README.md
Flagon domains
Pulumi infrastructure for redirecting alternate and commonly misspelled domains to
https://flagon.io through Cloudflare.
For every configured domain, the stack creates:
- a full Cloudflare zone;
- proxied apex and wildcard DNS records; and
- an entry in one account-level Bulk Redirect list.
The Bulk Redirect rule sends every path and subdomain to the equivalent path on
flagon.io with a permanent 301, preserving query strings.
Prerequisites
- Node.js 24
- Pulumi CLI
- a Cloudflare API token exposed as
CLOUDFLARE_API_TOKEN - a Pulumi backend (Pulumi Cloud or a self-managed backend)
The token needs Zone:Read, Zone:Edit, DNS:Edit, Account Filter Lists:Edit,
and Account Rulesets:Edit (called Mass URL Redirects:Write in some Cloudflare
interfaces) for the relevant account and zones.
Deploy
npm install
pulumi stack init production
pulumi config set cloudflareAccountId YOUR_CLOUDFLARE_ACCOUNT_ID
pulumi config set targetUrl https://flagon.io
pulumi config set --path 'domains[0]' flagon.dev
pulumi config set --path 'domains[1]' flaggon.io
pulumi preview
pulumi upAdd real domains only; the names above are examples. domains is deliberately
required so an empty or accidental deployment fails early.
After the first deployment, point each registrar at the zoneNameServers shown in
the Pulumi outputs. Domains registered through Cloudflare already use Cloudflare's
nameservers. HTTPS redirects will begin working after the zone activates and
Cloudflare provisions its edge certificate.
If a zone already exists in the account, import it before the first update:
pulumi import cloudflare:index/zone:Zone example-com ZONE_IDThe Pulumi resource name is the lowercase domain with punctuation changed to
hyphens (for example, example.com becomes example-com). Preview the import and
deployment carefully whenever adopting existing DNS, since the stack owns the
zone and its two redirect records after import.
Add a domain
Append it to the stack's domains configuration and run pulumi preview, followed
by pulumi up. Do not add flagon.io itself; the program rejects redirect loops.
Email aliases are intentionally not managed here yet. A future Google Workspace provider can be added without changing the Cloudflare domain model.