// cloudflare-dns's provisioner — the adapter making it a provider of the mesh `public-dns` interface // (novox/hq ADR 0044). The reconcile loop and the contributions file are the sdk harness's; this // writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing it // at the mesh's ingress, and remove it when the consumer is withdrawn (ADR 0048). // // The `public-dns` interface hands a consumer { fqdn, target, ttl } — a name that resolves publicly // and what it resolves to. Like umami's analytics it is a *data* provision, not a credential one: // nothing the mesh mints is set here (a DNS record is public, and the only secret is this module's // own Cloudflare token, which never leaves). So the password the harness carries is unused; the name // is derived from the login the mesh gave the consumer, which the consumer can derive too. Delivering // the record back to the consumer is the data-provision return path ADR 0048 leaves out of scope. import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner"; import { emit } from "@novox/mesh-sdk/events"; import { CloudflareClient } from "../client.js"; const cloudflare = CloudflareClient.fromEnv(); runProvisioner("public-dns", { async create(p: Provision): Promise { const fqdn = cloudflare.nameFor(p.as); await cloudflare.upsert(fqdn); await announce("record.created", { name: fqdn, target: cloudflare.ingress, consumer: p.consumer ?? "", }); }, async remove(p: { as: string }): Promise { const fqdn = cloudflare.nameFor(p.as); await cloudflare.remove(fqdn); await announce("record.removed", { name: fqdn, consumer: p.as }); }, }); /** Emit best-effort: a broker hiccup must never fail or reverse a DNS change that already happened. */ async function announce(type: string, body: unknown): Promise { try { await emit(type, body); } catch (err) { console.error(`[cloudflare-dns] could not emit ${type}: ${err}`); } }