{ // ── Cloudflare Workers config template for emailflare ──────────────────────── // // ⚠ This is a TEMPLATE. It is tracked in git and contains REPLACE_WITH_* // placeholders. Do NOT put real resource IDs here. // // The setup script (scripts/setup.mjs / `just emailflare-api-worker-setup`) // generates the gitignored `wrangler.jsonc` from this template with your real IDs. // // ★ FIRST-TIME SETUP — one command does everything: // just emailflare-api-worker-setup // (creates D1 + KV, generates wrangler.jsonc, applies migrations, sets secrets, deploys) // // ★ DEPLOY UPDATES — migrates schema then redeploys atomically: // just emailflare-api-worker-update // // ★ GRADUAL ROLLOUT — upload a version and control traffic split: // pnpm rollout:upload # apply migrations + upload new version // wrangler versions deploy \ // --version-percentage =10 # 10 % traffic // wrangler versions deploy \ // --version-percentage =100 # full cutover // // Manual setup (if needed): // 1. `wrangler d1 create emailflare` → fill in database_id below // 2. `wrangler kv namespace create emailflare-api-rate-limit` → fill in id below // 3. `pnpm migrations:apply:local` → init local dev DB // 4. Set secrets: // wrangler secret put ADMIN_TOKEN (min 32 chars) // wrangler secret put SESSION_SECRET (min 32 chars) // wrangler secret put CF_API_TOKEN (CF token: Email Send + Zone + DNS) // wrangler secret put CF_ACCOUNT_ID (your CF account ID) // wrangler secret put ADMIN_ORIGIN (e.g. "https://admin.example.com") "$schema": "node_modules/wrangler/config-schema.json", "name": "emailflare-api-worker", "main": "src/index.ts", "compatibility_date": "2025-05-01", "compatibility_flags": ["nodejs_compat"], "workers_dev": true, "preview_urls": false, "observability": { "enabled": true, "head_sampling_rate": 1, }, // Upload source maps so stack traces in the Cloudflare dashboard are readable "upload_source_maps": true, // Static assets: the built admin SPA is served from the Worker itself. // All unmatched routes fall through to index.html (SPA mode). // Build email-ui first: cd services/email-ui && pnpm build "assets": { "directory": "../email-ui/dist", "binding": "ASSETS", "not_found_handling": "single-page-application", }, // D1 SQLite database "d1_databases": [ { "binding": "DB", "database_name": "emailflare", "database_id": "REPLACE_WITH_D1_DATABASE_ID", "migrations_dir": "../../migrations", }, ], // KV for IP-based login rate limiting "kv_namespaces": [ { "binding": "RATE_LIMIT_KV", "id": "REPLACE_WITH_KV_NAMESPACE_ID", }, ], // No hardcoded env vars here — all account/deployment-specific values are set // via `wrangler secret put` (see scripts/setup.mjs + scripts/config.toml). // For local `wrangler dev`, copy .dev.vars.example → .dev.vars and fill in. // Workers Rate Limiting for API key calls (100 req / 60s per key) // Requires Workers Paid plan. Remove this block to disable. "unsafe": { "bindings": [ { "name": "RATE_LIMITER", "type": "ratelimit", "namespace_id": "1001", "simple": { "limit": 100, "period": 60, }, }, ], }, }