Files
LibreMail-Bug-Report-Ingest/infra/Pulumi.yaml
T
JMR-devandClaude Opus 4.8 21665b172d #2 Pulumi IaC scaffolding: Worker, R2 bucket, Google Cloud DNS
Add an infra/ Pulumi (Go) program in its own module
(github.com/JMR-dev/LibreMail-Bug-Report-Ingest/infra) that declares the
three pieces of edge/DNS infrastructure for the bug-report ingest pipeline:

- Cloudflare Worker script (libremail-bug-report-ingest, built in #1)
- Cloudflare R2 bucket (libremail-bug-reports) for encrypted reports (ADR 0001)
- Google Cloud DNS record (CNAME) pointing the ingest hostname at the Worker,
  referencing an existing managed zone by name

Per-environment stacks (dev/prod) via Pulumi.<stack>.yaml + pulumi.Config;
account id, zone, domain, etc. are parameterized through config and secrets
are kept out of git (documented in infra/README.md). Worker content is a
documented placeholder because the real TinyGo->Wasm artifact is produced by
the build pipeline.

Mock-based unit tests (pulumi.RunErr + pulumi.WithMocks) assert the registered
resources and their inputs; go build + go vet + go test all pass without the
Pulumi CLI. Structured so the #7 Cloudflare Rate Limiting ruleset can be added
later (reserved cloudflareZoneId config + insertion point in deploy.go).

Providers: pulumi-cloudflare v6.17.0, pulumi-gcp v8.41.1, pulumi/sdk v3.250.0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:45:07 -05:00

10 lines
497 B
YAML

name: libremail-bug-report-ingest-infra
runtime: go
description: >-
Pulumi (Go) infrastructure for the LibreMail bug-report ingest pipeline:
the Cloudflare Worker, the encrypted-report Cloudflare R2 bucket, and the
Google Cloud DNS record that points the ingest hostname at the Worker.
Secrets (Cloudflare API token, GCP credentials) live in the stack config as
Pulumi secrets / in the provider environment and are never committed. See
README.md for the full config + secret contract.