Monitor websites uptime using Cloudflare Workers
README.md

Cloudflare regional probe deployments #

The wrangler.*.toml files in this directory are generated from the region registry in packages/regions. Do not hand-edit them:

pnpm generate:wrangler

Deploy the identical Worker source once per enabled region. The deployment names and regional affinity are intentionally explicit:

Deployment Logical region Placement hint
uptime-probe-us-east us-east aws:us-east-1
uptime-probe-us-west us-west aws:us-west-2
uptime-probe-canada-central canada-central aws:ca-central-1
uptime-probe-eu-west eu-west aws:eu-west-1
uptime-probe-eu-north eu-north aws:eu-north-1
uptime-probe-eu-south eu-south aws:eu-south-1
uptime-probe-asia asia aws:ap-southeast-1
uptime-probe-asia-east asia-east aws:ap-northeast-1
uptime-probe-asia-south asia-south aws:ap-south-1

From the repository root, authenticate Wrangler, then deploy every discovered configuration with the identical high-entropy signing secret:

pnpm --filter @uptime/probe-worker exec wrangler login
scripts/deploy-workers.sh --dry-run
scripts/deploy-workers.sh --secrets-file /path/to/probe-secrets.env

scripts/deploy-workers.sh reads REGIONS_LIST from the process environment or the repository .env file and deploys only those Wrangler configurations, preserving list order. For example:

REGIONS_LIST="asia-east,asia-south"

The API exposes only this subset in the monitor editor, monitor saves reject disabled regions, and the scheduler skips disabled regions. When REGIONS_LIST is omitted, all canonical regions remain enabled for backward compatibility.

Every regional Wrangler configuration enables Cloudflare Workers observability. Deploying the fleet persists Worker logs in the Cloudflare dashboard for each regional Worker.

Set WORKERS_URL_DOMAIN in the scheduler environment to the shared suffix printed by Wrangler, such as account-subdomain.workers.dev. The scheduler combines it with each canonical Worker name to produce https://uptime-probe-{region}.{WORKERS_URL_DOMAIN}. Do not set routes, account IDs, or secrets in this repository unless they are intentionally public.

Placement verification #

  1. Point a temporary monitor at a controlled HTTPS echo service that records source metadata and returns request headers.
  2. Invoke every enabled probe for 24 hours and retain the Worker result colo plus the echo service records.
  3. Compare the logical-region streams and Cloudflare Trace output (https://<probe>/cdn-cgi/trace) over time. The expected evidence is regional affinity, not a permanently fixed city, PoP, or source IP.
  4. Record unexpected convergence or outages as a Cloudflare provider-failure caveat; these Workers do not offer provider-independent evidence.

Workers cannot reveal the full DNS resolution chain or final TCP destination used by fetch. The Worker rejects forbidden literal addresses and revalidates redirect URLs, but protect sensitive internal origins independently and do not use this MVP as an SSRF boundary for private networks.