Skip to content

Serve production Akeru Cloud on cloud.akeru-bot.com and keep staging for Leo only #442

Description

@linear-code

Problem

Production Akeru Cloud was going to run on its workers.dev address (akeru-cloud.leoisadev.workers.dev). Production should live on the product's own domain, and the staging cloud should be usable only by Leo.

Goal

Production Akeru Cloud serves on https://cloud.akeru-bot.com, and Akeru Bot links to it by default. Dev builds still default to staging. Staging stays on its workers.dev address, and only Leo's account can sign in or link an environment to it.

akeru-bot.com DNS and the landing page stay on Vercel, at Leo's request. Production therefore uses a Cloudflare for SaaS custom hostname instead of moving the zone to Cloudflare.

Acceptance criteria

  • The app's default cloud address (DEFAULT_AKERU_CLOUD_URL in contracts) is https://cloud.akeru-bot.com, and dev builds default to STAGING_AKERU_CLOUD_URL
  • cloud.akeru-bot.com reaches the production Worker through a Cloudflare for SaaS custom hostname with an active certificate
  • Staging rejects sign-up from any account other than Leo's: another email gets "is not allowed to access this application"
  • https://cloud.akeru-bot.com serves the sign-in page, and POST /v1/link/start works in production
  • Docs name the production and staging addresses (docs/internals/cloud.md)
  • Production sign-in offers Google as well as email codes
  • PR feat(cloud): optional Akeru Cloud account with a linked environment socket #364 is merged

Production sign-in on 2026-10-06, email codes only:

Akeru Cloud sign-in page at cloud.akeru-bot.com with only an email address field

How to verify

  • Cloud and server cloud tests pass with the new default. On 2026-10-06, 164 cloud, contracts, and server tests passed.
  • Open https://cloud.akeru-bot.com and confirm the sign-in page loads over HTTPS.
  • Try to sign up on staging with an email other than Leo's and confirm it is refused.
  • After Google is added, sign in to production with a Google account.

Out of scope

  • Moving akeru-bot.com DNS or the landing page off Vercel
  • Opening staging to anyone else

Context

Code: on akeru-cloud/foundation (PR #364). 70680db sets the default URL and the production custom domain. 3e01a13 switches production to a Cloudflare for SaaS hostname. 144c952 records the live hostname and Clerk setup in docs/internals/cloud.md. Production is already deployed, so merging #364 only redeploys.

How production is wired: Cloudflare for SaaS is enabled on the leodev.cv zone, with fallback origin akeru-cloud-origin.leodev.cv. A Worker route on leodev.cv sends cloud.akeru-bot.com/* to the production Worker. Vercel DNS holds the cloud CNAME, the _cf-custom-hostname.cloud and _acme-challenge.cloud TXT records, and the Clerk CNAMEs. The production Worker and D1 database are deployed with the shared Cloudflare state.

Sign-in: the Clerk production instance runs on akeru-bot.com with email codes only. Google needs OAuth credentials from Google Cloud, then a rerun of clerk deploy. Staging's Clerk allowlist holds only Leo's account, which has the admin role.

Deploy access: the GitHub environments cloud-production and cloud-staging exist. cloud-production holds a deploy token scoped to the Cloudflare account resources the Worker needs plus Workers Routes and Zone Read on leodev.cv, and the Cloudflare account ID. The earlier akeru-bot.com Cloudflare zone was deleted, and the old broader deploy token was revoked.

Related: AKR-129 (Akeru Cloud foundation).

Created with Claude Opus 5.5 in Claude Code.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions