Skip to content

[autoconfig] Approve required pnpm builds before installing Cloudflare packages #16035

Description

@penalosa

Problem

When cf init is run in an existing project, it delegates setup to @cloudflare/autoconfig. In packages/autoconfig/src/run.ts, runAutoConfig() can install cf@latest, Wrangler, and framework integration packages using the project's package manager. For pnpm 11+, an install can fail with ERR_PNPM_IGNORED_BUILDS if the active pnpm-workspace.yaml has not approved the workerd and esbuild build scripts.

The new Worker scaffold in cloudflare/cf#136 writes these approvals before pnpm install, following the create-cloudflare fix in #14193. The existing-project path still relies on autoconfig and has no equivalent approval step. This is adjacent to cloudflare/cf#92.

Proposed behavior

  • When autoconfig selects pnpm, add allowBuilds approvals for the Cloudflare dependencies it installs that require scripts (workerd and esbuild) before its first package installation.
  • Update the active workspace's pnpm-workspace.yaml, including when the project is inside a pnpm workspace. Preserve existing workspace settings, other approval entries, and explicit false decisions. Respect dangerouslyAllowAllBuilds: true rather than adding a conflicting policy.
  • Avoid writing during dry runs or when setup is cancelled. Leave non-pnpm projects unchanged. Do not pre-approve unrelated framework dependencies.
  • Cover the existing-project autoconfig flow with pnpm 11+ and an existing workspace file in tests.

This should cover both autoconfig's cf and Wrangler targets, which can install Cloudflare packages.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    feature:auto-configAutomatic configuration of a framework at deploy-time, or when running `wrangler setup`

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions