START HERE
This is the master sequence. It is deliberately explicit: exact order, exact values, exact stop conditions.
The rule for this entire manual
Do one numbered action, verify the expected result, then move to the next action. Do not change DNS, Access, Pages settings, D1, R2, and code at the same time. If a step fails, stop at that layer and use document 13 or 19.
What you are building
https://command.iridesceux.com — Cloudflare Pages + Pages Functions + D1 + R2 + Cloudflare Access. The raw Command *.pages.dev URL and preview deployments must also be Access-protected so they cannot bypass the custom hostname.The exact first-time order
Extract and inspect the release
Follow the linked documentConfirm you have real folders, not a ZIP inside a ZIP. Read document 01.
Create one private GitHub repository
Follow the linked documentPush the whole monorepo. Do not commit secrets. Read document 02.
Create the Command Pages project
Follow the linked documentRoot command-app; output public; Functions remain at command-app/functions.
Create D1 and load command-schema.sql
Follow the linked documentBind it to Command exactly as COMMAND_DB; redeploy.
Create R2
Follow the linked documentBind it exactly as COMMAND_ASSETS; redeploy.
Attach command.iridesceux.com to the Pages project
Follow the linked documentDo this in Pages before creating an Access policy on that custom hostname.
Verify the Zero Trust team domain
Follow the linked documentCurrent intended team domain: iridesceux.cloudflareaccess.com. It must resolve to a real Cloudflare Access/App Launcher page, not “Unable to find your Access organization.”
Configure One-Time PIN
Follow the linked documentAdd OTP as an identity provider if it is not already available.
Protect the raw Command *.pages.dev URL and preview deployments
Follow the linked documentThe Command custom hostname is not the only route to the Pages project. Secure the Pages-provided hostname too.
Create the Command Access application
Follow the linked documentSelf-hosted and private → Add public hostname → command.iridesceux.com → exact-email Allow policy.
Copy the Access AUD tag and set Command JWT variables
Follow the linked documentSet CF_ACCESS_TEAM_DOMAIN, CF_ACCESS_AUD, COMMAND_REQUIRE_ACCESS_JWT=true, and BOOTSTRAP_ADMIN_EMAIL; redeploy.
Verify /api/command/me
Follow the linked documentIt must return your real authenticated email and super_admin.
Run Setup Doctor
Follow the linked documentCore must show Functions, D1, R2, and Access/JWT healthy.
Deploy Iridesceux staging
Follow the linked documentSeparate Pages project: root public-site, output public.
Deploy HVN staging
Follow the linked documentSeparate Pages project: root hvn-site, output public; bind shared resources as documented.
Configure optional workers and OBS
Follow the linked documentOnly after core web stack works.
Run readiness tests
Follow the linked documentDocument 16, then document 14 for launch.
The four checkpoints you must not fake
| Checkpoint | Pass condition | Failure means |
|---|---|---|
| Pages/Functions | /api/command/me reaches a Function response, not static HTML/404. | Project root/function deployment is wrong. |
| Storage | D1 queries work; R2 upload persists after refresh. | Binding/schema/redeploy problem. |
| Access | Incognito hits Access before Command; after login the backend receives a valid Access JWT. | Zero Trust team/app/policy/AUD problem. |
| Operations | Master Control test commands reach the Broadcast Agent and a non-public OBS test scene. | Agent/service-token/OBS configuration problem. |
Current release: v32 Program Cue Sheets
Before normal operations, read 22 · Rundown, Traffic & Local EPG, 23 · Dolby Vision & HDR, 24 · Dolby Atmos & Spatial Audio, 27 · Premium Media Automation, and 28 · Program Cue Sheets & Timed Traffic. v32 adds program-content-relative commercial-break and screen-bug cues, local exact-time overrides, and rundown clock-shortfall protection while preserving the publish → approve → arm safety model.
24 · Dolby Atmos & Spatial Audio
27 · Premium Media Automation
Automatic Dolby detection, HLS packaging, pre-roll and opening format notice →
v32 · Program Cue Sheets
After program ingest and break-clock setup, use Break + Cue Builder → Program Cue Sheet to attach saved commercial breaks or screen bugs to exact program-content timecodes. Read document 28 before approving a cue-driven rundown for air.