| 1 | { |
| 2 | "$schema": "../../node_modules/wrangler/config-schema.json", |
| 3 | "name": "g1t-sudo", |
| 4 | "account_id": "1e6f2cffa3f445920836e8ebe446bb58", |
| 5 | "compatibility_date": "2026-09-26", |
| 6 | "main": "./workers/app.ts", |
| 7 | // Staff only: reachable at sudo.g1t.sh, behind Cloudflare Access, and |
| 8 | // nowhere else. No workers.dev address and no preview URLs, so there is |
| 9 | // no way round Access to the worker. |
| 10 | "routes": [{ "pattern": "sudo.g1t.sh", "custom_domain": true }], |
| 11 | "workers_dev": false, |
| 12 | "preview_urls": false, |
| 13 | // Even the stylesheet goes through the worker, which checks the Access |
| 14 | // token on every request before anything is served. |
| 15 | "assets": { "binding": "ASSETS", "run_worker_first": true }, |
| 16 | "services": [{ "binding": "BILLING", "service": "g1t-billing" }], |
| 17 | "vars": { |
| 18 | // The Zero Trust team domain, such as `g1t.cloudflareaccess.com`. |
| 19 | "ACCESS_TEAM_DOMAIN": "", |
| 20 | // The Access application's Audience (AUD) tag. |
| 21 | "ACCESS_AUD": "", |
| 22 | // Who may use sudo, comma separated. Access lets them in; this |
| 23 | // decides again, in case the Access policy is ever widened. |
| 24 | "STAFF_EMAILS": "syntaqx@gmail.com" |
| 25 | }, |
| 26 | "observability": { "enabled": true }, |
| 27 | "upload_source_maps": true |
| 28 | } |