Skip to content

Cloudflare ​

Read before changing media or the edge

  1. This page · 2. packages/data/README.md (the media seam) · 3. ADR-0027 — purge on write for the cache half. The machine contract for media is this page's context: frontmatter; .claude/rules/domains/media.md is GENERATED from it. Gates: npm test · test:ef · a real image through the run-web / run-mobile drivers. Your plan must answer: which stage of the upload path changes (pick → presign → PUT → record → compose); whether any URL is composed from a fabricated base; whether the R2 CORS file in the repo has actually been applied to the bucket. Related domains: setu-card · edge-functions · data-seam. Machine reads (the manifest's reads, in order): documentation/portal/integrations/cloudflare.md · packages/data/README.md.

The cache-ops mechanism described here is retired (2026-08-08)

public_page_ops_cache_refresh / _cache_invalidate / _health_check and their pg_cron schedules are superseded by the transactional outbox — their tables were dropped from Dev on 2026-08-08 and the Edge Functions are orphaned. The purge-by-tag contract itself is unchanged: a write enqueues an outbox row, the worker purges card-{slug} plus the OG raster.

⚠ And the gap this page has always understated: no write path calls invalidation at all today. Verified — zero cache/cloudflare/invalidate references in manage-profile, manage-settings or manage-reminder. So a vendor who edits their card currently sees no change on the public side, which reads as a broken product rather than a stale cache. That is QRS-350/351 and it must land before any card-affecting write path ships. Also note the scheduled purge requirement from ADR-0025: a campaign boundary is the first render-time temporal gate, and it is handled by a scheduled outbox row, never a short TTL.

Hosting + CDN + cache purge. Three Pages projects (DEV / UAT / PROD).

Roles ​

CapabilityUse
PagesHosts the built SPA (dist/). One project per env; "Production branch" renamed dev/uat/production.
CDN cachePublic pages cached at the edge — target hit-rate >95%.
Cache purge APICalled from Edge Functions (_shared/cloudflare.ts) to invalidate/refresh.
wranglerDeploy tooling (a devDependency).

Cache lifecycle (public_page_ops) ​

The four Type B functions: public_page_ops_cache_refresh, public_page_ops_cache_invalidate, public_page_ops_health_check, public_page_ops_metrics_collector. See the EF index and documentation/public-page-ops/.

Secrets ​

CLOUDFLARE_API_TOKEN, CLOUDFLARE_ZONE_ID — documented in .env.example, set per Supabase project.

Gotchas ​

  • "Production branch" must be renamed per project (dev/uat/production) or deploys target the wrong env.
  • Bot Fight Mode can return 403 to smoke checks — allowlist the checker.
  • Security headers / CSP are applied at the edge — see Security.

See Environment Strategy · Deployment & Promotion.