Skip to content
64 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

domains1# Flagon domains
2
3Pulumi infrastructure for redirecting alternate and commonly misspelled domains to
4`https://flagon.io` through Cloudflare.
5
6For every configured domain, the stack creates:
7
8- a full Cloudflare zone;
9- proxied apex and wildcard DNS records; and
10- an entry in one account-level Bulk Redirect list.
11
12The Bulk Redirect rule sends every path and subdomain to the equivalent path on
13`flagon.io` with a permanent `301`, preserving query strings.
14
15## Prerequisites
16
17- Node.js 24
18- Pulumi CLI
19- a Cloudflare API token exposed as `CLOUDFLARE_API_TOKEN`
20- a Pulumi backend (Pulumi Cloud or a self-managed backend)
21
22The token needs `Zone:Read`, `Zone:Edit`, `DNS:Edit`, `Account Filter Lists:Edit`,
23and `Account Rulesets:Edit` (called `Mass URL Redirects:Write` in some Cloudflare
24interfaces) for the relevant account and zones.
25
26## Deploy
27
28```sh
29npm install
30pulumi stack init production
31pulumi config set cloudflareAccountId YOUR_CLOUDFLARE_ACCOUNT_ID
32pulumi config set targetUrl https://flagon.io
33pulumi config set --path 'domains[0]' flagon.dev
34pulumi config set --path 'domains[1]' flaggon.io
35pulumi preview
36pulumi up
37```
38
39Add real domains only; the names above are examples. `domains` is deliberately
40required so an empty or accidental deployment fails early.
41
42After the first deployment, point each registrar at the `zoneNameServers` shown in
43the Pulumi outputs. Domains registered through Cloudflare already use Cloudflare's
44nameservers. HTTPS redirects will begin working after the zone activates and
45Cloudflare provisions its edge certificate.
46
47If a zone already exists in the account, import it before the first update:
48
49```sh
50pulumi import cloudflare:index/zone:Zone example-com ZONE_ID
51```
52
53The Pulumi resource name is the lowercase domain with punctuation changed to
54hyphens (for example, `example.com` becomes `example-com`). Preview the import and
55deployment carefully whenever adopting existing DNS, since the stack owns the
56zone and its two redirect records after import.
57
58## Add a domain
59
60Append it to the stack's `domains` configuration and run `pulumi preview`, followed
61by `pulumi up`. Do not add `flagon.io` itself; the program rejects redirect loops.
62
63Email aliases are intentionally not managed here yet. A future Google Workspace
64provider can be added without changing the Cloudflare domain model.