Skip to content

docs: document the three deployment/hosting layers - #2253

Merged
LucasSantana-Dev merged 29 commits into
mainfrom
docs/deployment-hosting-layers
Sep 8, 2026
Merged

LucasSantana-Dev merged 29 commits into
mainfrom
docs/deployment-hosting-layers

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Sep 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Nothing in the repo said which of the three independent hosting layers (Cloudflare Pages, Cloudflare Tunnel + homelab nginx, legacy Vercel preview) serves which host, or which config file governs each. Fixing the /invite redirect took three PRs (#1889, #1893, #1895) before landing in the right file.

  • Added a "Deployment & hosting" section to docs/ARCHITECTURE.md: the host/layer/config table, the CSP trick for identifying which layer answered a request, and the nginx.conf/_redirects gotchas that cost time before.
  • Added a one-line pointer to that section at the top of nginx.conf and _redirects.
  • vercel.json and _headers intentionally left untouched: vercel.json is strict JSON with no safe comment syntax, and _headers' Cloudflare Pages comment support isn't proven in this repo the way _redirects' is (its existing comment block already works in production - _headers has none to point to as precedent). Not worth guessing on a live config file for a one-line pointer when docs/ARCHITECTURE.md already names both files.

Test plan

  • Read-only doc/comment change, no code paths touched
  • nginx.conf comment uses #, the format nginx already uses throughout this file
  • _redirects comment extends the file's own pre-existing # comment block, proven safe since it's already live in production

Closes #1924


Summary by cubic

Documents which of the three hosting layers (Cloudflare Pages, Cloudflare Tunnel + homelab nginx, legacy Vercel preview) serves which host and which config file governs each, so fixes like /invite land in the right file instead of taking three PRs.

  • Adds a Deployment & hosting section to docs/ARCHITECTURE.md with the host/layer/config table, the CSP trick for identifying which layer answered, the nginx.conf /api-proxying rule plus its /invite, /webhook/, /webhooks/ exceptions, and the _redirects top-to-bottom gotcha.
  • Adds pointers to that section at the top of nginx.conf and _redirects.
  • Read-only change; leaves vercel.json and _headers untouched. Closes docs: record which layer serves which host (three serving layers, undocumented) #1924.

Written for commit 4b401a0. Summary will update on new commits.

Review in cubic

Nothing in the repo said which of the three independent hosting layers
(Cloudflare Pages, Cloudflare Tunnel + homelab nginx, legacy Vercel
preview) serves which host, or which config file governs each. Fixing
the /invite redirect took three PRs (#1889, #1893, #1895) before landing
in the right file.

Added a Deployment & hosting section to docs/ARCHITECTURE.md with the
host/layer/config table, the CSP trick for identifying which layer
answered a request, and the two nginx.conf/_redirects gotchas that cost
time before. Added a one-line pointer to that section at the top of
nginx.conf and _redirects.

vercel.json and _headers intentionally left untouched: vercel.json is
strict JSON with no safe comment syntax, and _headers' Cloudflare Pages
comment support isn't proven in this repo the way _redirects' is (its
existing header comment already works in production) - not worth
guessing on a live config file. docs/ARCHITECTURE.md already names both
files, which covers the same discoverability goal.

Closes #1924
@github-actions

github-actions Bot commented Sep 6, 2026

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread docs/ARCHITECTURE.md Outdated

