IRIDESC E UX · COMMAND
v30 · Program Primary Revision
Security, Backups & Offboarding
Production security posture, backup/rollback discipline, secret rotation, access removal, and incident response.
Minimum production security posture
- Command custom hostname is fully behind Cloudflare Access.
COMMAND_REQUIRE_ACCESS_JWT=true.COMMAND_ALLOW_HEADER_AUTHunset/false in production.- Exact-email or managed-group Access policy; never Include Everyone for Command.
- One identity per employee.
- Secrets stored as secrets/provider-native credentials, not Git.
- OBS WebSocket not Internet-exposed.
- GitHub repository private.
- Highest-trust roles kept to the smallest possible number.
Backups before changes
| Resource | Before risky change |
|---|---|
| D1 | Remote export to timestamped SQL. |
| Git/code | Clean commit + known rollback commit hash. |
| Pages | Know the last healthy deployment and rollback path. |
| R2/media | Do not bulk-delete without inventory/export plan. Maintain source masters separately. |
| OBS | Export/backup scene collection and profile before major reconfiguration. |
Rotate a secret safely
1
Create the new credential
Provider/password managerDo not revoke old credential yet if both sides must be updated in sequence.
2
Update the receiving service
Cloudflare/agent/vendorStore new value as secret.
3
Redeploy/restart where necessary
ServiceCommand Pages requires a new deployment; Broadcast Agent may require restart.
4
Verify functionality
Smallest possible testProve the new secret works.
5
Revoke old credential
ProviderOnly after successful verification.
6
Record rotation
Audit/change logRecord date, owner, affected service — not the secret itself.
Employee offboarding — full sequence
- Disable Command team record.
- Remove Access permission.
- Disable/suspend company email or IdP account.
- Remove GitHub repository/team access.
- Remove Cloudflare account membership if they had it.
- Remove social/vendor/finance/analytics access.
- Rotate known shared secrets.
- Review Command audit log and Cloudflare logs around departure.
- Collect/secure company devices/files as applicable.
- Document completion.
Incident response first ten minutes
1. Identify whether incident is PUBLIC SITE / COMMAND / BROADCAST / CREDENTIAL.
2. Preserve evidence: screenshots, timestamps, logs.
3. If Command is publicly exposed → immediately fix/disable Access exposure.
4. If broadcast output is unsafe → backup feed / KILL GRAPHICS / emergency stop as rehearsed.
5. If credential leaked → revoke/rotate it.
6. Freeze unrelated changes.
7. Assign one person to coordinate.
8. Restore the last known-safe state.
9. Verify externally.
10. Record root cause and prevention after service is stable.