Skip to content

Cloudflare and Edge

Current role

Cloudflare handles public DNS, tunnels, Access protection, and selected webhook bypass paths.

Current topology:

  • api.exzentcg.com → production telebot-prod VPS through Cloudflare/Nginx.
  • Telegram/admin frontends → Vercel.
  • otto.exzentcg.com → Cloudflare Tunnel/NPM → LXC 108.
  • n8n.exzentcg.com → Cloudflare Tunnel/NPM → LXC 102.
  • tcg-staging.exzentcg.com → Cloudflare Tunnel exzentcg-ampere → OCI Ampere VM (Medusa, loopback 127.0.0.1:9000, behind Access).
  • shop-staging.exzentcg.com → Cloudflare Tunnel exzentcg-ampere → OCI Ampere VM (storefront, loopback 127.0.0.1:8000, public).
  • dashboard-staging.exzentcg.com → Cloudflare Worker tcg-dashboard-staging (custom domain).
  • api-tcg.exzentcg.com → Cloudflare Tunnel exzentcg-ampere → OCI Ampere VM (production Medusa, loopback 127.0.0.1:9001, behind Access).
  • shop.exzentcg.com → Cloudflare Tunnel exzentcg-ampere → OCI Ampere VM (production storefront, loopback 127.0.0.1:8001, public).
  • dashboard.exzentcg.com → Cloudflare Worker tcg-dashboard (custom domain, behind Access).
  • docs.exzentcg.com → Cloudflare Pages.
  • hermes.exzentcg.com → Cloudflare Tunnel → LXC 109.

Access configuration

All Access applications were renamed to a consistent exzen-<service>[-<env>][-webhook|-static] scheme (2026-08-07). Examples: exzen-n8n, exzen-otto-webhook, exzen-tcg-staging, exzen-tcg-dashboard-static.

Authenticated apps allow exzensg@gmail.com, exzentcg@gmail.com, admin@exzentcg.com, and kohhxuanqi@gmail.com.

Two reusable bypass policies exist:

  • exzen-*-webhook apps use Webhook Bypass (genuine webhook paths).
  • exzen-tcg-dashboard-static uses Static Assets Public (Next.js /_next/static, _next/image, favicon must be unauthenticated so the page renders).

Service token: exzen-tcg-dashboard-worker (used by exzen-tcg-staging non-identity policy).

Current notes

  • Operator UIs are protected by Cloudflare Access; only webhook/static paths are proxied open.
  • The orphaned sneakydunk Worker was deleted (its only caller SNEAKYDUNK_.gs had already been removed).
  • The dead ai.exzentcg.com / "Ollama" route was fully removed (DNS, tunnel, NPM, and Access) — no such backend existed.
  • Zone TLS is hardened: ssl=strict, always_use_https=on, min_tls_version=1.2, tls_1_3=on, security_level=high.
  • There is currently no active uptime monitoring; the old Uptime/status route was confirmed stale and removed. Backups/monitoring remain open risks.