pcbjam/site/.dev.vars.example

30 lines
1.5 KiB
Text
Raw Normal View History

feat(site): move the marketing site from Vercel to Cloudflare Pages www.pcbjam.com was the last piece of the stack on Vercel. It is now a Cloudflare Pages project (pcbjam-site) deployed by deploy-site.yml on every push to main touching site/** — content must not wait for a release tag. The Astro adapter is gone entirely: the build is pure static and the one dynamic route, /api/waitlist, is a Pages Function. Going adapter-free (rather than swapping in @astrojs/cloudflare, which has dropped Pages support and only targets Workers) removes three problems at once — no Astro/adapter major-version coupling, Footer.astro's build-time execSync keeps working because prerendering stays in Node, and image optimisation stays plain build-time sharp with no Cloudflare Images binding. Verified against a real Pages runtime (wrangler pages dev): 21/21 parity probes pass, versus 19/21 on live Vercel. The scripted runbook is in deploy/site/ — every mutating step is dry-run by default. Four behaviour differences were found by measurement and are handled here: - The blog post's COOP/COEP was already broken in production. vercel.json scoped the headers to the bare URL, but the page's own canonical is the trailing-slash form, which served 200 with no isolation headers — so search arrivals lost SharedArrayBuffer and the embedded Gerber viewer degraded. public/_headers covers both forms. - Pages answers unknown URLs with the homepage at HTTP 200 when the output has no 404.html — a soft-404 that invites indexing junk URLs as the homepage. Hence src/pages/404.astro. - Vercel's edge refused cross-site form POSTs ("Cross-site POST form submissions are forbidden"); Pages does not, and a cross-site <form> submit needs no CORS permission to be sent, so the allowlist cannot stop it. The Function reproduces the guard; JSON posts stay exempt as that is demo.pcbjam.com's allowlisted path. - Cache-Control: immutable on /_astro/* came from the Vercel adapter's generated route config, so it is now an explicit _headers rule. Secrets move to `wrangler pages secret put --project-name pcbjam-site` (RESEND_API_KEY, RESEND_SEGMENT_ID, WAITLIST_FROM_EMAIL); WAITLIST_ALLOWED_ORIGINS stays unset so the allowlist stays in code. Local dev reads .dev.vars, now gitignored — the root repo's **/.dev.vars does not cover a nested git repo. privacy.md and cookies.md named Vercel as a GDPR Art. 28 processor; those mentions are removed and the existing Cloudflare entry widened to cover website hosting. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LAmkjM7okPdScp9XLW1JVr
2026-07-27 13:34:12 +02:00
# PCBJam marketing site — server-side secrets for the waitlist Pages Function.
#
# Copy to `.dev.vars` (gitignored) for local dev; `wrangler pages dev` loads it
# and exposes the values on the Function's `context.env`. Note this is NOT `.env`
# any more: the endpoint is a Cloudflare Pages Function, not an Astro SSR route,
# so it reads bindings rather than `astro:env/server`.
#
# In production these are set once, out of band, and are NOT deploy inputs:
# wrangler pages secret put RESEND_API_KEY --project-name pcbjam-site
# wrangler pages secret put RESEND_SEGMENT_ID --project-name pcbjam-site
# wrangler pages secret put WAITLIST_FROM_EMAIL --project-name pcbjam-site
#
# Without RESEND_API_KEY the endpoint still accepts submits (logs + no email),
# so the form UX is testable locally without keys.
# Resend API key (https://resend.com/api-keys). Server-only — never PUBLIC_.
RESEND_API_KEY=
# Resend Segment to add waitlist contacts to (https://resend.com/segments).
# (Resend renamed "Audiences" → "Segments"; this is the Segment ID.)
RESEND_SEGMENT_ID=
# Optional: confirmation sender. Domain must be verified in Resend.
# Defaults to "PCBJam <hello@pcbjam.com>" (see functions/api/waitlist.ts).
WAITLIST_FROM_EMAIL=
# Optional: comma-separated origins allowed to cross-post the waitlist form.
# Deliberately UNSET in production so it keeps the in-code default
# (https://demo.pcbjam.com) — the static demo has no backend of its own.
# WAITLIST_ALLOWED_ORIGINS=