Repository navigation
docs: document the three deployment/hosting layers - #2253
Conversation
Nothing in the repo said which of the three independent hosting layers (Cloudflare Pages, Cloudflare Tunnel + homelab nginx, legacy Vercel preview) serves which host, or which config file governs each. Fixing the /invite redirect took three PRs (#1889, #1893, #1895) before landing in the right file. Added a Deployment & hosting section to docs/ARCHITECTURE.md with the host/layer/config table, the CSP trick for identifying which layer answered a request, and the two nginx.conf/_redirects gotchas that cost time before. Added a one-line pointer to that section at the top of nginx.conf and _redirects. vercel.json and _headers intentionally left untouched: vercel.json is strict JSON with no safe comment syntax, and _headers' Cloudflare Pages comment support isn't proven in this repo the way _redirects' is (its existing header comment already works in production) - not worth guessing on a live config file. docs/ARCHITECTURE.md already names both files, which covers the same discoverability goal. Closes #1924
|
Failed to generate code suggestions for PR |
There was a problem hiding this comment.
All reported issues were addressed
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three-layer production hosting split in ARCHITECTURE.md — Cloudflare Pages for the public site, Cloudflare Tunnel → nginx for the API, and the self-hosted docker-compose image — with a new "Deployment & hosting" section spelling out which config governs which host, a curl CSP check to identify the responding layer, and the caveats that nginx.conf only proxies /api and _redirects is order-sensitive. Adds cross-referencing header comments to nginx.conf and _redirects pointing back to that section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit 09b8508, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents a new "Deployment & hosting" section in ARCHITECTURE.md describing the three independent production layers (Cloudflare Pages for the public site, Cloudflare Tunnel→homelab nginx and self-hosted docker-compose for the API, legacy Vercel previews), which config file governs each, and how to identify the responding layer via the CSP script-src beacon. Notes the gotchas: nginx.conf only proxies /api so new backend paths need their own location block, and _redirects is evaluated top-to-bottom under the SPA catch-all. Adds header comments in nginx.conf and _redirects pointing back to that section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents a "Deployment & hosting" section in ARCHITECTURE.md that maps each production host to the layer and config file that serves it (Cloudflare Pages via _redirects/_headers, Cloudflare Tunnel/self-hosted via nginx.conf, legacy Vercel via vercel.json), and explains how to identify the answering layer by its CSP, that nginx.conf only proxies /api with everything else falling through to the SPA, and that _redirects is evaluated top-to-bottom under a catch-all. Adds cross-referencing header comments to nginx.conf and _redirects pointing at that section. Widens the package-layout table columns for readability with no content change.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the production hosting topology in ARCHITECTURE.md, adding a "Deployment & hosting" section that maps each host (lucky.lucassantana.tech via Cloudflare Pages, lucky-api.lucassantana.tech and self-hosted compose via nginx, previews via Vercel) to the config file that actually serves it, plus a curl CSP check to identify which layer answered and the gotchas that nginx.conf only proxies /api and _redirects is evaluated top-to-bottom. Adds cross-referencing header comments in nginx.conf and _redirects pointing back to that section. Widens the package-layouts table column so the bot row renders without breaking the layout.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three-layer production hosting setup in ARCHITECTURE.md — a new "Deployment & hosting" section maps each host (lucky.lucassantana.tech on Cloudflare Pages, lucky-api via Tunnel→nginx, self-hosted compose, legacy Vercel previews) to the config file that actually serves it, with a CSP-header trick to identify which layer answered and reminders that nginx only proxies /api and _redirects is order-sensitive. Adds pointer comments in nginx.conf and _redirects back to that section so editors land in the right file. Widens two Markdown table columns; no behavioural change to routing itself.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three-layer production hosting split in ARCHITECTURE.md — Cloudflare Pages for the public site, Cloudflare Tunnel→nginx for the API, and the self-hosted docker-compose nginx — spelling out which config file governs each host, how to identify the responding layer via CSP, and the gotchas that nginx.conf only proxies /api and _redirects is order-sensitive under its catch-all. Adds cross-referencing comments to nginx.conf and _redirects pointing back to that section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three independent production hosting layers (Cloudflare Pages via _redirects/_headers, Cloudflare Tunnel/self-hosted nginx via nginx.conf, and legacy Vercel previews) in a new "Deployment & hosting" section, spelling out which config governs each host, how to identify the responding layer by its CSP, and the gotchas that nginx only proxies /api while _redirects is matched top-to-bottom. Adds pointer comments to nginx.conf and _redirects linking back to that section so editors land in the right file.