Access Protection for SecurityV0 Environments
Cloudflare Zero Trust Access configuration for non-prod SecurityV0 environments. Prod is gated by WorkOS hosted login only.
Cloudflare Zero Trust Access configuration for non-prod SecurityV0 environments. Prod is gated by WorkOS hosted login only.
Adopt Terraform + hybrid repo structure (new sv0-infrastructure for cross-cutting, existing in-repo modules stay) + Terraform Cloud free tier for state and runners. Design modules so each customer tenant can be stamped out as an independent stack for dedicated-deployment clients.
How to add a Service Auth policy to a Cloudflare Access application so bots can access protected sites programmatically
Canonical inventory of every GitHub Environment / repo secret used by sv0 deploys, CI, and tooling. One row per secret: name, repo, scope, exact workflow files that consume it, purpose, status. Includes a VM ↔ secret mapping for migration planning.
How to handle Terraform drift, when dashboard changes are allowed, and how to reconcile them back into IaC. Companion to ADR-019.
Phased rollout of Infrastructure-as-Code per ADR-019. Four phases, each 1-3 days. Phase 1 is urgent (Cloudflare baseline with health-probe Bypass app); Phases 2-4 queue behind pilot-readiness work.