# CI deployment Source: https://twiki.twango.dev/guides/ci # CI deployment Run validation and builds on pull requests. Deploy only trusted commits on the production branch, after validation succeeds. Set the GitHub Actions secret `CLOUDFLARE_API_TOKEN` and variable `CLOUDFLARE_ACCOUNT_ID`. Scope the token to the Worker and resources it needs. Restrict the production environment to your production branch. The essential commands are: ```sh bun install --frozen-lockfile bunx twiki build --target cloudflare bunx twiki deploy ``` Expose Cloudflare credentials only to the upload step. Keep deployments serialized so two uploads do not race. If static export runs in the same job, preserve the Cloudflare build first: both targets write generated state. Twiki's own `ci.yml` demonstrates this pattern: tests build the documentation, the Cloudflare artifact transfers to a separate deployment job, and a final check compares the live content and application versions with the build descriptor. npm releases use a separate job and OIDC permissions within the same workflow. [Twiki CI workflow](https://github.com/twangodev/twiki/blob/main/.github/workflows/ci.yml) See [[guides/caching|Caching]] for reusable build state and [[guides/cloudflare|Cloudflare]] for initial routing setup.