IRIDESC E UX · COMMAND
v30 · Program Primary Revision
Architecture & Folder Map
Use this page whenever a Cloudflare root directory, binding, hostname, or authentication layer is confusing.
Top-level package map
Iridesceux-HVN-v20.6-Exhaustive-Documentation/
├── command-app/ # private Command Pages project
│ ├── functions/ # Pages Functions; MUST stay beside public/
│ ├── public/ # static Command frontend
│ └── command-schema.sql # D1 schema
├── public-site/ # Iridesceux Pages project
│ ├── functions/
│ └── public/
├── hvn-site/ # HVN Pages project
│ ├── functions/
│ └── public/
├── broadcast-agent/ # local process on trusted OBS computer
├── hvn-realtime-worker/ # optional Worker
├── hvn-safety-worker/ # optional Worker
├── BROADCAST_ASSETS/ # staged stream/standby loop
├── DOCUMENTATION/ # canonical internal manuals
├── TESTS/ # audit/integration test assets
└── TESTS/results/ # generated audit output; never deployed
Never move
command-app/functions/ inside command-app/public/. Cloudflare requires the Functions directory at the Pages project root, not the static output root.Official reference: Cloudflare Pages Functions directory placement
Three Pages projects from one private monorepo
| Pages project | Root directory | Build command | Output | Functions |
|---|---|---|---|---|
| Command | command-app | exit 0 (or blank if Cloudflare accepts no-build) | public | command-app/functions |
| Iridesceux | public-site | exit 0 | public | public-site/functions |
| HVN | hvn-site | exit 0 | public | hvn-site/functions |
Cloudflare Pages supports multiple Pages projects from one monorepo by setting different root directories.
Official reference: https://developers.cloudflare.com/pages/configuration/build-configuration/
Official reference: https://developers.cloudflare.com/pages/get-started/git-integration/
What data lives where
GitHub
Code, static assets intended for source control, documentation. No production secrets.
D1 / COMMAND_DB
Command records/state: users, content metadata, schedule, audit log, broadcast/presentation state, ads metadata, safety records.
R2 / COMMAND_ASSETS
Uploaded operational files and media objects. D1 stores the metadata/key; R2 stores the bytes.
Cloudflare variables
Non-secret configuration such as team domain, AUD, feature URLs.
Cloudflare secrets
Tokens, API keys, Command master key, Broadcast Agent token.
OBS computer
OBS scenes/sources and local agent process. OBS WebSocket is not exposed to the public Internet.
Private means every route to Command is protected
Protect both the custom hostname and the Cloudflare-provided Pages hostnames. If
command.iridesceux.com is behind Access but YOUR-PROJECT.pages.dev is not, users can bypass the custom-hostname gate and the mirrored internal docs under /docs/ can be reached through the raw Pages URL. Use the Pages project Enable access policy control and verify main + preview Pages hostnames in Incognito.Official reference: Cloudflare instructions for securing Pages project and preview hostnames
Authentication flow
User browser
↓
Cloudflare Access protects command.iridesceux.com
↓ (valid CF_Authorization / Cf-Access-Jwt-Assertion)
Command Pages Function
↓ verifies issuer against iridesceux.cloudflareaccess.com
↓ verifies audience against CF_ACCESS_AUD
↓ gets email from signed JWT
Command D1 team_members / BOOTSTRAP_ADMIN_EMAIL
↓
Command role authorization
Cloudflare Access authentication and Command authorization are separate layers. Access answers “may this identity reach the app?” Command answers “what may this identity do inside the app?”