Files
netris-nestri/apps/api/wrangler.jsonc
T
Wanjohi 065af689b3 feat(api): serve the host installer and its downloads
GET /install.sh serves a POSIX script, embedded in the API at build time
so the script and the routes that redeem its token ship together. It
checks the platform, asks where box images should live, downloads the
host agent at a pinned version, verifies it against SHA256SUMS, installs
it for the calling user and hands over with the token in the environment
rather than argv.

GET /install/:component/:version/:asset redirects to a one-minute signed
URL on a private S3-compatible bucket, so every download passes through a
route that can be logged or switched off. The SigV4 signer is written
against Web Crypto and checked against AWS's published example.
2026-09-28 09:12:23 +03:00

76 lines
3.1 KiB
JSON

// The public API, deployed as a Cloudflare Worker.
//
// The same `app/index.ts` also runs as an ordinary HTTP server — see
// `app/server.ts` and the `Dockerfile` beside it.
//
// Hostnames and the reasoning behind their shape: `docs/dns.md`.
// Secrets, the Hyperdrive id, and how to deploy: `docs/deploy.md`.
{
"$schema": "node_modules/wrangler/config-schema.json",
"name": "nestri-api",
"main": "app/index.ts",
// The installer is imported as text and served at /install.sh.
"rules": [{ "type": "Text", "globs": ["**/*.sh"], "fallthrough": false }],
"compatibility_date": "2026-09-05",
"compatibility_flags": ["nodejs_compat"],
"workers_dev": false,
// `ip` is pinned rather than left to default. Wrangler otherwise binds
// whatever `localhost` resolves to, which is `::1` first on most systems
// — and a host with no IPv6 address on its loopback interface fails to
// start at all, with a bind error from deep inside the runtime rather
// than anything naming a port.
"dev": {
"ip": "127.0.0.1",
"port": 3000,
// Distinct per app. Both dev servers run at once and the debugger
// port is not derived from the one above, so leaving it default
// meant the second to start died on an address already in use.
"inspector_port": 9230
},
// `AUTH` routes by binding rather than by hostname, so it is one hop
// shorter than a request over the internet and needs no public address.
// It is an optimisation and not a requirement: with no such binding the
// middleware reaches the issuer over plain HTTP at `AUTH_ISSUER_URL`,
// which is what the container path does.
//
// `wrangler dev` discovers a sibling session serving the same script name,
// so running both dev servers wires this up locally.
"services": [{ "binding": "AUTH", "service": "nestri-auth" }],
"hyperdrive": [
{
"binding": "HYPERDRIVE",
"id": "0000000000000000000000000000dev0",
"localConnectionString": "postgres://postgres:postgres@localhost:5432/nestri"
}
],
"vars": {
// The issuer's **public** URL, always. A token's `iss` claim carries
// the address it was minted through, and verification compares the two
// literally — so naming the binding here instead would reject every
// real token, and report it as an ordinary 401.
"AUTH_ISSUER_URL": "http://localhost:1337"
},
"env": {
"sandbox": {
"name": "nestri-api-sandbox",
"workers_dev": false,
"routes": [{ "pattern": "api.sandbox.nestri.io", "custom_domain": true }],
"observability": { "enabled": true },
"services": [{ "binding": "AUTH", "service": "nestri-auth-sandbox" }],
"hyperdrive": [{ "binding": "HYPERDRIVE", "id": "<sandbox-hyperdrive-id>" }],
"vars": { "AUTH_ISSUER_URL": "https://auth.sandbox.nestri.io" }
},
"production": {
"name": "nestri-api",
"workers_dev": false,
"routes": [{ "pattern": "api.nestri.io", "custom_domain": true }],
"observability": { "enabled": true },
"services": [{ "binding": "AUTH", "service": "nestri-auth" }],
"hyperdrive": [{ "binding": "HYPERDRIVE", "id": "<production-hyperdrive-id>" }],
"vars": { "AUTH_ISSUER_URL": "https://auth.nestri.io" }
}
}
}