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit 7a88bdc, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three-layer production hosting split in ARCHITECTURE.md — Cloudflare Pages for the public site, Cloudflare Tunnel→homelab nginx for the API, and self-hosted docker-compose — spelling out which config file governs each host, how to identify the responding layer by its CSP, and that nginx.conf only proxies /api while _redirects is order-sensitive. Adds a header comment to nginx.conf clarifying its scope and cross-links the _redirects comment to the new section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three independent production hosting layers (Cloudflare Pages for the public site, Cloudflare Tunnel→nginx for the API, self-hosted docker-compose, plus legacy Vercel previews) in a new "Deployment & hosting" section of ARCHITECTURE.md, spelling out which config file governs each host, how to identify the answering layer via the CSP beacon, and the two footguns (nginx only proxies /api, _redirects catch-all swallows rules below it). Adds cross-referencing header comments to nginx.conf and _redirects pointing back to that section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the production hosting topology in ARCHITECTURE.md, adding a "Deployment & hosting" section that maps each host to its serving layer (lucky.lucassantana.tech via Cloudflare Pages _redirects/_headers, the API and self-hosted compose via nginx.conf, previews via legacy Vercel) and explains how to identify the responding layer from its CSP. Notes the load-bearing gotchas: nginx.conf only proxies /api so new backend-served paths need their own location block, and _redirects is evaluated top-to-bottom under a swallowing SPA catch-all. Adds cross-referencing comments to nginx.conf and _redirects pointing back to the doc.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the production hosting topology in ARCHITECTURE.md, adding a "Deployment & hosting" section that maps each host (lucky.lucassantana.tech via Cloudflare Pages, lucky-api and self-hosted compose via nginx, preview deploys via Vercel) to the config file that actually serves it, plus how to tell which layer answered a request via the CSP beacon and the gotchas that nginx.conf only proxies /api and _redirects catch-alls swallow later rules. Adds cross-referencing header comments to nginx.conf and _redirects pointing back to that section, and widens the package-layout table columns so the bot row renders. No behavioural change.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
Clarify that nginx.conf proxies /api as the general rule, with three explicit exceptions: /invite, /webhook/, and /webhooks/. These paths are handled by dedicated location blocks, not the catch-all frontend routing. Fixes misleading documentation that stated only /api is proxied.
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Auto-approved: Adds documentation of the three hosting layers and pointers to it in nginx.conf and _redirects; comment-only, no behavior change. Bounded, clearly beneficial documentation update that should reduce misconfigured-fix churn.
Re-trigger cubic
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three independent production hosting layers (Cloudflare Pages for the public site, Cloudflare Tunnel → nginx for the API, and self-hosted docker-compose, with legacy Vercel previews) in a new "Deployment & hosting" section, spelling out which config file governs each host, how to identify the answering layer via the CSP beacon, and the top-to-bottom evaluation gotchas in _redirects and nginx.conf. Adds cross-referencing header comments to nginx.conf and _redirects pointing back to that section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the production hosting topology in ARCHITECTURE.md, adding a "Deployment & hosting" section that maps each host to the layer that serves it (Cloudflare Pages via _redirects/_headers, homelab nginx via nginx.conf, self-hosted docker-compose, and legacy Vercel previews) and explains how to tell which layer answered a request by inspecting the CSP. Notes the routing rules that trip people up: nginx.conf only proxies /api plus explicit location blocks so new backend paths need their own block, and _redirects is top-to-bottom with a catch-all that swallows anything below it. Adds cross-referencing comments to nginx.conf and _redirects pointing back to that section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit 3a3bba0, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the production hosting topology in a new "Deployment & hosting" section of ARCHITECTURE.md, mapping each host (lucky.lucassantana.tech via Cloudflare Pages, lucky-api.lucassantana.tech via tunnel→nginx, self-hosted compose, legacy Vercel previews) to the exact config file that governs it, plus a curl CSP check to tell which layer answered and the top-to-bottom _redirects/nginx fall-through rules. Adds header comments to nginx.conf and _redirects pointing back to that section so editors land in the right file. Also widens two Markdown table columns for formatting only.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three independent production hosting layers (Cloudflare Pages for lucky.lucassantana.tech, Cloudflare Tunnel → homelab nginx for the API, self-hosted docker-compose, and legacy Vercel previews) in ARCHITECTURE.md, noting which config file governs each, how to identify the responding layer via the CSP beacon, and that nginx.conf only proxies /api (plus explicit blocks) with everything else falling through to the SPA. Adds orienting comments to nginx.conf and _redirects pointing back to the new section. Also widens the bot row in the package-layouts table so it renders without truncation.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three independent production hosting layers (Cloudflare Pages for the public site, Cloudflare Tunnel → nginx for the API, self-hosted docker compose, and legacy Vercel previews) in a new "Deployment & hosting" section, spelling out which config file governs each host, how to fingerprint which layer answered a request via the CSP beacon, and the top-to-bottom _redirects and /api-only nginx proxy rules that make new public paths easy to miss. Adds orienting header comments to nginx.conf and _redirects pointing back at that section. Widens the shared/bot package-layout table columns; no content change there.