Per ADR-009: everything on pezza.dev sits behind Cloudflare Access; Barback follows the same pattern. This is Zero Trust dashboard config, tracked here as a runbook since it lives outside the repo.
- Create an Access application for
barback.pezza.dev
- Allow policy: single email (owner), email OTP or GitHub SSO — matching the other pezza.dev apps
- Session duration ~30 days (single user; expired sessions surface as failed SPA fetches until reload — see the session-expiry issue)
- Verify: anonymous requests hit the Access login, never the app; the app's own Bar Assistant login remains as a second layer
- Rationale: upstream is pinned (ADR-001) and bumped deliberately, so the origin must not be anonymously reachable
Per ADR-009: everything on pezza.dev sits behind Cloudflare Access; Barback follows the same pattern. This is Zero Trust dashboard config, tracked here as a runbook since it lives outside the repo.
barback.pezza.dev