Publishing

Setting up your GitHub repository

This page is for whoever manages the site’s GitHub repository. It explains how to set the repository up so that editors can work in Orbit, small content changes can go live without anyone visiting GitHub, and the live site stays protected.

How publishing works with Orbit

  1. Editors work on a preview branch (for example preview). When they save, Orbit sends the change there in the background, and your preview site builds.
  2. When a page is ready, an editor clicks Ask to publish on it, with an optional note. The request is saved in the repository itself (a small file, orbit.requests.json, on the preview branch), so everyone using Orbit sees it — the page shows Waiting for approval — with no server and no GitHub visit.
  3. An approver opens the page (or Unpublished), checks what changed and clicks Publish — Orbit copies those changes to the live branch (for example main) and pushes. Or they Send back with a reason the editor sees.

So the live branch only changes when an approver says so, and code changes from developers still go through your normal pull-request reviews.

Who can do what

Person Needs on GitHub Can do in Orbit
Viewer Read access (organisation repositories), or a public repository Look at pages and their history — nothing can be changed
Editor Write access (to push to the preview branch) Edit and save (to the preview site), ask to publish
Approver Permission to push to the live branch — on the live branch’s bypass list (step 4) Everything an editor can, plus publish, and approve or send back requests

With Sign in with GitHub (Orbit MD 1.1 and later), Orbit reads each person’s role from GitHub — nobody has to set it, and nobody sees a button GitHub would refuse. Developer tools (branches, Settings) are offered to people with Admin or Maintain access. Add Orbit MD to the repository first (step 5).

Without signing in (or on another host), Orbit’s Editor / Developer view (the View menu) decides which buttons someone sees — a convenience, not a lock. Either way GitHub is what actually enforces it: someone who isn’t an approver can’t push to a protected live branch.