Server side of bug reporting: a Cloudflare Worker receives reports from the app (#33),
best-effort anonymizes PII, stores them encrypted in R2, and every Friday at 5pm publishes
any not-yet-removed reports as GitHub issues. Lives in separate infrastructure, not the
Android app repo.
Spec
When a user submits a debug report, the issue should be received by a Cloudflare worker. The
worker will run a program to best effort anonymize the data / remove PII. Then the
information will be stored in a Cloudflare R2 bucket for review in an encrypted state. Every
Friday at 5pm, any issues not removed will be automatically submitted as GitHub issues to the
project.
#35 — weekly (Fri 17:00 Central Time [slides with DST] ) cron publishes remaining reports as GitHub issues
Open questions
Encryption scheme + key custody for R2 objects.
Target GitHub label(s); abuse / rate limiting.
Technical Details
Worker written in Go
Pulimi IaaC written in Go
Deployment from GitHub Actions
Key custody in Cloudflare's Secret Manager
DNS managed in Google Cloud DNS
Notes
The privacy posture must be documented for F-Droid (#16) and the README (#20). The client
side is #10. Submission is user-initiated only (#33) — the Worker never pulls from devices.
## Summary
Server side of bug reporting: a Cloudflare Worker receives reports from the app (#33),
best-effort anonymizes PII, stores them encrypted in R2, and every Friday at 5pm publishes
any not-yet-removed reports as GitHub issues. Lives in **separate infrastructure**, not the
Android app repo.
## Spec
When a user submits a debug report, the issue should be received by a Cloudflare worker. The
worker will run a program to best effort anonymize the data / remove PII. Then the
information will be stored in a Cloudflare R2 bucket for review in an encrypted state. Every
Friday at 5pm, any issues not removed will be automatically submitted as GitHub issues to the
project.
## Breakdown
- [ ] #34 — Worker ingest + PII anonymization + encrypted R2 storage
- [ ] #35 — weekly (Fri 17:00 Central Time [slides with DST] ) cron publishes remaining reports as GitHub issues
## Open questions
- Encryption scheme + key custody for R2 objects.
- Target GitHub label(s); abuse / rate limiting.
Technical Details
- Worker written in Go
- Pulimi IaaC written in Go
- Deployment from GitHub Actions
- Key custody in Cloudflare's Secret Manager
- DNS managed in Google Cloud DNS
## Notes
The privacy posture must be documented for F-Droid (#16) and the README (#20). The client
side is #10. Submission is user-initiated only (#33) — the Worker never pulls from devices.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Server side of bug reporting: a Cloudflare Worker receives reports from the app (#33),
best-effort anonymizes PII, stores them encrypted in R2, and every Friday at 5pm publishes
any not-yet-removed reports as GitHub issues. Lives in separate infrastructure, not the
Android app repo.
Spec
When a user submits a debug report, the issue should be received by a Cloudflare worker. The
worker will run a program to best effort anonymize the data / remove PII. Then the
information will be stored in a Cloudflare R2 bucket for review in an encrypted state. Every
Friday at 5pm, any issues not removed will be automatically submitted as GitHub issues to the
project.
Breakdown
Open questions
Technical Details
Notes
The privacy posture must be documented for F-Droid (#16) and the README (#20). The client
side is #10. Submission is user-initiated only (#33) — the Worker never pulls from devices.