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three-layer production hosting split in ARCHITECTURE.md — Cloudflare Pages for the public site, Cloudflare Tunnel → nginx for the API, and the self-hosted docker-compose image — with a new "Deployment & hosting" section spelling out which config governs which host, a curl CSP check to identify the responding layer, and the caveats that nginx.conf only proxies /api and _redirects is order-sensitive. Adds cross-referencing header comments to nginx.conf and _redirects pointing back to that section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit 09b8508, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents a new "Deployment & hosting" section in ARCHITECTURE.md describing the three independent production layers (Cloudflare Pages for the public site, Cloudflare Tunnel→homelab nginx and self-hosted docker-compose for the API, legacy Vercel previews), which config file governs each, and how to identify the responding layer via the CSP script-src beacon. Notes the gotchas: nginx.conf only proxies /api so new backend paths need their own location block, and _redirects is evaluated top-to-bottom under the SPA catch-all. Adds header comments in nginx.conf and _redirects pointing back to that section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents a "Deployment & hosting" section in ARCHITECTURE.md that maps each production host to the layer and config file that serves it (Cloudflare Pages via _redirects/_headers, Cloudflare Tunnel/self-hosted via nginx.conf, legacy Vercel via vercel.json), and explains how to identify the answering layer by its CSP, that nginx.conf only proxies /api with everything else falling through to the SPA, and that _redirects is evaluated top-to-bottom under a catch-all. Adds cross-referencing header comments to nginx.conf and _redirects pointing at that section. Widens the package-layout table columns for readability with no content change.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the production hosting topology in ARCHITECTURE.md, adding a "Deployment & hosting" section that maps each host (lucky.lucassantana.tech via Cloudflare Pages, lucky-api.lucassantana.tech and self-hosted compose via nginx, previews via Vercel) to the config file that actually serves it, plus a curl CSP check to identify which layer answered and the gotchas that nginx.conf only proxies /api and _redirects is evaluated top-to-bottom. Adds cross-referencing header comments in nginx.conf and _redirects pointing back to that section. Widens the package-layouts table column so the bot row renders without breaking the layout.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three-layer production hosting setup in ARCHITECTURE.md — a new "Deployment & hosting" section maps each host (lucky.lucassantana.tech on Cloudflare Pages, lucky-api via Tunnel→nginx, self-hosted compose, legacy Vercel previews) to the config file that actually serves it, with a CSP-header trick to identify which layer answered and reminders that nginx only proxies /api and _redirects is order-sensitive. Adds pointer comments in nginx.conf and _redirects back to that section so editors land in the right file. Widens two Markdown table columns; no behavioural change to routing itself.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three-layer production hosting split in ARCHITECTURE.md — Cloudflare Pages for the public site, Cloudflare Tunnel→nginx for the API, and the self-hosted docker-compose nginx — spelling out which config file governs each host, how to identify the responding layer via CSP, and the gotchas that nginx.conf only proxies /api and _redirects is order-sensitive under its catch-all. Adds cross-referencing comments to nginx.conf and _redirects pointing back to that section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three independent production hosting layers (Cloudflare Pages via _redirects/_headers, Cloudflare Tunnel/self-hosted nginx via nginx.conf, and legacy Vercel previews) in a new "Deployment & hosting" section, spelling out which config governs each host, how to identify the responding layer by its CSP, and the gotchas that nginx only proxies /api while _redirects is matched top-to-bottom. Adds pointer comments to nginx.conf and _redirects linking back to that section so editors land in the right file.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit 7a88bdc, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three-layer production hosting split in ARCHITECTURE.md — Cloudflare Pages for the public site, Cloudflare Tunnel→homelab nginx for the API, and self-hosted docker-compose — spelling out which config file governs each host, how to identify the responding layer by its CSP, and that nginx.conf only proxies /api while _redirects is order-sensitive. Adds a header comment to nginx.conf clarifying its scope and cross-links the _redirects comment to the new section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three independent production hosting layers (Cloudflare Pages for the public site, Cloudflare Tunnel→nginx for the API, self-hosted docker-compose, plus legacy Vercel previews) in a new "Deployment & hosting" section of ARCHITECTURE.md, spelling out which config file governs each host, how to identify the answering layer via the CSP beacon, and the two footguns (nginx only proxies /api, _redirects catch-all swallows rules below it). Adds cross-referencing header comments to nginx.conf and _redirects pointing back to that section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the production hosting topology in ARCHITECTURE.md, adding a "Deployment & hosting" section that maps each host to its serving layer (lucky.lucassantana.tech via Cloudflare Pages _redirects/_headers, the API and self-hosted compose via nginx.conf, previews via legacy Vercel) and explains how to identify the responding layer from its CSP. Notes the load-bearing gotchas: nginx.conf only proxies /api so new backend-served paths need their own location block, and _redirects is evaluated top-to-bottom under a swallowing SPA catch-all. Adds cross-referencing comments to nginx.conf and _redirects pointing back to the doc.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the production hosting topology in ARCHITECTURE.md, adding a "Deployment & hosting" section that maps each host (lucky.lucassantana.tech via Cloudflare Pages, lucky-api and self-hosted compose via nginx, preview deploys via Vercel) to the config file that actually serves it, plus how to tell which layer answered a request via the CSP beacon and the gotchas that nginx.conf only proxies /api and _redirects catch-alls swallow later rules. Adds cross-referencing header comments to nginx.conf and _redirects pointing back to that section, and widens the package-layout table columns so the bot row renders. No behavioural change.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

