IRIDESC E UX · COMMAND
v30 · Program Primary Revision
INTERNALSTEP-BY-STEP

Architecture & Folder Map

Use this page whenever a Cloudflare root directory, binding, hostname, or authentication layer is confusing.

Top-level package map

Iridesceux-HVN-v20.6-Exhaustive-Documentation/
├── command-app/              # private Command Pages project
│   ├── functions/            # Pages Functions; MUST stay beside public/
│   ├── public/               # static Command frontend
│   └── command-schema.sql    # D1 schema
├── public-site/              # Iridesceux Pages project
│   ├── functions/
│   └── public/
├── hvn-site/                 # HVN Pages project
│   ├── functions/
│   └── public/
├── broadcast-agent/          # local process on trusted OBS computer
├── hvn-realtime-worker/      # optional Worker
├── hvn-safety-worker/        # optional Worker
├── BROADCAST_ASSETS/         # staged stream/standby loop
├── DOCUMENTATION/            # canonical internal manuals
├── TESTS/                    # audit/integration test assets
└── TESTS/results/            # generated audit output; never deployed
Never move command-app/functions/ inside command-app/public/. Cloudflare requires the Functions directory at the Pages project root, not the static output root.

Three Pages projects from one private monorepo

Pages projectRoot directoryBuild commandOutputFunctions
Commandcommand-appexit 0 (or blank if Cloudflare accepts no-build)publiccommand-app/functions
Iridesceuxpublic-siteexit 0publicpublic-site/functions
HVNhvn-siteexit 0publichvn-site/functions

Cloudflare Pages supports multiple Pages projects from one monorepo by setting different root directories.

What data lives where

GitHub
Code, static assets intended for source control, documentation. No production secrets.
D1 / COMMAND_DB
Command records/state: users, content metadata, schedule, audit log, broadcast/presentation state, ads metadata, safety records.
R2 / COMMAND_ASSETS
Uploaded operational files and media objects. D1 stores the metadata/key; R2 stores the bytes.
Cloudflare variables
Non-secret configuration such as team domain, AUD, feature URLs.
Cloudflare secrets
Tokens, API keys, Command master key, Broadcast Agent token.
OBS computer
OBS scenes/sources and local agent process. OBS WebSocket is not exposed to the public Internet.

Private means every route to Command is protected

Protect both the custom hostname and the Cloudflare-provided Pages hostnames. If command.iridesceux.com is behind Access but YOUR-PROJECT.pages.dev is not, users can bypass the custom-hostname gate and the mirrored internal docs under /docs/ can be reached through the raw Pages URL. Use the Pages project Enable access policy control and verify main + preview Pages hostnames in Incognito.

Authentication flow

User browser
  ↓
Cloudflare Access protects command.iridesceux.com
  ↓  (valid CF_Authorization / Cf-Access-Jwt-Assertion)
Command Pages Function
  ↓  verifies issuer against iridesceux.cloudflareaccess.com
  ↓  verifies audience against CF_ACCESS_AUD
  ↓  gets email from signed JWT
Command D1 team_members / BOOTSTRAP_ADMIN_EMAIL
  ↓
Command role authorization

Cloudflare Access authentication and Command authorization are separate layers. Access answers “may this identity reach the app?” Command answers “what may this identity do inside the app?”