Saltar al contenido principal

Control platform releases

The Releases page in alphaswarm_admin (route /platform/releases, API /admin/platform/releases/*) builds and deploys AlphaSwarm's own repositories — the marketing website (alphaswarm_website) and the docs site (alphaswarm_docs), which build on GitHub Actions and serve on Cloudflare Pages.

It is the source-to-site counterpart to the Platform page, which drives the running ECS services via boto3. Control-plane services (admin, agentcore proxy) appear here read-only and link back to the Platform (ECS) page, which owns their rollout.

What it shows​

SurfaceSourcePurpose
Repository tableplatform_repositories registryEvery platform repo + its deploy target (Cloudflare Pages / GitHub Actions / ECS) and readiness.
Credentials strip__platform__ integration tenantWhether the platform GitHub PAT + Cloudflare token are connected.
Build runsGitHub Actions listWorkflowRunsRecent runs of the repo's build workflow (status, conclusion, branch, actor).
DeploymentsCloudflare Pages deploymentsRecent Pages deployments (stage, status, branch, commit, URL).

Deploy targets​

Each registered repository declares a deploy target that governs the build/deploy actions:

  • cloudflare_pages (website, docs) — Build dispatches the GitHub Actions build workflow (workflow_dispatch); Deploy creates a Cloudflare Pages deployment through the Cloudflare API.
  • github_actions — build is deploy: both map to the workflow workflow_dispatch.
  • ecs (admin, agentcore proxy) — rolled out from the Platform (ECS) page; the release surface lists them read-only.

How it connects​

"Connecting" a platform repository has three parts:

  1. Registry — alphaswarm_admin.services.platform_repositories catalogues the repos and their targets. Extend / override it without a code change via ALPHASWARM_ADMIN_PLATFORM_REPOS_JSON (a JSON array of PlatformRepository objects merged over the defaults by key).
  2. Credentials — the admin resolves a GitHub PAT (builds + run history) and a Cloudflare scoped token (Pages deploys + history) from the __platform__ integration tenant. Connect them through the cloud-onboarding wizard / account-integration routes (the same flow as any customer org, with org_id=__platform__).
  3. Workflow trigger — the target repo's build workflow must declare on: workflow_dispatch so the admin can trigger it via the GitHub Actions REST API. alphaswarm_website/.github/workflows/deploy.yml already does.

Required configuration​

Env varPurpose
ALPHASWARM_ADMIN_PLATFORM_GITHUB_ORGGitHub org/owner of the platform repos (default Alpha-Swarm-ai).
ALPHASWARM_ADMIN_PLATFORM_RELEASES_ORG_IDIntegration tenant the GitHub PAT + Cloudflare token resolve from (default __platform__).
ALPHASWARM_ADMIN_PLATFORM_CLOUDFLARE_ACCOUNT_IDCloudflare account that owns the Pages projects — required before a deploy can be triggered.
ALPHASWARM_ADMIN_PLATFORM_REPOS_JSONOptional registry overrides.

Safety posture​

build and deploy are destructive (they run a real pipeline against a production site), so both are:

  • Step-up-MFA gated (require_admin_step_up("manage:infrastructure"), AGENTS rule 52) — the UI's typed-confirmation dialog arms the action and the api client transparently retries the RFC 9470 challenge.
  • Audit-first — a status=pending row is written BEFORE the upstream call and a succeeded|failed row AFTER, carrying the actor chain.

No GitHub PAT or Cloudflare token ever crosses the BFF boundary in a response body or log line; the providers resolve them from the encrypted integration store per call.