Skip to content

fix(tooling): close the last Access and Google guidance gaps - #51

Merged
WillieCubed merged 1 commit into
mainfrom
docs/cloudflare-guidance-audit
Sep 24, 2026
Merged

WillieCubed merged 1 commit into
mainfrom
docs/cloudflare-guidance-audit

Conversation

@WillieCubed

Copy link
Copy Markdown
Contributor

TL;DR

The bootstrap and production how-to guides for Cloudflare Access and Google Workspace were missing a
handful of facts the owner verified live while setting the platform up: checking and fixing the
Cloudflare account's name, a PKCE troubleshooting fallback, skipping service account keys, skipping
Access country rules, and two Google Group checks. This fills every one of those gaps in the source
of truth repository, so every repository that copies from it gets the complete guidance.

Overview of Changes

packages/cli/src/lib/platform/guides.mjs prints the click-by-click steps that lvbt bootstrap --production and lvbt preflight show in a terminal. Five gaps against the owner's verified notes
are closed there and mirrored in docs/how-to/set-up-production.md, which is the same guidance for
someone reading ahead instead of running the command:

  • Every guide that opens Cloudflare and asks the reader to choose the LVBT account now also says to
    check the account switcher and rename the account if it still shows the old, misspelled name,
    instead of assuming the account is already named correctly.
  • The Google Workspace identity provider guide now says Proof Key for Code Exchange only needs to
    come off if the later "Test" step fails with a code-verifier error, and it now tells the reader to
    skip service account keys and domain-wide delegation while creating the OAuth client, since nothing
    in this setup uses either.
  • The Access application guide now says not to add a Country rule to the allow policy, since it would
    lock out anyone signing in while travelling for little real protection.
  • The Google Group guide used to walk through creating a group from nothing; it now also checks an
    existing group's "Who can join" and "Allow external members" settings before the setup relies on
    it, because those are the two settings that would otherwise quietly let the wrong people in.
  • Offboarding someone now also says to revoke their Cloudflare One session immediately, rather than
    only removing them from the group and waiting for their current session to expire.

No behavior outside the printed guide text changed. pnpm check passes, including the existing test
that every guide pastes each copied value before asking for the next.

Follow-ups

None. This closes the guidance gaps identified in this review; no further guidance work is known to
be outstanding on this repository.

🤖 Generated with Claude Code

Add the remaining owner-verified facts to the bootstrap guide text
(packages/cli/src/lib/platform/guides.mjs) and the production how-to
so both stay complete:

- Every guide that opens Cloudflare and chooses the LVBT account now
  says to check the account switcher and rename the account if it
  still shows the old, misspelled name.
- The Google Workspace identity provider guide now says to turn PKCE
  back off only if Test fails with a code-verifier error, and to skip
  service account keys and domain-wide delegation when creating the
  OAuth client.
- The Access application guide now says not to add a Country rule.
- The Google Group guide now checks an existing group's join and
  external-member settings before relying on it, not only a newly
  created one, and its offboarding step now also revokes the Cloudflare
  One session immediately instead of waiting for the next sign-in.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@WillieCubed
WillieCubed merged commit 67e2c08 into main Sep 24, 2026
1 check passed
@WillieCubed
WillieCubed deleted the docs/cloudflare-guidance-audit branch September 24, 2026 04:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant