D1, R2, Variables & Secrets
A complete storage/configuration manual with exact binding names, backup commands, and redeploy rules.
D1 — create, initialize, bind, verify
Create database
Cloudflare → Storage & databases → D1iridesceux-commandLoad schema remotely
Terminal → command-appnpx wrangler login
npx wrangler d1 execute iridesceux-command --remote --file=command-schema.sqlVerify schema
Terminalnpx wrangler d1 execute iridesceux-command --remote --command="SELECT name FROM sqlite_schema WHERE type='table' ORDER BY name;"Bind database
Command Pages → Settings → BindingsType: D1 database; Variable name: COMMAND_DB; resource: iridesceux-command.
Redeploy
Command PagesNew deployment required for the binding to take effect.
D1 backup and restore discipline
Before a risky schema change or launch:
cd command-app
npx wrangler d1 export iridesceux-command --remote --output=../backups/iridesceux-command-YYYY-MM-DD.sqlStore backups somewhere private and access-controlled. Test that the export file exists and has non-zero size. Do not assume a backup is valid merely because the command returned.
R2 — create, bind, verify
Create bucket
Cloudflare → R2iridesceux-command-assetsKeep it private.
Bind bucket
Command Pages → Settings → BindingsType: R2 bucket; Variable name: COMMAND_ASSETS; select the bucket.
Redeploy
Command PagesNew deployment after binding.
Upload a disposable file
Authenticated CommandUpload a small test asset, refresh, read it back, then delete it.
Variables and secrets — exact classification
| Name | Type | Required now? | Purpose |
|---|---|---|---|
BOOTSTRAP_ADMIN_EMAIL | Variable | Yes | Exact email first Super Admin uses. |
CF_ACCESS_TEAM_DOMAIN | Variable | Yes | https://iridesceux.cloudflareaccess.com. |
CF_ACCESS_AUD | Variable | Yes | Current Command Access application AUD. |
COMMAND_REQUIRE_ACCESS_JWT | Variable | Yes | true in deployed production Command. |
COMMAND_ALLOW_HEADER_AUTH | Variable | No; keep false/unset | Development-only fallback. Do not enable in production. |
COMMAND_MASTER_KEY | Secret | Before using Command Vault | Server-side encryption key for Command vault records. |
BROADCAST_AGENT_TOKEN | Secret | Before agent | Shared application-level auth between Command and trusted Broadcast Agent. |
CF_ACCESS_CLIENT_ID | Secret/credential | Before agent if agent endpoint is Access-protected | Cloudflare Access service-token client ID for machine auth. |
CF_ACCESS_CLIENT_SECRET | Secret | Same as above | Cloudflare Access service-token secret. |
GITHUB_TOKEN / site-specific GitHub tokens | Secret | Only if Code Studio deploy/edit is used | GitHub Contents/API access. |
RESEND_API_KEY | Secret | Only when mail features are enabled | Email delivery. |
HVN_REALTIME_CONTROL_URL | Variable | Optional | Realtime Worker origin for Command publish calls. |
HVN_REALTIME_PUBLISH_TOKEN | Secret | Optional | Publish authorization for realtime Worker. |
.dev.vars or .env files that are ignored by Git.Generate strong random secrets on macOS
COMMAND_MASTER_KEY has a strict format: it must be Base64 and decode to exactly 32 bytes. Generate it with:
openssl rand -base64 32For an independent shared token such as BROADCAST_AGENT_TOKEN, a 32-byte hexadecimal token is appropriate:
openssl rand -hex 32Copy each value directly into the matching Cloudflare Secret field or an approved password manager. Do not paste secret values into chat, issue trackers, or public terminal screenshots.
What requires a redeploy
| Change | Redeploy? |
|---|---|
| Add/change Pages binding | Yes |
| Add/change runtime environment variable/secret | Yes for Pages Functions to receive the new deployment configuration. |
| Change D1 data through Command | No |
| Upload/delete R2 object through Command | No |
| Change Access policy | No Command deploy, but users may need a new Access session. |
| Change Access app / AUD | Yes if CF_ACCESS_AUD changes in Command. |