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the production hosting topology in ARCHITECTURE.md, spelling out that three independent layers each own a separate config — Cloudflare Pages (_redirects/_headers) serves the public site, homelab nginx (nginx.conf) serves the API and self-hosted compose, and Vercel handles legacy preview deploys — and how to tell which layer answered a request via the content-security-policy beacon. Notes the routing gotchas: nginx.conf only proxies /api plus explicit /invite//webhook blocks with everything else falling through to the SPA, and _redirects evaluates top-to-bottom so rules must precede the catch-all. Adds cross-referencing comments to nginx.conf and _redirects pointing at the new section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit 0e98a5e, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three independent production hosting layers (Cloudflare Pages for the public site, Cloudflare Tunnel→nginx for the API, and self-hosted docker-compose, with Vercel as legacy preview) in a new "Deployment & hosting" section, spelling out which config file governs each host, how to identify the answering layer via the CSP beacon, and the top-to-bottom _redirects/nginx.conf fall-through rules that route unmatched paths to the SPA. Adds a header comment to nginx.conf clarifying which hosts it serves and cross-links the _redirects note to the new section. Also widens the shared/frontend package-layout table columns so the bot row no longer breaks alignment.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit 19135b5, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three-layer production hosting split (Cloudflare Pages, Cloudflare Tunnel → homelab nginx, and self-hosted docker compose, plus legacy Vercel previews) in a new Deployment & hosting section, including a curl CSP check to identify which layer answered a request and the catch-all fall-through rules for nginx.conf and _redirects. Adds pointers to that section from the top of nginx.conf and _redirects, and widens the package-layout table columns for readability.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents a new "Deployment & hosting" section in ARCHITECTURE.md that maps each production host to the layer and config file that serves it (Cloudflare Pages _redirects/_headers, homelab nginx via tunnel, self-hosted compose, legacy Vercel), explains how to identify the answering layer via the CSP beacon, and notes that nginx.conf only proxies /api plus explicit location blocks while everything else falls through to the SPA. Adds cross-referencing header comments to nginx.conf and _redirects pointing at that section, and fixes the whitespace/column alignment in the package-layouts table.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents a new "Deployment & hosting" section in ARCHITECTURE.md that maps each production host (lucky.lucassantana.tech on Cloudflare Pages, lucky-api.lucassantana.tech and self-hosted compose on nginx, Vercel previews) to the config file that actually serves it, and explains how to identify the answering layer via the CSP beacon, that nginx only proxies /api plus explicit path blocks, and that _redirects catch-all order matters. Adds cross-reference comments in nginx.conf and _redirects pointing back to that section. Also normalizes table column widths in the package-layouts section (no content change).
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three-layer production hosting split (Cloudflare Pages, Cloudflare Tunnel → homelab nginx, and self-hosted docker compose, plus legacy Vercel previews) in a new "Deployment & hosting" section, spelling out which config file governs each host and how to identify the responding layer by its CSP beacon. Notes that nginx.conf only proxies /api plus explicit /invite//webhook blocks with everything else falling through to the SPA, and that _redirects evaluates top-to-bottom under the catch-all. Adds cross-referencing header comments to nginx.conf and _redirects pointing back to the new section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit c469fc6, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the three-layer production hosting split in ARCHITECTURE.md — Cloudflare Pages for the public site (_redirects/_headers), Cloudflare Tunnel and self-hosted compose both through nginx.conf, and legacy Vercel previews — with a curl CSP check to identify which layer answered and notes that nginx.conf only proxies /api plus explicit blocks while _redirects is top-to-bottom under the SPA catch-all. Adds cross-referencing comments to nginx.conf and _redirects pointing back to the new doc section.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Documents the production hosting split in ARCHITECTURE.md: adds a "Deployment & hosting" section mapping each host (lucky.lucassantana.tech via Cloudflare Pages, lucky-api and self-hosted compose via nginx, preview deploys via legacy Vercel) to the config file that actually governs it, with a curl CSP check to identify which layer answered and notes on the /api-only nginx proxy rule and the top-to-bottom _redirects catch-all. Cross-links the nginx and _redirects config comments to that section so editors land in the right file. Widens two markdown table columns; no behaviour change there.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 25 functions depend on the 25 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 25 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 25 function(s) in the blast radius were not formally verified this run
|



Summary
Nothing in the repo said which of the three independent hosting layers (Cloudflare Pages, Cloudflare Tunnel + homelab nginx, legacy Vercel preview) serves which host, or which config file governs each. Fixing the /invite redirect took three PRs (#1889, #1893, #1895) before landing in the right file.
Test plan
#, the format nginx already uses throughout this file#comment block, proven safe since it's already live in productionCloses #1924
Summary by cubic
Documents which of the three hosting layers (Cloudflare Pages, Cloudflare Tunnel + homelab nginx, legacy Vercel preview) serves which host and which config file governs each, so fixes like
/inviteland in the right file instead of taking three PRs.docs/ARCHITECTURE.mdwith the host/layer/config table, the CSP trick for identifying which layer answered, thenginx.conf/api-proxying rule plus its/invite,/webhook/,/webhooks/exceptions, and the_redirectstop-to-bottom gotcha.nginx.confand_redirects.vercel.jsonand_headersuntouched. Closes docs: record which layer serves which host (three serving layers, undocumented) #1924.Written for commit 4b401a0. Summary will update on new commits.