mirror of
https://github.com/nestriness/nestri.git
synced 2026-09-19 17:25:19 +03:00
Moving the issuer's state into Postgres removed the last thing that tied either app to one hosting provider. What was left was a deployment tool describing resources that no longer existed — so this replaces it with `wrangler`, which is what actually deploys a Worker, and adds a second way to run each app that involves no provider at all. Each app now has a `wrangler.jsonc` with an environment per stage, and a `Dockerfile` beside it. The handler is the same one in both cases; what differs is only where its settings come from. Two of them gained a second spelling so that nothing has to branch on the runtime: Postgres arrives as a pooled binding or as `DATABASE_URL`, and the route to the issuer is a service binding or `AUTH_INTERNAL_URL`. That last one is new, and it is a split the binding was already making without saying so. `AUTH_ISSUER_URL` has to be the issuer's public name, because it is compared literally against every token's `iss` claim — but the public name is often not routable from inside a deployment. So the name and the route are two settings now rather than one that cannot be both. DNS moves out of code and into `docs/dns.md`, which lists every hostname and what it is for. Six records that change roughly never did not need a tool, and the table outlives whatever is answering the names — which is the point, since some of them will stop being Workers. The sandbox hostnames are hyphenated rather than nested for the same reason: a certificate covering `*.nestri.io` covers one label and not two, so `api-sandbox.nestri.io` can become an ordinary origin later without a certificate having to be ordered for it first. Also drops `EMAIL_DEV_LOG` from committed configuration into `.dev.vars`, which `wrangler deploy` cannot upload. Printing a live sign-in code to a log should not be one forgotten override away from production.
50 lines
859 B
Plaintext
50 lines
859 B
Plaintext
node_modules
|
|
|
|
# Output
|
|
.output
|
|
.vercel
|
|
.netlify
|
|
.wrangler
|
|
.svelte-kit
|
|
# JS-framework build-output dirs, at any depth — but not the top-level
|
|
# build/ directory, which is the guest rootfs build (see build/README.md),
|
|
# a real source tree we want tracked.
|
|
**/build
|
|
!/build
|
|
|
|
# Rust
|
|
/target
|
|
**/*.rs.bk
|
|
|
|
# build/'s own output — the packed rootfs images, not source
|
|
/build/output/
|
|
|
|
# OS
|
|
.DS_Store
|
|
Thumbs.db
|
|
|
|
# Env
|
|
.env
|
|
.env.*
|
|
!.env.example
|
|
!.env.test
|
|
|
|
# Vite
|
|
vite.config.js.timestamp-*
|
|
vite.config.ts.timestamp-*
|
|
|
|
dist
|
|
.lunora/
|
|
.lunora-cache
|
|
lunora/_generated
|
|
|
|
#turbo
|
|
.turbo
|
|
|
|
# nesdoctor writes its report next to wherever it is run, and it is run from
|
|
# the repository root during development. It contains the operator's own
|
|
# machine: home paths, installed game titles, launch times. Committed once by
|
|
# accident; never again.
|
|
nesdoctor.json
|
|
*.nesdoctor.json
|