Files
LibreMail-Bug-Report-Ingest/infra/main.go
T
JMR-devandClaude Opus 4.8 21665b172d #2 Pulumi IaC scaffolding: Worker, R2 bucket, Google Cloud DNS
Add an infra/ Pulumi (Go) program in its own module
(github.com/JMR-dev/LibreMail-Bug-Report-Ingest/infra) that declares the
three pieces of edge/DNS infrastructure for the bug-report ingest pipeline:

- Cloudflare Worker script (libremail-bug-report-ingest, built in #1)
- Cloudflare R2 bucket (libremail-bug-reports) for encrypted reports (ADR 0001)
- Google Cloud DNS record (CNAME) pointing the ingest hostname at the Worker,
  referencing an existing managed zone by name

Per-environment stacks (dev/prod) via Pulumi.<stack>.yaml + pulumi.Config;
account id, zone, domain, etc. are parameterized through config and secrets
are kept out of git (documented in infra/README.md). Worker content is a
documented placeholder because the real TinyGo->Wasm artifact is produced by
the build pipeline.

Mock-based unit tests (pulumi.RunErr + pulumi.WithMocks) assert the registered
resources and their inputs; go build + go vet + go test all pass without the
Pulumi CLI. Structured so the #7 Cloudflare Rate Limiting ruleset can be added
later (reserved cloudflareZoneId config + insertion point in deploy.go).

Providers: pulumi-cloudflare v6.17.0, pulumi-gcp v8.41.1, pulumi/sdk v3.250.0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:45:07 -05:00

20 lines
773 B
Go

// Command infra is the Pulumi (Go) entrypoint for the LibreMail bug-report
// ingest infrastructure.
//
// It provisions the three pieces of edge/DNS infrastructure the pipeline needs:
//
// - the Cloudflare Worker script that receives bug reports (built in #1),
// - the Cloudflare R2 bucket that stores the encrypted reports (ADR 0001),
// - the Google Cloud DNS record that points the ingest hostname at the Worker.
//
// The program is a thin wrapper: all resource wiring lives in deploy, which is
// exercised directly by the mock-based unit tests in deploy_test.go (no Pulumi
// CLI required). See infra/README.md for the config/secrets a deployer supplies.
package main
import "github.com/pulumi/pulumi/sdk/v3/go/pulumi"
func main() {
pulumi.Run(deploy)
}