Problem
Production Akeru Cloud was going to run on its workers.dev address (akeru-cloud.leoisadev.workers.dev). Production should live on the product's own domain, and the staging cloud should be usable only by Leo.
Goal
Production Akeru Cloud serves on https://cloud.akeru-bot.com, and Akeru Bot links to it by default. Dev builds still default to staging. Staging stays on its workers.dev address, and only Leo's account can sign in or link an environment to it.
akeru-bot.com DNS and the landing page stay on Vercel, at Leo's request. Production therefore uses a Cloudflare for SaaS custom hostname instead of moving the zone to Cloudflare.
Acceptance criteria
Production sign-in on 2026-10-06, email codes only:

How to verify
- Cloud and server cloud tests pass with the new default. On 2026-10-06, 164 cloud, contracts, and server tests passed.
- Open https://cloud.akeru-bot.com and confirm the sign-in page loads over HTTPS.
- Try to sign up on staging with an email other than Leo's and confirm it is refused.
- After Google is added, sign in to production with a Google account.
Out of scope
- Moving
akeru-bot.com DNS or the landing page off Vercel
- Opening staging to anyone else
Context
Code: on akeru-cloud/foundation (PR #364). 70680db sets the default URL and the production custom domain. 3e01a13 switches production to a Cloudflare for SaaS hostname. 144c952 records the live hostname and Clerk setup in docs/internals/cloud.md. Production is already deployed, so merging #364 only redeploys.
How production is wired: Cloudflare for SaaS is enabled on the leodev.cv zone, with fallback origin akeru-cloud-origin.leodev.cv. A Worker route on leodev.cv sends cloud.akeru-bot.com/* to the production Worker. Vercel DNS holds the cloud CNAME, the _cf-custom-hostname.cloud and _acme-challenge.cloud TXT records, and the Clerk CNAMEs. The production Worker and D1 database are deployed with the shared Cloudflare state.
Sign-in: the Clerk production instance runs on akeru-bot.com with email codes only. Google needs OAuth credentials from Google Cloud, then a rerun of clerk deploy. Staging's Clerk allowlist holds only Leo's account, which has the admin role.
Deploy access: the GitHub environments cloud-production and cloud-staging exist. cloud-production holds a deploy token scoped to the Cloudflare account resources the Worker needs plus Workers Routes and Zone Read on leodev.cv, and the Cloudflare account ID. The earlier akeru-bot.com Cloudflare zone was deleted, and the old broader deploy token was revoked.
Related: AKR-129 (Akeru Cloud foundation).
Created with Claude Opus 5.5 in Claude Code.
Problem
Production Akeru Cloud was going to run on its
workers.devaddress (akeru-cloud.leoisadev.workers.dev). Production should live on the product's own domain, and the staging cloud should be usable only by Leo.Goal
Production Akeru Cloud serves on https://cloud.akeru-bot.com, and Akeru Bot links to it by default. Dev builds still default to staging. Staging stays on its
workers.devaddress, and only Leo's account can sign in or link an environment to it.akeru-bot.comDNS and the landing page stay on Vercel, at Leo's request. Production therefore uses a Cloudflare for SaaS custom hostname instead of moving the zone to Cloudflare.Acceptance criteria
DEFAULT_AKERU_CLOUD_URLin contracts) is https://cloud.akeru-bot.com, and dev builds default toSTAGING_AKERU_CLOUD_URLcloud.akeru-bot.comreaches the production Worker through a Cloudflare for SaaS custom hostname with an active certificatePOST /v1/link/startworks in productiondocs/internals/cloud.md)Production sign-in on 2026-10-06, email codes only:
How to verify
Out of scope
akeru-bot.comDNS or the landing page off VercelContext
Code: on
akeru-cloud/foundation(PR #364). 70680db sets the default URL and the production custom domain. 3e01a13 switches production to a Cloudflare for SaaS hostname. 144c952 records the live hostname and Clerk setup indocs/internals/cloud.md. Production is already deployed, so merging #364 only redeploys.How production is wired: Cloudflare for SaaS is enabled on the
leodev.cvzone, with fallback originakeru-cloud-origin.leodev.cv. A Worker route onleodev.cvsendscloud.akeru-bot.com/*to the production Worker. Vercel DNS holds thecloudCNAME, the_cf-custom-hostname.cloudand_acme-challenge.cloudTXT records, and the Clerk CNAMEs. The production Worker and D1 database are deployed with the shared Cloudflare state.Sign-in: the Clerk production instance runs on
akeru-bot.comwith email codes only. Google needs OAuth credentials from Google Cloud, then a rerun ofclerk deploy. Staging's Clerk allowlist holds only Leo's account, which has the admin role.Deploy access: the GitHub environments
cloud-productionandcloud-stagingexist.cloud-productionholds a deploy token scoped to the Cloudflare account resources the Worker needs plus Workers Routes and Zone Read onleodev.cv, and the Cloudflare account ID. The earlierakeru-bot.comCloudflare zone was deleted, and the old broader deploy token was revoked.Related: AKR-129 (Akeru Cloud foundation).
Created with Claude Opus 5.5 in Claude Code.