9.6 KiB
Deployment Environment Protection Configuration
Date Configured: 2025-12-18 Repository: allaunthefox/NoDupeLabs Configured by: Claude Code
Overview
Deployment environments have been configured with appropriate protection rules to ensure safe and controlled deployments across different stages.
Environment Configuration
1. Production Environment
Purpose: Live production deployments requiring approval and branch restrictions.
Protection Rules
| Rule Type | Configuration | Purpose |
|---|---|---|
| Branch Policy | Protected branches only | Only allows deployments from protected branches (main) |
| Required Reviewers | 1 reviewer required | Deployment requires approval from: allaunthefox |
| Wait Timer | 0 minutes | No additional wait time (can be added later) |
| Admin Bypass | Enabled | Repository admins can bypass if needed |
Key Features
✅ Deployment Restrictions:
- Can ONLY deploy from protected branches
- Currently restricted to:
mainbranch (protected) - Prevents accidental deployments from feature branches
✅ Review Requirements:
- Requires manual approval before deployment
- Reviewer: @allaunthefox (repository owner)
- Prevents self-review: No (owner can approve own deployments)
✅ Safety Guarantees:
- No untested code can reach production
- All production deployments go through main branch
- Manual checkpoint before each deployment
2. Development Environment
Purpose: Testing and development deployments with flexible branch access.
Protection Rules
| Rule Type | Configuration | Purpose |
|---|---|---|
| Branch Policy | Custom branch policies | Allows deployments from any branch |
| Required Reviewers | None | No approval required for dev deployments |
| Allowed Branches | * (wildcard) |
All branches can deploy to development |
| Admin Bypass | Enabled | Repository admins can bypass if needed |
Key Features
✅ Deployment Flexibility:
- Can deploy from ANY branch
- No approval required
- Fast iteration for testing
✅ Use Cases:
- Feature branch testing
- Integration testing
- CI/CD validation
- Pre-production verification
Deployment Workflow
Standard Deployment Flow
┌─────────────────┐
│ Feature Branch │
│ (any branch) │
└────────┬────────┘
│
├──────────────► Development Environment
│ (automatic, no approval)
│
▼
┌─────────────┐
│ Pull Request│
│ to main │
└──────┬──────┘
│
▼
┌─────────────┐
│ Main Branch │
│ (protected) │
└──────┬──────┘
│
├──────────────► Production Environment
│ (requires approval from allaunthefox)
│
▼
┌──────────────┐
│ Production │
│ Deployed │
└──────────────┘
Approval Process for Production
- Deployment Triggered: CI/CD workflow reaches production deployment step
- Workflow Paused: GitHub pauses and requests review
- Notification Sent: Reviewer (allaunthefox) receives notification
- Review & Approve: Reviewer examines changes and approves/rejects
- Deployment Proceeds: If approved, deployment continues to production
Configuration Details
Production Environment API Response
{
"name": "production",
"protection_rules": [
{
"type": "branch_policy",
"deployment_branch_policy": {
"protected_branches": true,
"custom_branch_policies": false
}
},
{
"type": "required_reviewers",
"reviewers": [
{
"type": "User",
"login": "allaunthefox"
}
],
"prevent_self_review": false
}
],
"wait_timer": 0,
"can_admins_bypass": true
}
Development Environment API Response
{
"name": "development",
"protection_rules": [
{
"type": "branch_policy",
"deployment_branch_policy": {
"protected_branches": false,
"custom_branch_policies": true
}
}
],
"deployment_branch_policies": [
{
"name": "*",
"type": "branch"
}
],
"wait_timer": 0,
"can_admins_bypass": true
}
GitHub Actions Integration
How to Use Environments in Workflows
Production Deployment Example
deploy-production:
name: Deploy to Production
runs-on: ubuntu-latest
environment:
name: production
url: https://production.example.com
if: github.ref == 'refs/heads/main'
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Deploy to production
run: |
# Deployment will pause here for approval
echo "Deploying to production..."
