched the cleanup step to always run with the built-in token by removing the secret guard and using ${{ github.token }} for the GitHub API call.

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit 010ee24. Configure here.

Comment thread .github/workflows/preview.yml Outdated
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kentcdodds
kentcdodds merged commit 71d6dcf into main Apr 18, 2026
9 checks passed
@kentcdodds
kentcdodds deleted the cursor/remove-unused-workflow-secrets branch April 18, 2026 13:58
@cursor cursor Bot changed the title Remove unused preview workflow secret Fix preview environment cleanup token and naming Apr 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants