2026-08-12 — Access in front of static sites

Documented the standard pattern for member-only static documentation: keep Antora (or any static generator), Direct Upload from private CI, put Cloudflare Access on the orange-cloud hostname and the Pages *.pages.dev host.

Reader “accounts”:

  • GitHub org invite (default for forge-centric orgs), or

  • Google / Workspace, or

  • email one-time PIN allowlist

Not Cloudflare dashboard members. First Access login consumes a Zero Trust seat (~50 on the free plan).

Follow-up the same day: How Access learns GitHub org membership (flow diagram + simplified mocks).

Pages: