Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| domains | 1 | # Flagon domains |
| 2 | ||
| 3 | Pulumi infrastructure for redirecting alternate and commonly misspelled domains to | |
| 4 | `https://flagon.io` through Cloudflare. | |
| 5 | ||
| 6 | For every configured domain, the stack creates: | |
| 7 | ||
| 8 | - a full Cloudflare zone; | |
| 9 | - proxied apex and wildcard DNS records; and | |
| 10 | - an entry in one account-level Bulk Redirect list. | |
| 11 | ||
| 12 | The Bulk Redirect rule sends every path and subdomain to the equivalent path on | |
| 13 | `flagon.io` with a permanent `301`, preserving query strings. | |
| 14 | ||
| 15 | ## Prerequisites | |
| 16 | ||
| 17 | - Node.js 24 | |
| 18 | - Pulumi CLI | |
| 19 | - a Cloudflare API token exposed as `CLOUDFLARE_API_TOKEN` | |
| 20 | - a Pulumi backend (Pulumi Cloud or a self-managed backend) | |
| 21 | ||
| 22 | The token needs `Zone:Read`, `Zone:Edit`, `DNS:Edit`, `Account Filter Lists:Edit`, | |
| 23 | and `Account Rulesets:Edit` (called `Mass URL Redirects:Write` in some Cloudflare | |
| 24 | interfaces) for the relevant account and zones. | |
| 25 | ||
| 26 | ## Deploy | |
| 27 | ||
| 28 | ```sh | |
| 29 | npm install | |
| 30 | pulumi stack init production | |
| 31 | pulumi config set cloudflareAccountId YOUR_CLOUDFLARE_ACCOUNT_ID | |
| 32 | pulumi config set targetUrl https://flagon.io | |
| 33 | pulumi config set --path 'domains[0]' flagon.dev | |
| 34 | pulumi config set --path 'domains[1]' flaggon.io | |
| 35 | pulumi preview | |
| 36 | pulumi up | |
| 37 | ``` | |
| 38 | ||
| 39 | Add real domains only; the names above are examples. `domains` is deliberately | |
| 40 | required so an empty or accidental deployment fails early. | |
| 41 | ||
| 42 | After the first deployment, point each registrar at the `zoneNameServers` shown in | |
| 43 | the Pulumi outputs. Domains registered through Cloudflare already use Cloudflare's | |
| 44 | nameservers. HTTPS redirects will begin working after the zone activates and | |
| 45 | Cloudflare provisions its edge certificate. | |
| 46 | ||
| 47 | If a zone already exists in the account, import it before the first update: | |
| 48 | ||
| 49 | ```sh | |
| 50 | pulumi import cloudflare:index/zone:Zone example-com ZONE_ID | |
| 51 | ``` | |
| 52 | ||
| 53 | The Pulumi resource name is the lowercase domain with punctuation changed to | |
| 54 | hyphens (for example, `example.com` becomes `example-com`). Preview the import and | |
| 55 | deployment carefully whenever adopting existing DNS, since the stack owns the | |
| 56 | zone and its two redirect records after import. | |
| 57 | ||
| 58 | ## Add a domain | |
| 59 | ||
| 60 | Append it to the stack's `domains` configuration and run `pulumi preview`, followed | |
| 61 | by `pulumi up`. Do not add `flagon.io` itself; the program rejects redirect loops. | |
| 62 | ||
| 63 | Email aliases are intentionally not managed here yet. A future Google Workspace | |
| 64 | provider can be added without changing the Cloudflare domain model. |