| 1 | # Flagon domains |
| 2 | |
| 3 | Pulumi infrastructure for redirecting alternate and commonly misspelled domains to |
| 4 | `https://flagon.io` through Cloudflare. |
| 5 | |
| 6 | For every configured domain, the stack creates: |
| 7 | |
| 8 | - a full Cloudflare zone; |
| 9 | - proxied apex and wildcard DNS records; and |
| 10 | - an entry in one account-level Bulk Redirect list. |
| 11 | |
| 12 | The Bulk Redirect rule sends every path and subdomain to the equivalent path on |
| 13 | `flagon.io` with a permanent `301`, preserving query strings. |
| 14 | |
| 15 | ## Prerequisites |
| 16 | |
| 17 | - Node.js 24 |
| 18 | - Pulumi CLI |
| 19 | - a Cloudflare API token exposed as `CLOUDFLARE_API_TOKEN` |
| 20 | - a Pulumi backend (Pulumi Cloud or a self-managed backend) |
| 21 | |
| 22 | The token needs `Zone:Read`, `Zone:Edit`, `DNS:Edit`, `Account Filter Lists:Edit`, |
| 23 | and `Account Rulesets:Edit` (called `Mass URL Redirects:Write` in some Cloudflare |
| 24 | interfaces) for the relevant account and zones. |
| 25 | |
| 26 | ## Deploy |
| 27 | |
| 28 | ```sh |
| 29 | npm install |
| 30 | pulumi stack init production |
| 31 | pulumi config set cloudflareAccountId YOUR_CLOUDFLARE_ACCOUNT_ID |
| 32 | pulumi config set targetUrl https://flagon.io |
| 33 | pulumi config set --path 'domains[0]' flagon.dev |
| 34 | pulumi config set --path 'domains[1]' flaggon.io |
| 35 | pulumi preview |
| 36 | pulumi up |
| 37 | ``` |
| 38 | |
| 39 | Add real domains only; the names above are examples. `domains` is deliberately |
| 40 | required so an empty or accidental deployment fails early. |
| 41 | |
| 42 | After the first deployment, point each registrar at the `zoneNameServers` shown in |
| 43 | the Pulumi outputs. Domains registered through Cloudflare already use Cloudflare's |
| 44 | nameservers. HTTPS redirects will begin working after the zone activates and |
| 45 | Cloudflare provisions its edge certificate. |
| 46 | |
| 47 | If a zone already exists in the account, import it before the first update: |
| 48 | |
| 49 | ```sh |
| 50 | pulumi import cloudflare:index/zone:Zone example-com ZONE_ID |
| 51 | ``` |
| 52 | |
| 53 | The Pulumi resource name is the lowercase domain with punctuation changed to |
| 54 | hyphens (for example, `example.com` becomes `example-com`). Preview the import and |
| 55 | deployment carefully whenever adopting existing DNS, since the stack owns the |
| 56 | zone and its two redirect records after import. |
| 57 | |
| 58 | ## Add a domain |
| 59 | |
| 60 | Append it to the stack's `domains` configuration and run `pulumi preview`, followed |
| 61 | by `pulumi up`. Do not add `flagon.io` itself; the program rejects redirect loops. |
| 62 | |
| 63 | Email aliases are intentionally not managed here yet. A future Google Workspace |
| 64 | provider can be added without changing the Cloudflare domain model. |