You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[quality] Production deploy bakes the pre-transfer castrojo.github.io origin into every canonical URL, og:url and sitemap entry #348
Every page on the live production site declares a canonical URL, an og:url,
and 44 sitemap entries pointing at https://castrojo.github.io/endusers/ — a
personal fork origin, not the origin the content is served from.
The site is served from https://cncf.github.io/endusers/ (HTTP 200, verified
below). .github/workflows/deploy-gh-pages.yml:58 overrides SITE_URL with
the pre-transfer personal origin, so docusaurus.config.js:28 (url: siteUrl)
bakes that origin into every absolute URL Docusaurus emits.
This is stale state left over from the castrojo/endusers -> cncf/endusers
transfer. .github/workflows/ci.yml:31 was already updated and uses SITE_URL: https://cncf.github.io; the deploy workflow was not.
Evidence (live production site, fetched 2026-09-20)
$ curl -sI https://cncf.github.io/endusers/ | head -1
HTTP/2 200
$ curl -s https://cncf.github.io/endusers/ | grep -oE '(canonical|og:url)[^>]{0,80}'
og:url content=https://castrojo.github.io/endusers/
canonical href=https://castrojo.github.io/endusers/
$ curl -s https://cncf.github.io/endusers/sitemap.xml | grep -c 'castrojo.github.io'
1 # single-line XML: all 44 <loc> entries use the castrojo origin, zero use cncf
At rev 00b44df the only remaining castrojo reference in .github/workflows/
is this one:
Search engines are told the canonical copy of every page lives on another
origin. A rel=canonical pointing off-origin is the strongest possible
de-indexing signal for the origin actually serving the content.
Social previews resolve to the wrong origin — og:url is what Slack,
LinkedIn and X follow when a link is unfurled.
The sitemap submitted for the site lists 44 URLs on an origin the project
does not control.
static/CNAME does not exist, so endusers.cncf.io is not yet active and https://cncf.github.io is the correct value today. The comment already in
the workflow (lines 54-57) covers the later flip to the custom domain.
Why existing gates miss it
onBrokenLinks: 'throw' validates internal routes, not the absolute origin
they are rendered against.
npm run test:unit (55 tests at 00b44df) contains no assertion over .github/workflows/** env values.
ci.yml builds with the correctSITE_URL, so the defect is invisible on
every pull request and appears only in the deploy job.
The docusaurus.config.js default (https://endusers.cncf.io) is correct;
only the workflow override is wrong, so reading the config suggests nothing
is amiss. Open PR fix(config): point editUrl at cncf/endusers, not castrojo #245 fixes editUrl in that config — a different key in a
different file, and it does not touch this.
# Build for the GitHub Pages project URL. When the custom domain in# static/CNAME is verified and active, update these values to# SITE_URL=https://endusers.cncf.io and BASE_URL=/ so canonical and# Open Graph URLs point to the production domain.
- name: Build websiteenv:
SITE_URL: https://castrojo.github.ioBASE_URL: /endusers/run: npm run build:production
with this:
# Build for the GitHub Pages project URL. When the custom domain in# static/CNAME is verified and active, update these values to# SITE_URL=https://endusers.cncf.io and BASE_URL=/ so canonical and# Open Graph URLs point to the production domain.
- name: Build websiteenv:
SITE_URL: https://cncf.github.ioBASE_URL: /endusers/run: npm run build:production
Nothing else changes: BASE_URL is already correct, and the value now matches ci.yml, so pull-request builds and deploy builds agree.
No PR is attached, and that is not a judgement call
The entire fix is inside .github/workflows/. This agent's GitHub App token is
minted at the contributor tier, which does not carry the Workflows
permission, so GitHub rejects any push whose diff touches that directory. There
is nothing this agent can push that would contain the change. It needs a
human maintainer or an agent running at a tier that holds the Workflows
permission to land it. The replacement text above is complete and mechanical
so applying it requires no re-derivation.
A regression-guard test asserting that the deploy workflow's SITE_URL matches
the origin the site is served from is deliberately not proposed here: it
would be red against main until this change lands, and splitting it out would
mean shipping a failing test. It is worth filing separately once this is green.