Clarify that nginx.conf proxies /api as the general rule, with three
explicit exceptions: /invite, /webhook/, and /webhooks/. These paths
are handled by dedicated location blocks, not the catch-all frontend
routing. Fixes misleading documentation that stated only /api is
proxied.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Auto-approved: Adds documentation of the three hosting layers and pointers to it in nginx.conf and _redirects; comment-only, no behavior change. Bounded, clearly beneficial documentation update that should reduce misconfigured-fix churn.

Re-trigger cubic

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three independent production hosting layers (Cloudflare Pages for the public site, Cloudflare Tunnel → nginx for the API, and self-hosted docker-compose, with legacy Vercel previews) in a new "Deployment & hosting" section, spelling out which config file governs each host, how to identify the answering layer via the CSP beacon, and the top-to-bottom evaluation gotchas in _redirects and nginx.conf. Adds cross-referencing header comments to nginx.conf and _redirects pointing back to that section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the production hosting topology in ARCHITECTURE.md, adding a "Deployment & hosting" section that maps each host to the layer that serves it (Cloudflare Pages via _redirects/_headers, homelab nginx via nginx.conf, self-hosted docker-compose, and legacy Vercel previews) and explains how to tell which layer answered a request by inspecting the CSP. Notes the routing rules that trip people up: nginx.conf only proxies /api plus explicit location blocks so new backend paths need their own block, and _redirects is top-to-bottom with a catch-all that swallows anything below it. Adds cross-referencing comments to nginx.conf and _redirects pointing back to that section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit 3a3bba0, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the production hosting topology in a new "Deployment & hosting" section of ARCHITECTURE.md, mapping each host (lucky.lucassantana.tech via Cloudflare Pages, lucky-api.lucassantana.tech via tunnel→nginx, self-hosted compose, legacy Vercel previews) to the exact config file that governs it, plus a curl CSP check to tell which layer answered and the top-to-bottom _redirects/nginx fall-through rules. Adds header comments to nginx.conf and _redirects pointing back to that section so editors land in the right file. Also widens two Markdown table columns for formatting only.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three independent production hosting layers (Cloudflare Pages for lucky.lucassantana.tech, Cloudflare Tunnel → homelab nginx for the API, self-hosted docker-compose, and legacy Vercel previews) in ARCHITECTURE.md, noting which config file governs each, how to identify the responding layer via the CSP beacon, and that nginx.conf only proxies /api (plus explicit blocks) with everything else falling through to the SPA. Adds orienting comments to nginx.conf and _redirects pointing back to the new section. Also widens the bot row in the package-layouts table so it renders without truncation.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three independent production hosting layers (Cloudflare Pages for the public site, Cloudflare Tunnel → nginx for the API, self-hosted docker compose, and legacy Vercel previews) in a new "Deployment & hosting" section, spelling out which config file governs each host, how to fingerprint which layer answered a request via the CSP beacon, and the top-to-bottom _redirects and /api-only nginx proxy rules that make new public paths easy to miss. Adds orienting header comments to nginx.conf and _redirects pointing back at that section. Widens the shared/bot package-layout table columns; no content change there.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the production hosting topology in ARCHITECTURE.md, spelling out that three independent layers each own a separate config — Cloudflare Pages (_redirects/_headers) serves the public site, homelab nginx (nginx.conf) serves the API and self-hosted compose, and Vercel handles legacy preview deploys — and how to tell which layer answered a request via the content-security-policy beacon. Notes the routing gotchas: nginx.conf only proxies /api plus explicit /invite//webhook blocks with everything else falling through to the SPA, and _redirects evaluates top-to-bottom so rules must precede the catch-all. Adds cross-referencing comments to nginx.conf and _redirects pointing at the new section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit 0e98a5e, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three independent production hosting layers (Cloudflare Pages for the public site, Cloudflare Tunnel→nginx for the API, and self-hosted docker-compose, with Vercel as legacy preview) in a new "Deployment & hosting" section, spelling out which config file governs each host, how to identify the answering layer via the CSP beacon, and the top-to-bottom _redirects/nginx.conf fall-through rules that route unmatched paths to the SPA. Adds a header comment to nginx.conf clarifying which hosts it serves and cross-links the _redirects note to the new section. Also widens the shared/frontend package-layout table columns so the bot row no longer breaks alignment.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit 19135b5, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three-layer production hosting split (Cloudflare Pages, Cloudflare Tunnel → homelab nginx, and self-hosted docker compose, plus legacy Vercel previews) in a new Deployment & hosting section, including a curl CSP check to identify which layer answered a request and the catch-all fall-through rules for nginx.conf and _redirects. Adds pointers to that section from the top of nginx.conf and _redirects, and widens the package-layout table columns for readability.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents a new "Deployment & hosting" section in ARCHITECTURE.md that maps each production host to the layer and config file that serves it (Cloudflare Pages _redirects/_headers, homelab nginx via tunnel, self-hosted compose, legacy Vercel), explains how to identify the answering layer via the CSP beacon, and notes that nginx.conf only proxies /api plus explicit location blocks while everything else falls through to the SPA. Adds cross-referencing header comments to nginx.conf and _redirects pointing at that section, and fixes the whitespace/column alignment in the package-layouts table.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents a new "Deployment & hosting" section in ARCHITECTURE.md that maps each production host (lucky.lucassantana.tech on Cloudflare Pages, lucky-api.lucassantana.tech and self-hosted compose on nginx, Vercel previews) to the config file that actually serves it, and explains how to identify the answering layer via the CSP beacon, that nginx only proxies /api plus explicit path blocks, and that _redirects catch-all order matters. Adds cross-reference comments in nginx.conf and _redirects pointing back to that section. Also normalizes table column widths in the package-layouts section (no content change).

