// cloudflare-dns's provisioner — the adapter making it a provider of the mesh `public-dns` interface // (novox/hq ADR 0049). The reconcile loop, sealing and grant-file handling are the sdk harness's; // this writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing // it at the mesh's ingress, and remove it when the grant is withdrawn. // // The `public-dns` interface hands a consumer { fqdn, target, ttl } — a name that resolves publicly // and what it resolves to. It is not a secret (a DNS record is public), so nothing is sealed beyond // what the harness seals; the only secret is this module's own Cloudflare token, which never leaves. import { runProvisioner, type Grant, type Credential } from "@novox/mesh-sdk/provisioner"; import { emit } from "@novox/mesh-sdk/events"; import { CloudflareClient } from "../client.js"; const cloudflare = CloudflareClient.fromEnv(); runProvisioner("public-dns", { async create(grant: Grant): Promise { const fqdn = cloudflare.nameFor(grant.consumer); await cloudflare.upsert(fqdn); await announce("module.cloudflare-dns.record.created", { name: fqdn, target: cloudflare.ingress, consumer: grant.consumer, node: grant.node, }); return { fields: { fqdn, target: cloudflare.ingress, ttl: "300" } }; }, async remove(grant: Grant): Promise { const fqdn = cloudflare.nameFor(grant.consumer); await cloudflare.remove(fqdn); await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: grant.consumer, node: grant.node }); }, }); /** Emit best-effort: a broker hiccup must never fail or reverse a DNS change that already happened. */ async function announce(type: string, body: unknown): Promise { try { await emit(type, body); } catch (err) { console.error(`[cloudflare-dns] could not emit ${type}: ${err}`); } }