IRIDESC E UX · COMMAND
v30 · Program Primary Revision
INTERNALSTEP-BY-STEP

D1, R2, Variables & Secrets

A complete storage/configuration manual with exact binding names, backup commands, and redeploy rules.

D1 — create, initialize, bind, verify

1

Create database

Cloudflare → Storage & databases → D1
iridesceux-command
2

Load schema remotely

Terminal → command-app
npx wrangler login
npx wrangler d1 execute iridesceux-command --remote --file=command-schema.sql
3

Verify schema

Terminal
npx wrangler d1 execute iridesceux-command --remote --command="SELECT name FROM sqlite_schema WHERE type='table' ORDER BY name;"
4

Bind database

Command Pages → Settings → Bindings

Type: D1 database; Variable name: COMMAND_DB; resource: iridesceux-command.

5

Redeploy

Command Pages

New deployment required for the binding to take effect.

D1 backup and restore discipline

Before a risky schema change or launch:

cd command-app
npx wrangler d1 export iridesceux-command --remote --output=../backups/iridesceux-command-YYYY-MM-DD.sql

Store backups somewhere private and access-controlled. Test that the export file exists and has non-zero size. Do not assume a backup is valid merely because the command returned.

Restoring a production database is a change-control event. Take a fresh export first, identify the exact tables/data you intend to restore, and rehearse on a non-production database when possible.

R2 — create, bind, verify

1

Create bucket

Cloudflare → R2
iridesceux-command-assets

Keep it private.

2

Bind bucket

Command Pages → Settings → Bindings

Type: R2 bucket; Variable name: COMMAND_ASSETS; select the bucket.

3

Redeploy

Command Pages

New deployment after binding.

4

Upload a disposable file

Authenticated Command

Upload a small test asset, refresh, read it back, then delete it.

Expected: File persists across refresh and is removed when deleted.

Variables and secrets — exact classification

NameTypeRequired now?Purpose
BOOTSTRAP_ADMIN_EMAILVariableYesExact email first Super Admin uses.
CF_ACCESS_TEAM_DOMAINVariableYeshttps://iridesceux.cloudflareaccess.com.
CF_ACCESS_AUDVariableYesCurrent Command Access application AUD.
COMMAND_REQUIRE_ACCESS_JWTVariableYestrue in deployed production Command.
COMMAND_ALLOW_HEADER_AUTHVariableNo; keep false/unsetDevelopment-only fallback. Do not enable in production.
COMMAND_MASTER_KEYSecretBefore using Command VaultServer-side encryption key for Command vault records.
BROADCAST_AGENT_TOKENSecretBefore agentShared application-level auth between Command and trusted Broadcast Agent.
CF_ACCESS_CLIENT_IDSecret/credentialBefore agent if agent endpoint is Access-protectedCloudflare Access service-token client ID for machine auth.
CF_ACCESS_CLIENT_SECRETSecretSame as aboveCloudflare Access service-token secret.
GITHUB_TOKEN / site-specific GitHub tokensSecretOnly if Code Studio deploy/edit is usedGitHub Contents/API access.
RESEND_API_KEYSecretOnly when mail features are enabledEmail delivery.
HVN_REALTIME_CONTROL_URLVariableOptionalRealtime Worker origin for Command publish calls.
HVN_REALTIME_PUBLISH_TOKENSecretOptionalPublish authorization for realtime Worker.
Never store a production API key/token in a normal Git-tracked file. Cloudflare recommends secrets for sensitive values and local .dev.vars or .env files that are ignored by Git.

Generate strong random secrets on macOS

COMMAND_MASTER_KEY has a strict format: it must be Base64 and decode to exactly 32 bytes. Generate it with:

openssl rand -base64 32

For an independent shared token such as BROADCAST_AGENT_TOKEN, a 32-byte hexadecimal token is appropriate:

openssl rand -hex 32

Copy each value directly into the matching Cloudflare Secret field or an approved password manager. Do not paste secret values into chat, issue trackers, or public terminal screenshots.

What requires a redeploy

ChangeRedeploy?
Add/change Pages bindingYes
Add/change runtime environment variable/secretYes for Pages Functions to receive the new deployment configuration.
Change D1 data through CommandNo
Upload/delete R2 object through CommandNo
Change Access policyNo Command deploy, but users may need a new Access session.
Change Access app / AUDYes if CF_ACCESS_AUD changes in Command.