a0152f9c989b901f3868906043b35f8553248c4e
Add docs/decisions/labels-and-abuse.md fixing concrete values that unblock #14 and inform #7: - Labels on auto-published issues (JMR-dev/LibreMail): bug-report, automated, needs-triage. #14 must create any missing. - Ingest policy: 256 KiB payload cap (413); per-IP 15/60s + 100/1h rate limits (429 + Retry-After) via Cloudflare Rate Limiting rules in Pulumi; full response-code contract (202/400/413/415/405/429/5xx). - Weekly publish job: 50 issues/run cap; serial creation, 1s spacing, Retry-After honoured, exponential backoff (base 1s, cap 60s, jitter, max 5 attempts), mark-published-on-confirm de-dup. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
LibreMail Bug Report Ingest
Server-side infrastructure for LibreMail's debug bug-report pipeline. This repo is intentionally separate from the Android app repo — it owns the Cloudflare Worker and infrastructure-as-code, not the client.
What this is
Per JMR-dev/LibreMail#11:
- The LibreMail app lets a user opt in to submitting a debug report (LibreMail#33).
- A Cloudflare Worker in this repo receives the report over HTTPS, best-effort scrubs PII, and stores it encrypted in a Cloudflare R2 bucket (#34).
- Every Friday at 17:00 (Central Time, DST-aware), a scheduled job publishes any report not manually removed as a GitHub issue on the LibreMail repo (#35).
Stack
- Worker: Go
- Infrastructure as code: Pulumi (Go)
- Deployment: GitHub Actions
- Secrets/key custody: Cloudflare Secret Manager
- DNS: Google Cloud DNS
Status
Early bootstrap. See the project board and open issues for the current breakdown of work.
License
Languages
Go
100%