IRIDESC E UX · COMMAND
v32 · Program Cue Sheets
INTERNALSTEP-BY-STEP

START HERE

This is the master sequence. It is deliberately explicit: exact order, exact values, exact stop conditions.

The rule for this entire manual

Do one numbered action, verify the expected result, then move to the next action. Do not change DNS, Access, Pages settings, D1, R2, and code at the same time. If a step fails, stop at that layer and use document 13 or 19.

This version intentionally repeats important settings. Repetition is deliberate. You should not need to remember a value from a different page while doing a high-risk deployment task.

What you are building

Private operations app
https://command.iridesceux.com — Cloudflare Pages + Pages Functions + D1 + R2 + Cloudflare Access. The raw Command *.pages.dev URL and preview deployments must also be Access-protected so they cannot bypass the custom hostname.
Public corporate site
Iridesceux website — separate Pages project, can stay staging/unreleased during Command setup.
Public network site
HVN website/player — separate Pages project, can stay staging/unreleased during Command setup.
Broadcast control
Command queues actions; trusted Broadcast Agent executes them locally against OBS WebSocket.
Realtime presentation
Optional Worker speeds up presentation changes; D1 remains source of truth.
Safety monitor
Optional Worker polls official NWS alerts and writes candidates to Command; auto-TAKE stays off by default.

The exact first-time order

1

Extract and inspect the release

Follow the linked document

Confirm you have real folders, not a ZIP inside a ZIP. Read document 01.

2

Create one private GitHub repository

Follow the linked document

Push the whole monorepo. Do not commit secrets. Read document 02.

3

Create the Command Pages project

Follow the linked document

Root command-app; output public; Functions remain at command-app/functions.

4

Create D1 and load command-schema.sql

Follow the linked document

Bind it to Command exactly as COMMAND_DB; redeploy.

5

Create R2

Follow the linked document

Bind it exactly as COMMAND_ASSETS; redeploy.

6

Attach command.iridesceux.com to the Pages project

Follow the linked document

Do this in Pages before creating an Access policy on that custom hostname.

7

Verify the Zero Trust team domain

Follow the linked document

Current intended team domain: iridesceux.cloudflareaccess.com. It must resolve to a real Cloudflare Access/App Launcher page, not “Unable to find your Access organization.”

8

Configure One-Time PIN

Follow the linked document

Add OTP as an identity provider if it is not already available.

9

Protect the raw Command *.pages.dev URL and preview deployments

Follow the linked document

The Command custom hostname is not the only route to the Pages project. Secure the Pages-provided hostname too.

10

Create the Command Access application

Follow the linked document

Self-hosted and private → Add public hostname → command.iridesceux.com → exact-email Allow policy.

11

Copy the Access AUD tag and set Command JWT variables

Follow the linked document

Set CF_ACCESS_TEAM_DOMAIN, CF_ACCESS_AUD, COMMAND_REQUIRE_ACCESS_JWT=true, and BOOTSTRAP_ADMIN_EMAIL; redeploy.

12

Verify /api/command/me

Follow the linked document

It must return your real authenticated email and super_admin.

13

Run Setup Doctor

Follow the linked document

Core must show Functions, D1, R2, and Access/JWT healthy.

14

Deploy Iridesceux staging

Follow the linked document

Separate Pages project: root public-site, output public.

15

Deploy HVN staging

Follow the linked document

Separate Pages project: root hvn-site, output public; bind shared resources as documented.

16

Configure optional workers and OBS

Follow the linked document

Only after core web stack works.

17

Run readiness tests

Follow the linked document

Document 16, then document 14 for launch.

The four checkpoints you must not fake

CheckpointPass conditionFailure means
Pages/Functions/api/command/me reaches a Function response, not static HTML/404.Project root/function deployment is wrong.
StorageD1 queries work; R2 upload persists after refresh.Binding/schema/redeploy problem.
AccessIncognito hits Access before Command; after login the backend receives a valid Access JWT.Zero Trust team/app/policy/AUD problem.
OperationsMaster Control test commands reach the Broadcast Agent and a non-public OBS test scene.Agent/service-token/OBS configuration problem.

Current release: v32 Program Cue Sheets

Before normal operations, read 22 · Rundown, Traffic & Local EPG, 23 · Dolby Vision & HDR, 24 · Dolby Atmos & Spatial Audio, 27 · Premium Media Automation, and 28 · Program Cue Sheets & Timed Traffic. v32 adds program-content-relative commercial-break and screen-bug cues, local exact-time overrides, and rundown clock-shortfall protection while preserving the publish → approve → arm safety model.

24 · Dolby Atmos & Spatial Audio

27 · Premium Media Automation

Automatic Dolby detection, HLS packaging, pre-roll and opening format notice →

v32 · Program Cue Sheets

After program ingest and break-clock setup, use Break + Cue Builder → Program Cue Sheet to attach saved commercial breaks or screen bugs to exact program-content timecodes. Read document 28 before approving a cue-driven rundown for air.