Per ADR-009 (docs/adr/009-remote-access-cloudflare-tunnel-access.md): Barback goes public at barback.pezza.dev through a Cloudflare Tunnel. The repo-side changes can land ahead of go-live; the domain is not enabled until the always-on host migration (see the migration issue).
- Add a
cloudflared service to deploy/docker-compose.yml: cloudflare/cloudflared image, tunnel run --token ${CLOUDFLARE_TUNNEL_TOKEN}, restart: unless-stopped, depends_on: web
- Add
CLOUDFLARE_TUNNEL_TOKEN to deploy/.env.example with a comment (gitignored .env holds the real value)
- Document
BARBACK_ORIGIN=https://barback.pezza.dev as the production value in .env.example (APP_URL must match the public origin)
- Tunnel public hostname (dashboard side):
barback.pezza.dev → http://web:80
- No client rebuild needed — relative
/bar and /search URLs (ADR-005)
- Salt Rim, API port 8000, and Meilisearch 7700 stay loopback-only; the tunnel sees only the front door
Per ADR-009 (docs/adr/009-remote-access-cloudflare-tunnel-access.md): Barback goes public at barback.pezza.dev through a Cloudflare Tunnel. The repo-side changes can land ahead of go-live; the domain is not enabled until the always-on host migration (see the migration issue).
cloudflaredservice todeploy/docker-compose.yml:cloudflare/cloudflaredimage,tunnel run --token ${CLOUDFLARE_TUNNEL_TOKEN},restart: unless-stopped,depends_on: webCLOUDFLARE_TUNNEL_TOKENtodeploy/.env.examplewith a comment (gitignored.envholds the real value)BARBACK_ORIGIN=https://barback.pezza.devas the production value in.env.example(APP_URLmust match the public origin)barback.pezza.dev→http://web:80/barand/searchURLs (ADR-005)