feat(deploy): drop the IaC layer, and make both apps runnable as containers

Moving the issuer's state into Postgres removed the last thing that tied
either app to one hosting provider. What was left was a deployment tool
describing resources that no longer existed — so this replaces it with
`wrangler`, which is what actually deploys a Worker, and adds a second way
to run each app that involves no provider at all.

Each app now has a `wrangler.jsonc` with an environment per stage, and a
`Dockerfile` beside it. The handler is the same one in both cases; what
differs is only where its settings come from. Two of them gained a second
spelling so that nothing has to branch on the runtime: Postgres arrives as
a pooled binding or as `DATABASE_URL`, and the route to the issuer is a
service binding or `AUTH_INTERNAL_URL`.

That last one is new, and it is a split the binding was already making
without saying so. `AUTH_ISSUER_URL` has to be the issuer's public name,
because it is compared literally against every token's `iss` claim — but
the public name is often not routable from inside a deployment. So the
name and the route are two settings now rather than one that cannot be
both.

DNS moves out of code and into `docs/dns.md`, which lists every hostname
and what it is for. Six records that change roughly never did not need a
tool, and the table outlives whatever is answering the names — which is
the point, since some of them will stop being Workers. The sandbox
hostnames are hyphenated rather than nested for the same reason: a
certificate covering `*.nestri.io` covers one label and not two, so
`api-sandbox.nestri.io` can become an ordinary origin later without a
certificate having to be ordered for it first.

Also drops `EMAIL_DEV_LOG` from committed configuration into `.dev.vars`,
which `wrangler deploy` cannot upload. Printing a live sign-in code to a
log should not be one forgotten override away from production.
This commit is contained in:
Wanjohi
2026-09-05 15:27:56 +03:00
parent 3d0dcf3e46
commit 51ababc900
28 changed files with 1001 additions and 1322 deletions

59
apps/auth/wrangler.jsonc Normal file
View File

@@ -0,0 +1,59 @@
// The issuer, deployed as a Cloudflare Worker.
//
// The same `src/index.ts` also runs as an ordinary HTTP server — see
// `src/server.ts` and the `Dockerfile` beside it. Nothing in the handler is
// Workers-specific; what differs between the two is only where the settings
// below come from, so this file and the container's environment are two
// spellings of one list.
//
// Hostnames and the reasoning behind their shape: `docs/dns.md`.
// Secrets, the Hyperdrive id, and how to deploy: `docs/deploy.md`.
{
"$schema": "node_modules/wrangler/config-schema.json",
"name": "nestri-auth",
"main": "src/index.ts",
"compatibility_date": "2026-09-05",
"compatibility_flags": ["nodejs_compat"],
// No `*.workers.dev` hostname. A second address that mints tokens is a
// second issuer as far as a token's `iss` claim is concerned, and every
// token minted through it is rejected by the API.
"workers_dev": false,
"dev": {
"port": 1337
},
// Local-only settings live in `.dev.vars` beside this file rather than in
// `vars` here. `wrangler dev` reads that file and `wrangler deploy` cannot
// upload it — which is the guarantee wanted for the one setting in it:
// printing a live sign-in code to the log is a thing you ask for by name,
// and no stage anybody else can reach may have it. Written as a `vars`
// entry it would be one forgotten override away from being deployed.
// The default environment is the local one. `localConnectionString` is what
// `wrangler dev` uses, so a checkout with `docker compose up postgres`
// running needs nothing else; `id` is only read on deploy, and the two
// named environments below carry their own.
"hyperdrive": [
{
"binding": "HYPERDRIVE",
"id": "0000000000000000000000000000dev0",
"localConnectionString": "postgres://postgres:postgres@localhost:5432/nestri"
}
],
"env": {
"sandbox": {
"name": "nestri-auth-sandbox",
"workers_dev": false,
"routes": [{ "pattern": "auth-sandbox.nestri.io", "custom_domain": true }],
"observability": { "enabled": true },
"hyperdrive": [{ "binding": "HYPERDRIVE", "id": "<sandbox-hyperdrive-id>" }]
},
"production": {
"name": "nestri-auth",
"workers_dev": false,
"routes": [{ "pattern": "auth.nestri.io", "custom_domain": true }],
"observability": { "enabled": true },
"hyperdrive": [{ "binding": "HYPERDRIVE", "id": "<production-hyperdrive-id>" }]
}
}
}