Skip to content

ci: deploy with wrangler 4 and declare the rate limit as [[ratelimits]] - #245

Merged
alukach merged 1 commit into
mainfrom
chore/wrangler-4
Sep 30, 2026
Merged

alukach merged 1 commit into
mainfrom
chore/wrangler-4

Conversation

@alukach

@alukach alukach commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

What I'm changing

Follow-up to #235. The KEY_EXCHANGE_LIMIT rate limit binding is declared under [[unsafe.bindings]] because the workflows pin wrangler 3, and the first-class [[ratelimits]] key needs wrangler 4.36.0 or later. This moves the proxy to wrangler 4 and declares the binding the documented way, so wrangler validates it instead of passing an unsafe block through unchecked. workers/public-log-stream is already on wrangler 4 (4.77.0 in its lockfile), so after this the whole repo is on v4.

Decision to flag: wrangler 4 will start applying observability settings that wrangler 3 ignores. Wrangler 3 warns on the current wrangler.toml with Unexpected fields found in observability field: "traces", "destinations". So the Axiom destinations = ["axiom-logs"] / ["axiom-traces"] and the [observability.traces] block added in d0b46cb have probably never been applied from config, since every deploy since then went through wrangler@3. The first wrangler 4 production deploy may start applying them. If the axiom-logs and axiom-traces destinations don't exist in the Cloudflare account, that deploy may fail; the preview and staging deploys won't catch it, because staging and preview set destinations = []. Please confirm both destinations exist under Workers Observability → Destinations before this reaches production.

How I did it

  • .github/workflows/ci.yml, deploy.yml, preview.yml and README.md: wrangler@3 → wrangler@4.
  • wrangler.toml (production and env.staging) and wrangler.preview.toml: [[unsafe.bindings]] → [[ratelimits]], dropping type = "ratelimit". Name, namespace_id (1001, 1002, 1003) and simple = { limit = 100, period = 60 } are unchanged.
  • No Rust changes: the worker reads the binding through env.rate_limiter("KEY_EXCHANGE_LIMIT"), which doesn't care how it was declared.

The pin bump and the config change have to land together. Wrangler 3 reports Unexpected fields found in top-level field: "ratelimits" and would deploy without the binding.

How to test it

  • wrangler deploy --dry-run with wrangler 4.86.0 on a copy of each config (build step stubbed): production, --env staging and wrangler.preview.toml --name … each list env.KEY_EXCHANGE_LIMIT (100 requests/60s) Rate Limit with no config warnings. The same production dry run on wrangler 3 shows the ratelimits and observability warnings quoted above.
  • The pre-commit hook passed: cargo fmt --check, clippy and check for wasm32, cargo test.
  • CI's Integration Tests job runs wrangler dev on wrangler 4 against tests/test_api_keys.py, and this PR's preview deploy exercises wrangler deploy on v4.

PR Checklist

  • This PR has no breaking changes.
  • I have updated or added new tests to cover the changes in this PR. (Config and tooling only; covered by the dry runs and CI above.)
  • This PR affects the Source Cooperative Frontend & API, and I have opened issue/PR #XXX to track the change. (It doesn't.)

Related Issues

Follows #235. Checked the ADRs: ADR-013 describes the per-IP limit, not how the binding is declared, so it still holds. ADR-008 says "In production, logs and traces ship to Axiom"; given the observability note above, that may not have been true while production deployed on wrangler 3, and this change makes it true, so ADR-008 needs no edit.

🤖 Generated with Claude Code

The KEY_EXCHANGE_LIMIT binding was declared under [[unsafe.bindings]] because the workflows pinned wrangler 3, which doesn't know the first-class [[ratelimits]] key (it needs wrangler 4.36.0 or later). Pin wrangler@4 in ci.yml, deploy.yml, preview.yml and the README, and declare the binding as [[ratelimits]] in all three environments, so wrangler validates it. The worker reads it through env.rate_limiter either way, so no code changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @alukach's task in 10s —— View job


✅ No blocking issues — safe to merge.

The diff is a mechanical change: wrangler@3 becomes wrangler@4 in ci.yml, deploy.yml, preview.yml and the README. [[unsafe.bindings]] becomes [[ratelimits]] in wrangler.toml (production and env.staging) and in wrangler.preview.toml. Binding name, namespace IDs (1001, 1002, 1003) and limits are unchanged. env.staging.ratelimits is the right form for the environment-scoped key. The pin bump and config change land together, which they need to. I ran only git diff; I didn't run wrangler or CI.

Before the first production deploy, confirm that the axiom-logs and axiom-traces destinations exist in the Cloudflare account. The PR description already flags this, and I agree with it. Production sets destinations = ["axiom-logs"] and ["axiom-traces"] (wrangler.toml:49-60). Staging and preview use destinations = [], so their deploys won't catch a missing destination. This is a rollout check, not a code defect.

Simplify (ponytail)

  • Nothing to cut. The change removes an unsafe block and a redundant type line, and adds no code.

💰 Estimated review cost: $0.10 · 0m10s · 4 turns

@github-actions

Copy link
Copy Markdown

🚀 Latest commit deployed to https://source-data-proxy-pr-245.source-coop.workers.dev

  • Date: 2026-09-30T03:37:53Z
  • Commit: f8ea8cb

@alukach
alukach merged commit aec49b8 into main Sep 30, 2026
22 checks passed
@alukach
alukach deleted the chore/wrangler-4 branch September 30, 2026 03:41

This branch was successfully deployed

1 active deployment
preview — 1a92eb38 Deployed Sep 30, 2026 by alukach via Deploy & Test / Deploy #392
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant