# Cloudflare regional probe deployments The `wrangler.*.toml` files in this directory are generated from the region registry in `packages/regions`. Do not hand-edit them: ```bash pnpm generate:wrangler ``` Deploy the identical Worker source once per enabled region. The deployment names and regional affinity are intentionally explicit: | Deployment | Logical region | Placement hint | | ----------------------------- | ---------------- | -------------------- | | `uptime-probe-us-east` | `us-east` | `aws:us-east-1` | | `uptime-probe-us-west` | `us-west` | `aws:us-west-2` | | `uptime-probe-canada-central` | `canada-central` | `aws:ca-central-1` | | `uptime-probe-eu-west` | `eu-west` | `aws:eu-west-1` | | `uptime-probe-eu-north` | `eu-north` | `aws:eu-north-1` | | `uptime-probe-eu-south` | `eu-south` | `aws:eu-south-1` | | `uptime-probe-asia` | `asia` | `aws:ap-southeast-1` | | `uptime-probe-asia-east` | `asia-east` | `aws:ap-northeast-1` | | `uptime-probe-asia-south` | `asia-south` | `aws:ap-south-1` | From the repository root, authenticate Wrangler, then deploy every discovered configuration with the identical high-entropy signing secret: ```bash pnpm --filter @uptime/probe-worker exec wrangler login scripts/deploy-workers.sh --dry-run scripts/deploy-workers.sh --secrets-file /path/to/probe-secrets.env ``` `scripts/deploy-workers.sh` reads `REGIONS_LIST` from the process environment or the repository `.env` file and deploys only those Wrangler configurations, preserving list order. For example: ```dotenv REGIONS_LIST="asia-east,asia-south" ``` The API exposes only this subset in the monitor editor, monitor saves reject disabled regions, and the scheduler skips disabled regions. When `REGIONS_LIST` is omitted, all canonical regions remain enabled for backward compatibility. Every regional Wrangler configuration enables Cloudflare Workers observability. Deploying the fleet persists Worker logs in the Cloudflare dashboard for each regional Worker. Set `WORKERS_URL_DOMAIN` in the scheduler environment to the shared suffix printed by Wrangler, such as `account-subdomain.workers.dev`. The scheduler combines it with each canonical Worker name to produce `https://uptime-probe-{region}.{WORKERS_URL_DOMAIN}`. Do not set routes, account IDs, or secrets in this repository unless they are intentionally public. ## Placement verification 1. Point a temporary monitor at a controlled HTTPS echo service that records source metadata and returns request headers. 2. Invoke every enabled probe for 24 hours and retain the Worker result `colo` plus the echo service records. 3. Compare the logical-region streams and Cloudflare Trace output (`https:///cdn-cgi/trace`) over time. The expected evidence is regional affinity, not a permanently fixed city, PoP, or source IP. 4. Record unexpected convergence or outages as a Cloudflare provider-failure caveat; these Workers do not offer provider-independent evidence. Workers cannot reveal the full DNS resolution chain or final TCP destination used by `fetch`. The Worker rejects forbidden literal addresses and revalidates redirect URLs, but protect sensitive internal origins independently and do not use this MVP as an SSRF boundary for private networks.