Skip to content

Fix Windows PowerShell bootstrap returning 403 for hosted installer #20

Description

@Teakowa

Goal

Make the documented Windows installation command on wrightkit.dev work from the supported Windows PowerShell environment, and add regression coverage for the public bootstrap URL itself.

Context

The website currently documents:

irm https://wrightkit.dev/install.ps1 | iex

A real Windows install attempt fails before install.ps1 executes:

irm : The remote server returned an error: (403) Forbidden

This is distinct from Wright's installer-internal release transport. The canonical wright/install.ps1 already owns release resolution/download behavior and has production R2 smoke coverage, while wrightkit.dev syncs that canonical script into the static site during build.

The missing regression surface is the public bootstrap path itself: current site verification proves that build/install.ps1 exists and looks structurally valid, but does not prove that a supported Windows PowerShell client can fetch the deployed https://wrightkit.dev/install.ps1 endpoint.

The exact server/CDN cause of the 403 should be verified during implementation rather than assumed from the symptom.

Scope

  • Reproduce the 403 against the deployed https://wrightkit.dev/install.ps1 endpoint from the supported Windows PowerShell environment.
  • Fix the public hosting/delivery path so the documented irm https://wrightkit.dev/install.ps1 | iex bootstrap succeeds.
  • Keep wright/install.ps1 as the canonical installer source; do not create a divergent website-owned installer implementation.
  • Add a production-facing Windows smoke that fetches the actual public wrightkit.dev/install.ps1 URL through the documented PowerShell path.
  • Keep the bootstrap smoke focused on website delivery. Installer-internal release/R2 behavior remains owned and tested in wright.
  • Make failures distinguish a public bootstrap/delivery failure from a failure after the installer has started.
  • Update website installation documentation only if the supported command or delivery contract changes.

Non-goals

  • Reimplementing Wright's release downloader in the website repository.
  • Duplicating Wright's installer/R2 test suite in wrightkit.dev.
  • Adding a second canonical copy of install.ps1.
  • Weakening unrelated Cloudflare/security policy without first establishing that it is the actual cause.
  • Changing Wright release artifact layout or package-manager distribution.

Acceptance criteria

  • On the supported Windows PowerShell environment, irm https://wrightkit.dev/install.ps1 returns the canonical Wright PowerShell installer instead of HTTP 403.
  • The documented irm https://wrightkit.dev/install.ps1 | iex path successfully enters the installer execution path.
  • CI or deployment verification exercises the deployed public URL from Windows PowerShell rather than only inspecting the locally built install.ps1 file.
  • The website continues to source install.ps1 from the canonical wright installer.
  • Public-bootstrap failures are attributable separately from installer-internal release/download failures.
  • Existing static build verification for installer presence/shape remains intact unless replaced by an equally direct check.

Dependencies / ownership

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions