Publishing
Setting up your GitHub repository
This page is for whoever manages the site’s GitHub repository. It explains how to set the repository up so that editors can work in Orbit, small content changes can go live without anyone visiting GitHub, and the live site stays protected.
How publishing works with Orbit
- Editors work on a preview branch (for example
preview). When they save, Orbit sends the change there in the background, and your preview site builds. - When a page is ready, an editor clicks Ask to publish on it, with an
optional note. The request is saved in the repository itself (a small file,
orbit.requests.json, on the preview branch), so everyone using Orbit sees it — the page shows Waiting for approval — with no server and no GitHub visit. - An approver opens the page (or Unpublished), checks what changed and
clicks Publish — Orbit copies those changes to the live branch (for
example
main) and pushes. Or they Send back with a reason the editor sees.
So the live branch only changes when an approver says so, and code changes from developers still go through your normal pull-request reviews.
Who can do what
| Person | Needs on GitHub | Can do in Orbit |
|---|---|---|
| Viewer | Read access (organisation repositories), or a public repository | Look at pages and their history — nothing can be changed |
| Editor | Write access (to push to the preview branch) | Edit and save (to the preview site), ask to publish |
| Approver | Permission to push to the live branch — on the live branch’s bypass list (step 4) | Everything an editor can, plus publish, and approve or send back requests |
With Sign in with GitHub (Orbit MD 1.1 and later), Orbit reads each person’s role from GitHub — nobody has to set it, and nobody sees a button GitHub would refuse. Developer tools (branches, Settings) are offered to people with Admin or Maintain access. Add Orbit MD to the repository first (step 5).
Without signing in (or on another host), Orbit’s Editor / Developer view (the View menu) decides which buttons someone sees — a convenience, not a lock. Either way GitHub is what actually enforces it: someone who isn’t an approver can’t push to a protected live branch.