mirror of
https://github.com/nestriness/nestri.git
synced 2026-09-19 09:15:19 +03:00
Moving the issuer's state into Postgres removed the last thing that tied either app to one hosting provider. What was left was a deployment tool describing resources that no longer existed — so this replaces it with `wrangler`, which is what actually deploys a Worker, and adds a second way to run each app that involves no provider at all. Each app now has a `wrangler.jsonc` with an environment per stage, and a `Dockerfile` beside it. The handler is the same one in both cases; what differs is only where its settings come from. Two of them gained a second spelling so that nothing has to branch on the runtime: Postgres arrives as a pooled binding or as `DATABASE_URL`, and the route to the issuer is a service binding or `AUTH_INTERNAL_URL`. That last one is new, and it is a split the binding was already making without saying so. `AUTH_ISSUER_URL` has to be the issuer's public name, because it is compared literally against every token's `iss` claim — but the public name is often not routable from inside a deployment. So the name and the route are two settings now rather than one that cannot be both. DNS moves out of code and into `docs/dns.md`, which lists every hostname and what it is for. Six records that change roughly never did not need a tool, and the table outlives whatever is answering the names — which is the point, since some of them will stop being Workers. The sandbox hostnames are hyphenated rather than nested for the same reason: a certificate covering `*.nestri.io` covers one label and not two, so `api-sandbox.nestri.io` can become an ordinary origin later without a certificate having to be ordered for it first. Also drops `EMAIL_DEV_LOG` from committed configuration into `.dev.vars`, which `wrangler deploy` cannot upload. Printing a live sign-in code to a log should not be one forgotten override away from production.
40 lines
1.1 KiB
JSON
40 lines
1.1 KiB
JSON
{
|
|
"name": "nestri",
|
|
"private": true,
|
|
"license": "Apache-2.0",
|
|
"workspaces": {
|
|
"packages": [
|
|
"apps/*",
|
|
"packages/*"
|
|
],
|
|
"catalog": {
|
|
"@cloudflare/workers-types": "^5.20260722.1",
|
|
"@tsconfig/node22": "^22.0.5",
|
|
"@types/bun": "latest",
|
|
"@types/node": "^26.1.1",
|
|
"hono": "^4.12.31",
|
|
"typescript": "^7.0.1-rc",
|
|
"zod": "^4.4.3"
|
|
}
|
|
},
|
|
"type": "module",
|
|
"scripts": {
|
|
"dev": "wrangler dev -c apps/auth/wrangler.jsonc -c apps/api/wrangler.jsonc",
|
|
"dev:server": "bun run --cwd apps/auth serve & bun run --cwd apps/api serve",
|
|
"dev:docker": "docker compose up --build",
|
|
"db:migrate": "bun run --cwd packages/core db:migrate",
|
|
"db:push": "bun run --cwd packages/core db:push",
|
|
"test": "test",
|
|
"deploy:sandbox": "wrangler deploy -c apps/auth/wrangler.jsonc -e sandbox && wrangler deploy -c apps/api/wrangler.jsonc -e sandbox",
|
|
"deploy:production": "wrangler deploy -c apps/auth/wrangler.jsonc -e production && wrangler deploy -c apps/api/wrangler.jsonc -e production"
|
|
},
|
|
"devDependencies": {
|
|
"oxfmt": "^0.61.0",
|
|
"oxlint": "^1.76.0",
|
|
"wrangler": "^4.45.0"
|
|
},
|
|
"peerDependencies": {
|
|
"typescript": "catalog:"
|
|
}
|
|
}
|