The Vercel -> Cloudflare Pages move is done and the Vercel project is deleted, so the one-shot scripts have no remaining purpose. Nothing in CI ever called them — deploy-site.yml runs npm ci / test / build / pages deploy inline — so this removes 10 files and orphans nothing. Deleted: 00-baseline (refused to run without x-vercel-id, so permanently unrunnable), 01-preflight (proved Vercel state and API-token scopes), 07-dns-cutover (the phased cutover; in the end the records were attached through the dashboard, and the rules/apex phases went unused once we chose APEX_MODE=serve), 09-detach-vercel (its target project is gone), plus 03-ensure-project, 04-set-secrets, 05-deploy, 06-verify-deploy, 02-verify-local and 99-rollback, all either spent or duplicating CI. Their lib/cf-api.sh went with them: the survivors use wrangler, so the whole remaining path needs only `wrangler login` and no zone scopes. What is kept is the part with ongoing value: lib/parity.sh, the assertion set that caught five real defects during the migration — the live COOP/COEP bug on the post's canonical URL, the soft-404 Pages would have introduced, the cross-site form-POST guard Vercel had been providing for free, the missing immutable header, and HSTS max-age=0. "Does the page return 200" catches none of those. 08-verify-prod.sh becomes verify.sh, since the numbered sequence it belonged to no longer exists. It drops the stamp machinery, the dry-run plumbing and the Vercel-fallback messaging (there is no fallback now: recovery is promoting a previous Pages deployment), and gains --skip-dns / --skip-domains so it can be pointed at a single deployment via PROD_BASE before promoting it. The README is rewritten around the four invariants that fail SILENTLY — never widen _headers to /*, keep both URL forms of the Gerber post, never delete 404.astro, keep the cross-site form-POST guard — each with the reason, since the reason is the only thing that stops someone simplifying them back out. Verified after: 21 probes, 20 pass, 1 warn (HSTS max-age is 6 months vs Vercel's 2 years — on, just shorter), 0 fail. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LAmkjM7okPdScp9XLW1JVr
21 lines
987 B
TOML
21 lines
987 B
TOML
# Cloudflare Pages config for the marketing site (project `pcbjam-site`).
|
|
#
|
|
# This exists to keep the Function's RUNTIME CONTRACT in version control rather
|
|
# than living only in whatever flags the Pages project happened to be created
|
|
# with — the same reasoning as apps/server/wrangler.jsonc declaring its custom
|
|
# domain in code.
|
|
#
|
|
# nodejs_compat is for the `resend` SDK used by functions/api/waitlist.ts.
|
|
#
|
|
# Secrets are NOT here — they are set once, out of band:
|
|
# wrangler pages secret put RESEND_API_KEY --project-name pcbjam-site
|
|
# and locally come from .dev.vars (gitignored). WAITLIST_ALLOWED_ORIGINS is
|
|
# deliberately unset so it keeps the default in functions/api/waitlist.ts.
|
|
#
|
|
# The custom domains (www.pcbjam.com and the apex) are attached out of band too —
|
|
# there is no `wrangler pages domain` subcommand; see deploy/site/README.md.
|
|
|
|
name = "pcbjam-site"
|
|
pages_build_output_dir = "./dist"
|
|
compatibility_date = "2026-06-01"
|
|
compatibility_flags = ["nodejs_compat"]
|