docs: correct the HTTPS note in DEPLOYING - #12
Merged
Merged
Conversation
The page told you to enable "Enforce HTTPS" once GitHub issued a certificate. That instruction can never be followed for a js.org subdomain, so it would have sent future-you looking for a certificate that will never appear. js.org serves its subdomains through Cloudflare, which terminates TLS itself — resilix.js.org resolves to Cloudflare addresses and answers with `server: cloudflare`. GitHub cannot complete an ACME challenge for a hostname it does not terminate, and the API says exactly that: "The certificate does not exist yet (HTTP 404)". HTTPS already works; https_enforced simply stays false. The section now shows the three commands that establish this rather than asserting it, and states the one visible consequence: the github.io URL 301s to http:// before upgrading. It also distinguishes the case that does not apply here — a domain you own, where GitHub does issue a certificate and enforcement should be switched on, with the reminder that an orange-cloud Cloudflare proxy is the usual reason Pages provisioning never completes. Tense fixed alongside it. The page described the cutover as pending when it completed on 2026-08-26; it is now marked done and kept as a record, since the same five steps apply to any future move. "If it is rejected again" became "It is free, but it is not ownership" — the request was accepted, and the reassignment risk is the part that survives. Added the trap that wasted time during the wait: resilix.js.org returns HTTP 200 before the entry is merged, because js.org wildcards *.js.org and serves a placeholder. A status code proves nothing; only the entry on master does.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The page said to enable "Enforce HTTPS" once GitHub issued a certificate. It never will — js.org terminates TLS at Cloudflare, so GitHub can't complete an ACME challenge and the API returns
The certificate does not exist yet. HTTPS already works;https_enforcedstaysfalse.Also:
resilix.devresilix.js.orgreturns 200 before merge because js.org wildcards*.js.org— only the entry onmasterproves anything