Add an infra/ Pulumi (Go) program in its own module (github.com/JMR-dev/LibreMail-Bug-Report-Ingest/infra) that declares the three pieces of edge/DNS infrastructure for the bug-report ingest pipeline: - Cloudflare Worker script (libremail-bug-report-ingest, built in #1) - Cloudflare R2 bucket (libremail-bug-reports) for encrypted reports (ADR 0001) - Google Cloud DNS record (CNAME) pointing the ingest hostname at the Worker, referencing an existing managed zone by name Per-environment stacks (dev/prod) via Pulumi.<stack>.yaml + pulumi.Config; account id, zone, domain, etc. are parameterized through config and secrets are kept out of git (documented in infra/README.md). Worker content is a documented placeholder because the real TinyGo->Wasm artifact is produced by the build pipeline. Mock-based unit tests (pulumi.RunErr + pulumi.WithMocks) assert the registered resources and their inputs; go build + go vet + go test all pass without the Pulumi CLI. Structured so the #7 Cloudflare Rate Limiting ruleset can be added later (reserved cloudflareZoneId config + insertion point in deploy.go). Providers: pulumi-cloudflare v6.17.0, pulumi-gcp v8.41.1, pulumi/sdk v3.250.0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
10 lines
497 B
YAML
10 lines
497 B
YAML
name: libremail-bug-report-ingest-infra
|
|
runtime: go
|
|
description: >-
|
|
Pulumi (Go) infrastructure for the LibreMail bug-report ingest pipeline:
|
|
the Cloudflare Worker, the encrypted-report Cloudflare R2 bucket, and the
|
|
Google Cloud DNS record that points the ingest hostname at the Worker.
|
|
Secrets (Cloudflare API token, GCP credentials) live in the stack config as
|
|
Pulumi secrets / in the provider environment and are never committed. See
|
|
README.md for the full config + secret contract.
|