Add an infra/ Pulumi (Go) program in its own module (github.com/JMR-dev/LibreMail-Bug-Report-Ingest/infra) that declares the three pieces of edge/DNS infrastructure for the bug-report ingest pipeline: - Cloudflare Worker script (libremail-bug-report-ingest, built in #1) - Cloudflare R2 bucket (libremail-bug-reports) for encrypted reports (ADR 0001) - Google Cloud DNS record (CNAME) pointing the ingest hostname at the Worker, referencing an existing managed zone by name Per-environment stacks (dev/prod) via Pulumi.<stack>.yaml + pulumi.Config; account id, zone, domain, etc. are parameterized through config and secrets are kept out of git (documented in infra/README.md). Worker content is a documented placeholder because the real TinyGo->Wasm artifact is produced by the build pipeline. Mock-based unit tests (pulumi.RunErr + pulumi.WithMocks) assert the registered resources and their inputs; go build + go vet + go test all pass without the Pulumi CLI. Structured so the #7 Cloudflare Rate Limiting ruleset can be added later (reserved cloudflareZoneId config + insertion point in deploy.go). Providers: pulumi-cloudflare v6.17.0, pulumi-gcp v8.41.1, pulumi/sdk v3.250.0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
31 lines
1.8 KiB
YAML
31 lines
1.8 KiB
YAML
# Dev stack configuration.
|
|
#
|
|
# NON-SECRET values only. Secrets (Cloudflare API token, GCP credentials) are set
|
|
# with `pulumi config set --secret ...` (they land here ENCRYPTED) or supplied via
|
|
# provider environment variables. NEVER commit a plaintext secret. See README.md.
|
|
#
|
|
# Replace every REPLACE_ME_* value below with your real dev account/zone/domain
|
|
# before running `pulumi up`.
|
|
config:
|
|
# --- GCP provider (see also GOOGLE_CREDENTIALS / gcp:credentials) ---
|
|
gcp:project: REPLACE_ME_GCP_PROJECT_ID
|
|
|
|
# --- Program config (namespace = project name from Pulumi.yaml) ---
|
|
libremail-bug-report-ingest-infra:cloudflareAccountId: REPLACE_ME_CLOUDFLARE_ACCOUNT_ID
|
|
libremail-bug-report-ingest-infra:workerName: libremail-bug-report-ingest
|
|
libremail-bug-report-ingest-infra:workerCompatibilityDate: "2025-06-01"
|
|
libremail-bug-report-ingest-infra:r2BucketName: libremail-bug-reports-dev
|
|
# R2 location hint (optional). One of: apac, eeur, enam, weur, wnam, oc.
|
|
libremail-bug-report-ingest-infra:r2BucketLocation: enam
|
|
# Google Cloud DNS managed-zone NAME (the zone already exists; it is referenced,
|
|
# not created, by this stack).
|
|
libremail-bug-report-ingest-infra:dnsManagedZone: REPLACE_ME_GCLOUD_DNS_MANAGED_ZONE_NAME
|
|
# Ingest hostname (FQDN, trailing dot) and the Worker route/custom-domain it
|
|
# points at (CNAME target, FQDN, trailing dot).
|
|
libremail-bug-report-ingest-infra:dnsRecordName: bugreport.dev.libremail.example.
|
|
libremail-bug-report-ingest-infra:dnsRecordType: CNAME
|
|
libremail-bug-report-ingest-infra:dnsRecordTarget: libremail-bug-report-ingest.REPLACE_ME_SUBDOMAIN.workers.dev.
|
|
libremail-bug-report-ingest-infra:dnsTtlSeconds: "300"
|
|
# Optional, reserved for #7 (rate-limit ruleset) and Worker routes/custom domain:
|
|
# libremail-bug-report-ingest-infra:cloudflareZoneId: REPLACE_ME_CLOUDFLARE_ZONE_ID
|