Repository navigation
Add Cloudflare DNS and Turnstile to Terraform - #623
Conversation
|
Orchestrator The env group updates add only |
There was a problem hiding this comment.
Important
Verify the new authoritative DNS answers before changing the registrar delegation; the current sequence discovers missing or incorrect records only after they affect live traffic.
Reviewed changes Terraform provisioning and cutover guidance for Cloudflare DNS and Turnstile:
- DNS zone and records: Adds a full Cloudflare zone, Free subscription, existing DNS records, and staging Render CNAMEs.
- Turnstile delivery: Creates a widget and passes its secret through SSM to both API environment groups, with nameserver and site-key outputs.
- Cutover tooling: Documents deployment and adds a script comparing existing Spaceship DNS answers with Cloudflare answers.
GPT Sol | 𝕏
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes Re-reviewed the DNS cutover instructions changed since the prior Pullfrog review.
- Pre-delegation verification: Moved the DNS comparison ahead of the registrar switch, requiring both assigned Cloudflare nameservers to match Spaceship before delegation and checking again after propagation.
GPT Sol | 𝕏
|
) * Add Render Terraform for production and staging (#621) * Add Terraform for Render production and staging * Handle Render database URLs without explicit ports * Keep production intact through the first apply and isolate staging integrations The imported API service ignores its own env_vars so the first apply only adds and links the environment group, and the existing Render project is imported (environments keyed by their live names) so the API stays in its Production environment while a Staging environment is added. Staging gets placeholder Stripe identifiers, staging return URLs, its own redirect allowlist and an invalid Supabase host, so it cannot touch production billing or storage. Empty custom domain lists become null, the landing no longer auto-deploys, and the web health check uses /api/health. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 1480d1b) * Store confirmed waitlist contacts in Orbit database (#620) * feat: store confirmed waitlist marketing contacts locally * fix: preserve marketing opt-outs and canonicalize waitlist languages * Restore user marketing delivery after explicit opt-in (cherry picked from commit 4c7b76a) * Add Google authorization code sign in (#622) * Implement Google authorization code sign in for ticket 796 * Register Google code routes in agent catalog * Parse Google token responses with installed SDK * fix: retry Google code sign-in after redemption (cherry picked from commit 2301ccc) * Add Cloudflare DNS and Turnstile to Terraform (#623) * Add Cloudflare DNS and Turnstile Terraform resources * Verify Cloudflare DNS answers before the registrar switch Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 7e946a6) * Gate production API releases through Render (#624) * Add gated production API release workflow * Handle queued Render deploys and recheck the live commit before recording a release Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 78b42f2) * Keep Terraform from reverting web release digests (#627) * fix: preserve workflow deployed web digests in Terraform * docs: guard web service applies against Render image tag bug (cherry picked from commit b8ea2c1) * Configure staging billing from SSM and verify test purchases (#629) (cherry picked from commit 5e5623e) * Align Google code error assertion with redesign response --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>




Closes thomasluizon/orbit-tickets#804
Change
infra/versions.tfand added the fulluseorbit.orgzone and explicit Free subscription ininfra/cloudflare.tf.www, andapptargets are variables with the current values as defaults. Staging CNAMEs derive their targets from the Render staging services.infra/configuration.tf. The public site key and assigned nameservers are Terraform outputs. No enforcement setting changes.infra/README.mdand addedinfra/check-dns-cutover.shto compare DNS answers after the registrar switch. The provider lock file records the exact plugin build.The existing records share one map so their TTL and proxy policy is uniform. The staging records use the Render resource URLs so their assigned hostnames do not have to be guessed.
Verification
terraform fmt -check -recursive infra: passed.terraform -chdir=infra validate -no-color: passed.local.existing_dns_recordsthroughterraform console; all 16 entries matcheddig @launch1.spaceship.netanswers, including MX priorities and the Google DKIM value.bash infra/check-dns-cutover.sh launch1.spaceship.net: passed as a script check. The Cloudflare comparison runs after apply and the nameserver switch.dotnet build Orbit.slnx: 0 errors.dotnet test Orbit.slnx --no-build --verbosity quiet: 6,756 passed, 0 failed.External interface evidence
terraform -chdir=infra providers schema -jsonexposescloudflare_zone.idandname_servers,cloudflare_turnstile_widget.sitekeyand sensitivesecret, andcloudflare_zone_subscription.rate_plan.idwithfreeas an allowed value. It defines DNS TTL1as automatic. The zone and widget do not exist yet, so there is no live resource response to inspect before apply.aws_ssm_parameter.valuesensitive. The installed Render 1.9.1 schema marksrender_env_group.env_vars.valuesensitive and exposes computedrender_web_service.url.terraform -chdir=infra show -json | jq -r '.values.root_module.resources[] | select(.address == "render_web_service.staging_api") | .values.url'returnedhttps://orbit-api-staging-uqu2.onrender.com. The staging web service is not in state yet; it uses the same Render resource schema.Assumptions
Manual steps
CLOUDFLARE_API_TOKENfrom the macOS Keychain item with serviceorbit-cloudflare-api-token. A successfulterraform -chdir=infra plan -var-file=local.tfvarsproves the provider can authenticate. The existingRENDER_API_KEY, AWS default credentials, and published image digests ininfra/local.tfvarsare also required for that plan.cloudflare_name_serversandturnstile_site_keyoutputs and the twoBotProtection__SecretKeySecureString names in AWS Systems Manager Parameter Store forus-east-2. Confirm both API environment groups in the Render Dashboard receive the key.useorbit.org, open Nameservers, choose Change and Custom nameservers, and enter bothcloudflare_name_serversvalues. After propagation,dig NS useorbit.orgmust show the assigned nameservers andbash infra/check-dns-cutover.sh <cloudflare-nameserver>must pass for each one.