Site access allowlist¶
Cloudflare Access for colombia.alelom.com is driven by a JSON file in this private repo.
You (GitHub write access) can add or remove emails there; other people who only have
Access login to the site cannot change the list.
Edit the allowlist¶
Open and edit on GitHub:
Format:
{
"emails": [
"someone@example.com",
"another@example.com"
]
}
Commit on main. The workflow
.github/workflows/sync-access-policy.yml
syncs that email list into the Cloudflare Access app automatically. No dashboard click for
routine add/remove.
Notes¶
- Only emails in that file get Access (plus whatever Cloudflare identity providers the app already uses for login — the include list is what this file updates).
- Don’t paste the live email list onto this MkDocs page — keep it in the repo file so the site doesn’t re-publish the roster to every Access viewer who opens Personal → Admin.
- Background:
AGENTS.md(Deployment & infrastructure) andREADME.md.
See also: Admin overview · Personal TODO