Skip to content

docs: correct the HTTPS note in DEPLOYING - #12

Merged
lintdeveloper merged 1 commit into
mainfrom
docs/deploying-https-note
Aug 27, 2026
Merged

lintdeveloper merged 1 commit into
mainfrom
docs/deploying-https-note

Conversation

@lintdeveloper

Copy link
Copy Markdown
Owner

The page said to enable "Enforce HTTPS" once GitHub issued a certificate. It never will — js.org terminates TLS at Cloudflare, so GitHub can't complete an ACME challenge and the API returns The certificate does not exist yet. HTTPS already works; https_enforced stays false.

Also:

  • marks the cutover done 2026-08-26 instead of pending, kept as a record since the same steps apply to a future move to resilix.dev
  • distinguishes the owned-domain case, where GitHub does issue a cert (and orange-cloud proxying is the usual reason it doesn't)
  • records the trap: resilix.js.org returns 200 before merge because js.org wildcards *.js.org — only the entry on master proves anything

The page told you to enable "Enforce HTTPS" once GitHub issued a certificate.
That instruction can never be followed for a js.org subdomain, so it would
have sent future-you looking for a certificate that will never appear.

js.org serves its subdomains through Cloudflare, which terminates TLS itself —
resilix.js.org resolves to Cloudflare addresses and answers with
`server: cloudflare`. GitHub cannot complete an ACME challenge for a hostname
it does not terminate, and the API says exactly that: "The certificate does not
exist yet (HTTP 404)". HTTPS already works; https_enforced simply stays false.
The section now shows the three commands that establish this rather than
asserting it, and states the one visible consequence: the github.io URL 301s to
http:// before upgrading.

It also distinguishes the case that does not apply here — a domain you own,
where GitHub does issue a certificate and enforcement should be switched on,
with the reminder that an orange-cloud Cloudflare proxy is the usual reason
Pages provisioning never completes.

Tense fixed alongside it. The page described the cutover as pending when it
completed on 2026-08-26; it is now marked done and kept as a record, since the
same five steps apply to any future move. "If it is rejected again" became "It
is free, but it is not ownership" — the request was accepted, and the
reassignment risk is the part that survives.

Added the trap that wasted time during the wait: resilix.js.org returns HTTP
200 before the entry is merged, because js.org wildcards *.js.org and serves a
placeholder. A status code proves nothing; only the entry on master does.
@lintdeveloper
lintdeveloper merged commit cd2e89d into main Aug 27, 2026
11 checks passed
@lintdeveloper
lintdeveloper deleted the docs/deploying-https-note branch August 27, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant