build: add Fly.io deployment process
CI / test (pull_request) Failing after 2m45s
CI / docker (pull_request) Has been skipped

fly.toml (Dockerfile.web, scale-to-zero in syd, /api/health checks),
make deploy / deploy-status targets, a Gitea workflow deploying on v*
tags or manual dispatch via FLY_API_TOKEN, and README instructions
covering first-time setup and the server's runtime env knobs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Gary Hansen
2026-07-07 21:50:30 +10:00
co-authored by Claude Fable 5
parent 111b8bf48e
commit ccfd3fd156
4 changed files with 119 additions and 1 deletions
+48
View File
@@ -246,6 +246,54 @@ data: {}
Completed jobs are kept in memory for one hour before being purged.
### Server configuration
The server is safe to expose publicly by default and reads these environment
variables at startup:
| Variable | Default | Meaning |
|---|---|---|
| `EXPLOREDNS_JOB_TIMEOUT` | `5m` | Hard deadline per traversal (Go duration). Timed-out jobs report `error` with any partial results. |
| `EXPLOREDNS_MAX_JOBS` | `8` | Maximum concurrent traversals; further `POST /api/traverse` requests get `429`. |
| `EXPLOREDNS_CORS_ORIGIN` | *(unset)* | Off by default (the SPA is same-origin). Set an origin — or `*` for development — to enable cross-origin API access. |
---
## Deploying to Fly.io
The repo ships a [fly.toml](fly.toml) that builds `Dockerfile.web` and runs
the web server with scale-to-zero machines in `syd` (edit `app` /
`primary_region` to taste).
### First-time setup
```sh
flyctl auth login
flyctl apps create exploredns # match the app name in fly.toml
make deploy # flyctl deploy --remote-only
```
`make deploy-status` shows machine and health-check state. The app serves
the SPA at `https://<app>.fly.dev/` with `/api/health` as the health check.
### Continuous deployment
`.gitea/workflows/deploy.yml` deploys on any `v*` tag push (or manual
dispatch). It needs a `FLY_API_TOKEN` repository secret:
```sh
flyctl tokens create deploy -x 999999h
```
### Notes
- Traversal traffic is outbound UDP/TCP port 53, which Fly machines allow;
upstream root discovery uses Fly's internal resolver via `/etc/resolv.conf`
and falls back to the built-in IANA root hints.
- The job timeout, job cap, and same-origin CORS defaults above are what make
unauthenticated public exposure reasonable; tighten `EXPLOREDNS_MAX_JOBS`
if the app attracts traffic.
---