Priority
Impact: high — affects the canonical URL, Open Graph URL and sitemap of every page on the live production site
Effort: low — one line, no new dependency, no behaviour change beyond the emitted origin
Confirmed and reproduced: this fix requires pushing a change to .github/workflows/deploy-gh-pages.yml, and both git push and the Contents API reject the write:
! [remote rejected] fix/deploy-site-url-castrojo-348 -> fix/deploy-site-url-castrojo-348 (refusing to allow an OAuth App to create or update workflow `.github/workflows/deploy-gh-pages.yml` without `workflow` scope)
The Contents API confirms the same restriction is scoped specifically to the workflow path (a parallel PUT to README.md on the same branch succeeds; the identical PUT to .github/workflows/deploy-gh-pages.yml returns 404). This is a token/tier limitation of this agent, external to the repository itself, not something fixable with a different diff.
The one-line fix is exactly as specified in the issue body: change SITE_URL: https://castrojo.github.io to SITE_URL: https://cncf.github.io at .github/workflows/deploy-gh-pages.yml:58. It needs a maintainer or an agent/token holding the Workflows permission to push it.
Finding
Every page on the live production site declares a canonical URL, an
og:url,and 44 sitemap entries pointing at
https://castrojo.github.io/endusers/— apersonal fork origin, not the origin the content is served from.
The site is served from
https://cncf.github.io/endusers/(HTTP 200, verifiedbelow).
.github/workflows/deploy-gh-pages.yml:58overridesSITE_URLwiththe pre-transfer personal origin, so
docusaurus.config.js:28(url: siteUrl)bakes that origin into every absolute URL Docusaurus emits.
This is stale state left over from the
castrojo/endusers->cncf/enduserstransfer.
.github/workflows/ci.yml:31was already updated and usesSITE_URL: https://cncf.github.io; the deploy workflow was not.Evidence (live production site, fetched 2026-09-20)
At rev
00b44dfthe only remainingcastrojoreference in.github/workflows/is this one:
Impact
origin. A
rel=canonicalpointing off-origin is the strongest possiblede-indexing signal for the origin actually serving the content.
og:urlis what Slack,LinkedIn and X follow when a link is unfurled.
does not control.
static/CNAMEdoes not exist, soendusers.cncf.iois not yet active andhttps://cncf.github.iois the correct value today. The comment already inthe workflow (lines 54-57) covers the later flip to the custom domain.
Why existing gates miss it
onBrokenLinks: 'throw'validates internal routes, not the absolute originthey are rendered against.
npm run test:unit(55 tests at00b44df) contains no assertion over.github/workflows/**env values.ci.ymlbuilds with the correctSITE_URL, so the defect is invisible onevery pull request and appears only in the deploy job.
docusaurus.config.jsdefault (https://endusers.cncf.io) is correct;only the workflow override is wrong, so reading the config suggests nothing
is amiss. Open PR fix(config): point editUrl at cncf/endusers, not castrojo #245 fixes
editUrlin that config — a different key in adifferent file, and it does not touch this.
Recommendation
One-line change. Exact replacement for
.github/workflows/deploy-gh-pages.ymllines 53-59 — replace this:
with this:
Nothing else changes:
BASE_URLis already correct, and the value now matchesci.yml, so pull-request builds and deploy builds agree.Verification after merge
No PR is attached, and that is not a judgement call
The entire fix is inside
.github/workflows/. This agent's GitHub App token isminted at the
contributortier, which does not carry the Workflowspermission, so GitHub rejects any push whose diff touches that directory. There
is nothing this agent can push that would contain the change. It needs a
human maintainer or an agent running at a tier that holds the Workflows
permission to land it. The replacement text above is complete and mechanical
so applying it requires no re-derivation.
A regression-guard test asserting that the deploy workflow's
SITE_URLmatchesthe origin the site is served from is deliberately not proposed here: it
would be red against
mainuntil this change lands, and splitting it out wouldmean shipping a failing test. It is worth filing separately once this is green.
Priority
Filed by quality agent (hold-gated mode)
— hive: agent=quality backend=copilot model=claude-opus-5