diff --git a/apps/api/src/resources/env.ts b/apps/api/src/resources/env.ts index 3c7deef21f..824473ef93 100644 --- a/apps/api/src/resources/env.ts +++ b/apps/api/src/resources/env.ts @@ -105,7 +105,6 @@ export const apiConfiguredEnv = (stage: MapleStage, region: MapleRegion, domains // The repository-reading half is shared with maple-ai; the install flow and // the webhook receiver are this Worker's alone. githubAppSourceEnv, - optionalPlain("GITHUB_APP_SLUG"), optionalPlain("GITHUB_APP_CLIENT_ID"), optionalSecret("GITHUB_APP_CLIENT_SECRET"), optionalSecret("GITHUB_APP_WEBHOOK_SECRET"), diff --git a/packages/infra/src/env.ts b/packages/infra/src/env.ts index 4818259eb9..8c3a8fec08 100644 --- a/packages/infra/src/env.ts +++ b/packages/infra/src/env.ts @@ -297,13 +297,14 @@ export const planetScaleOAuthEnv: Config.Config = merge( /** * The GitHub App as a repository reader: app id + private key mint installation - * tokens, `GITHUB_API_BASE_URL` points them at GitHub Enterprise Server. Bound by - * every Worker that resolves a connected repository — api for the integration, - * maple-ai for the agents' source and sandbox tools. The install flow's client - * id/secret and the webhook secret stay api-only. + * tokens, `GITHUB_API_BASE_URL` points them at GitHub Enterprise Server, the slug is the + * reviewer's `@` handle in published reviews. Bound by every Worker that resolves a connected + * repository: api for the integration, maple-ai for the agents' source and sandbox tools and + * PR reviews. The install flow's client id/secret and the webhook secret stay api-only. */ export const githubAppSourceEnv: Config.Config = merge( optionalPlain("GITHUB_APP_ID"), + optionalPlain("GITHUB_APP_SLUG"), optionalSecret("GITHUB_APP_PRIVATE_KEY"), optionalPlain("GITHUB_API_BASE_URL"), )