diff --git a/README.md b/README.md index c4b0f6c..1d028e7 100644 --- a/README.md +++ b/README.md @@ -42,6 +42,7 @@ The setup wizard will: - create or attach a D1 database - prompt for the required secrets +- write the hostname allowlist into `wrangler.jsonc` - validate the worker configuration - offer to apply migrations and deploy immediately @@ -105,11 +106,24 @@ You can also use `pnpm setup:secrets`, which prompts for the values and uploads | `CF_API_TOKEN` | Cloudflare API token with DNS:Edit for your zone | | `CF_ZONE_ID` | Zone ID (visible on your domain's overview page in the dashboard) | | `DDNS_SHARED_SECRET` | A password you choose. Callers must send this to authenticate. | -| `DDNS_ALLOWED_HOSTNAMES` | Comma-separated hostnames this worker may update, e.g. `nas.example.com,home.example.com`. Wildcard companions such as `*.nas.example.com` are supported as explicit entries. | - The repository includes [`.env.production.example`](./.env.production.example) so the manual upload path has a ready-made template. -### 4. Deploy +### 4. Configure allowed hostnames + +Set `DDNS_ALLOWED_HOSTNAMES` in `wrangler.jsonc` under `vars`: + +```jsonc +"vars": { + "DDNS_ALLOWED_HOSTNAMES": "nas.example.com,*.nas.example.com", + "DDNS_PROXIED": "false", + "DDNS_TTL": "1", + "DDNS_LOG_RETENTION_DAYS": "30" +} +``` + +You can also use `pnpm setup:secrets`, which uploads the actual secrets and writes `DDNS_ALLOWED_HOSTNAMES` into `wrangler.jsonc` for you. + +### 5. Deploy ```sh pnpm deploy @@ -119,10 +133,11 @@ This runs D1 migrations automatically before deploying. ## Environment variables -These non-secret variables have defaults in `wrangler.jsonc` and can be overridden per-environment: +These non-secret variables live in `wrangler.jsonc` and can be overridden per-environment: | Variable | Default | Description | |---|---|---| +| `DDNS_ALLOWED_HOSTNAMES` | none | Required. Comma-separated hostnames this worker may update, e.g. `nas.example.com,home.example.com`. Wildcard companions such as `*.nas.example.com` are supported as explicit entries. | | `DDNS_PROXIED` | `"false"` | Whether DNS records are proxied through Cloudflare. Most NAS setups need `"false"` (DNS-only) for direct IP access on non-standard ports. | | `DDNS_TTL` | `"1"` | DNS record TTL in seconds. `"1"` means automatic. Valid range: 60-86400. | | `DDNS_LOG_RETENTION_DAYS` | `"30"` | How many days of update logs to keep in D1. A cron job runs every 6 hours to prune older rows. | diff --git a/package.json b/package.json index 2deea0e..5503361 100644 --- a/package.json +++ b/package.json @@ -8,6 +8,7 @@ "pnpm": ">=9" }, "dependencies": { + "@clack/prompts": "^1.2.0", "chanfana": "^3.3.0", "cloudflare": "^5.2.0", "hono": "4.12.9", @@ -31,5 +32,30 @@ "predeploy": "node --experimental-strip-types ./scripts/verify-setup.ts && wrangler d1 migrations apply DB --remote", "dev": "wrangler d1 migrations apply DB --local && wrangler dev", "test": "wrangler deploy --dry-run && npx vitest run --config tests/vitest.config.mts" + }, + "cloudflare": { + "bindings": { + "CF_API_TOKEN": { + "description": "Cloudflare API token with Zone > DNS > Edit permission for the zone this worker will update." + }, + "CF_ZONE_ID": { + "description": "Zone ID from your domain overview page in the Cloudflare dashboard." + }, + "DDNS_SHARED_SECRET": { + "description": "Long random password used by Synology or other clients to authenticate update requests." + }, + "DDNS_ALLOWED_HOSTNAMES": { + "description": "Comma-separated allowlist of DNS names this worker may update, for example nas.example.com,*.nas.example.com." + }, + "DDNS_PROXIED": { + "description": "Set to false for most NAS setups. Use true only if you want the updated records proxied through Cloudflare." + }, + "DDNS_TTL": { + "description": "Use 1 for automatic TTL, or a value from 60 to 86400 seconds." + }, + "DDNS_LOG_RETENTION_DAYS": { + "description": "How many days of update logs to keep in D1 before scheduled cleanup removes them." + } + } } } diff --git a/tsconfig.scripts.json b/tsconfig.scripts.json index 344015d..af6c8a6 100644 --- a/tsconfig.scripts.json +++ b/tsconfig.scripts.json @@ -9,5 +9,5 @@ "allowImportingTsExtensions": true, "noEmit": true }, - "include": ["scripts/**/*.ts"] + "include": ["scripts/**/*.ts", "scripts/**/*.d.ts"] } \ No newline at end of file diff --git a/wrangler.jsonc b/wrangler.jsonc index 8fc864a..ccfaaa9 100644 --- a/wrangler.jsonc +++ b/wrangler.jsonc @@ -30,11 +30,11 @@ "required": [ "CF_API_TOKEN", "CF_ZONE_ID", - "DDNS_SHARED_SECRET", - "DDNS_ALLOWED_HOSTNAMES" + "DDNS_SHARED_SECRET" ] }, "vars": { + "DDNS_ALLOWED_HOSTNAMES": "nas.example.com,*.nas.example.com", "DDNS_PROXIED": "false", "DDNS_TTL": "1", "DDNS_LOG_RETENTION_DAYS": "30"