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three-layer production hosting split (Cloudflare Pages, Cloudflare Tunnel → homelab nginx, and self-hosted docker compose, plus legacy Vercel previews) in a new "Deployment & hosting" section, spelling out which config file governs each host and how to identify the responding layer by its CSP beacon. Notes that nginx.conf only proxies /api plus explicit /invite//webhook blocks with everything else falling through to the SPA, and that _redirects evaluates top-to-bottom under the catch-all. Adds cross-referencing header comments to nginx.conf and _redirects pointing back to the new section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit c469fc6, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the three-layer production hosting split in ARCHITECTURE.md — Cloudflare Pages for the public site (_redirects/_headers), Cloudflare Tunnel and self-hosted compose both through nginx.conf, and legacy Vercel previews — with a curl CSP check to identify which layer answered and notes that nginx.conf only proxies /api plus explicit blocks while _redirects is top-to-bottom under the SPA catch-all. Adds cross-referencing comments to nginx.conf and _redirects pointing back to the new doc section.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Documents the production hosting split in ARCHITECTURE.md: adds a "Deployment & hosting" section mapping each host (lucky.lucassantana.tech via Cloudflare Pages, lucky-api and self-hosted compose via nginx, preview deploys via legacy Vercel) to the config file that actually governs it, with a curl CSP check to identify which layer answered and notes on the /api-only nginx proxy rule and the top-to-bottom _redirects catch-all. Cross-links the nginx and _redirects config comments to that section so editors land in the right file. Widens two markdown table columns; no behaviour change there.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 25 functions depend on the 25 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 25 function(s) in the blast radius were not formally verified this run

@sonarqubecloud

sonarqubecloud Bot commented Sep 8, 2026

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit 1b410c1 into main Sep 8, 2026
40 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the docs/deployment-hosting-layers branch September 8, 2026 05:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs: record which layer serves which host (three serving layers, undocumented)

1 participant