Development Deployment Example
deploy-development:
name: Deploy to Development
runs-on: ubuntu-latest
environment:
name: development
url: https://dev.example.com
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Deploy to development
run: |
# No approval needed, deploys immediately
echo "Deploying to development..."
Security Best Practices
✅ Implemented
- ✅ Production restricted to protected branches only
- ✅ Required approval for production deployments
- ✅ Development environment allows rapid iteration
- ✅ Admin bypass available for emergency situations
- ✅ Clear separation between dev and prod environments
📋 Optional Enhancements
Consider adding these for additional security:
-
Wait Timer for Production (0-43,200 minutes):
# Add a 5-minute cooldown before production deployments gh api -X PUT repos/allaunthefox/NoDupeLabs/environments/production \ --field wait_timer=5 -
Prevent Self-Review:
- If you add additional reviewers, consider enabling this
- Currently disabled since you're the sole maintainer
-
Secret Management:
- Use environment-specific SECRET_REMOVEDs:
PRODUCTION_API_KEY,DEV_API_KEY - Access via: Settings → Environments → [environment] → Add SECRET_REMOVED
- Use environment-specific SECRET_REMOVEDs:
-
Multiple Reviewers:
- Add team members as reviewers when project grows
- Require multiple approvals for critical deployments
Managing Environment Protection
View Environment Status
# List all environments
gh api repos/allaunthefox/NoDupeLabs/environments
# View specific environment
gh api repos/allaunthefox/NoDupeLabs/environments/production
Modify Protection Rules
# Add wait timer to production
gh api -X PUT repos/allaunthefox/NoDupeLabs/environments/production \
--field wait_timer=5
# Add additional reviewer (example)
gh api -X PUT repos/allaunthefox/NoDupeLabs/environments/production \
--input - <<'EOF'
{
"reviewers": [
{"type": "User", "id": 28494262},
{"type": "User", "id": 12345678}
]
}
EOF
Remove Protection
# Remove all protection rules (not recommended for production)
gh api -X DELETE repos/allaunthefox/NoDupeLabs/environments/production
Approval Workflow
When Deployment Needs Approval
- GitHub Actions Run: Workflow reaches production deployment job
- Status: Shows "Waiting for approval" with ⏸️ icon
- Notification: You receive notification (email/GitHub)
- Action Required:
- Go to: https://github.com/allaunthefox/NoDupeLabs/actions
- Click on the workflow run
- Click "Review deployments"
- Select environment(s) to approve
- Add optional comment
- Click "Approve and deploy"
Approval Options
- ✅ Approve: Deployment proceeds
- ❌ Reject: Deployment is cancelled
- ⏱️ Timeout: No timeout configured (waits indefinitely)
Troubleshooting
Deployment Stuck "Waiting for Review"
Cause: Required reviewer hasn't approved Solution:
- Go to Actions tab
- Find the waiting run
- Click "Review deployments"
- Approve or reject
"Branch not allowed to deploy"
Cause: Trying to deploy to production from non-protected branch Solution:
- Merge to main first
- Deploy from main branch only
- Or temporarily modify branch policy if needed
"No reviewers available"
Cause: Reviewer account issue Solution: Verify reviewer has repo access
Current Deployment Targets
Based on your ci-cd.yml workflow:
| Environment | Trigger | Approval | Branch Restriction |
|---|---|---|---|
| development | (Not currently used in workflows) | ❌ No | ✅ Any branch |
| production | Push to main (deploy job) | ✅ Yes (allaunthefox) | ✅ Protected branches only |
Summary
Production Environment
- ✅ Protected and secure
- ✅ Requires approval from allaunthefox
- ✅ Only deploys from main branch
- ✅ Manual checkpoint before production
Development Environment
- ✅ Flexible and fast
- ✅ No approval needed
- ✅ Any branch can deploy
- ✅ Perfect for testing
Configuration Status: ✅ Complete and Production-Ready
Last Updated: 2025-12-18
For more information, see: