name = "reminal-relay" main = "src/index.ts" compatibility_date = "2024-11-01" compatibility_flags = ["nodejs_compat"] # Pinned so `wrangler deploy` errors out instead of silently shipping # to whichever Cloudflare account happens to be logged in. Belongs to # harshalg98@gmail.com (the everything-account). Forks must replace this value # with their own account ID before deploying. account_id = "0cd85a1166e44b17571b7457040d18ae" # live.reminal.app is the public viewer and relay. The previous public # hostname stays bound so already-running agents are not cut off. workers_dev = true # Keep this ABOVE [assets]: TOML binds every key after a table header to # that table — put it below and wrangler parses it as assets.routes. routes = [ { pattern = "live.reminal.app", custom_domain = true }, # Subdomain-per-tunnel: each `reminal expose` is served at port-.reminal.app # so the forwarded app sits at its own origin root (absolute paths / service # workers / same-origin work). Cloudflare only allows a wildcard at the START # of the host, so the route is *.reminal.app/* — but that's safe: the marketing # site (reminal.app/*, www.reminal.app/* -> reminal-site) and live.reminal.app # (custom domain) are MORE specific and win, so this only ever catches # port- and other undefined subdomains. The port- scoping lives in the # worker code (index.ts). Relies on the proxied *.reminal.app DNS record. { pattern = "*.reminal.app/*", zone_name = "reminal.app" }, ] [durable_objects] bindings = [ { name = "SESSION", class_name = "SessionRoom" }, { name = "RENDEZVOUS", class_name = "RendezvousRoom" } ] [[migrations]] tag = "v1" new_sqlite_classes = ["SessionRoom"] [[migrations]] tag = "v2" new_sqlite_classes = ["RendezvousRoom"] [assets] directory = "./public" binding = "ASSETS" # Run the Worker BEFORE serving a static asset. Without this, a request whose # path matches a file in ./public (notably "/" -> index.html) is served the # viewer directly and the Worker never runs — which meant port-.reminal.app/ # served the viewer instead of the tunnelled app's root. With it, the Worker # routes tunnel hosts first and falls through to env.ASSETS.fetch() for everything # else (live.reminal.app still gets the viewer, via the fall-through). run_worker_first = true [vars] # Version below which reminal clients FORCE an upgrade (served at /version). Set # to the fixed version when shipping a security/critical release, then `wrangler # deploy` — clients pick it up on their next ≤24h check and upgrade automatically # (no `--force`). Leave "" for normal (prompt-only) releases. CRITICAL_MIN = "" # Public half of the push signing key (VAPID). Browsers subscribe with it and # push services check each alert's signature against it; the private half is # the VAPID_PRIVATE_JWK secret (`wrangler secret put VAPID_PRIVATE_JWK`). # Changing this pair invalidates every browser's alert subscription, so treat # it like the signing cert: generate once, keep. VAPID_PUBLIC = "BLCthPsa5_VDrbVEMtDk6NUXowUbqY8n2hetWbpzjg-hR6-FC-nWC85emykddL6mqTx3P1jfaewicVW5237_YC4"