Cloudflare and Edge¶
Current role¶
Cloudflare handles public DNS, tunnels, Access protection, and selected webhook bypass paths.
Current topology:
api.exzentcg.com→ productiontelebot-prodVPS through Cloudflare/Nginx.- Telegram/admin frontends → Vercel.
otto.exzentcg.com→ Cloudflare Tunnel/NPM → LXC 108.n8n.exzentcg.com→ Cloudflare Tunnel/NPM → LXC 102.tcg-staging.exzentcg.com→ Cloudflare Tunnelexzentcg-ampere→ OCI Ampere VM (Medusa, loopback127.0.0.1:9000, behind Access).shop-staging.exzentcg.com→ Cloudflare Tunnelexzentcg-ampere→ OCI Ampere VM (storefront, loopback127.0.0.1:8000, public).dashboard-staging.exzentcg.com→ Cloudflare Workertcg-dashboard-staging(custom domain).api-tcg.exzentcg.com→ Cloudflare Tunnelexzentcg-ampere→ OCI Ampere VM (production Medusa, loopback127.0.0.1:9001, behind Access).shop.exzentcg.com→ Cloudflare Tunnelexzentcg-ampere→ OCI Ampere VM (production storefront, loopback127.0.0.1:8001, public).dashboard.exzentcg.com→ Cloudflare Workertcg-dashboard(custom domain, behind Access).docs.exzentcg.com→ Cloudflare Pages.hermes.exzentcg.com→ Cloudflare Tunnel → LXC 109.
Access configuration¶
All Access applications were renamed to a consistent exzen-<service>[-<env>][-webhook|-static] scheme (2026-08-07). Examples: exzen-n8n, exzen-otto-webhook, exzen-tcg-staging, exzen-tcg-dashboard-static.
Authenticated apps allow exzensg@gmail.com, exzentcg@gmail.com, admin@exzentcg.com, and kohhxuanqi@gmail.com.
Two reusable bypass policies exist:
exzen-*-webhookapps use Webhook Bypass (genuine webhook paths).exzen-tcg-dashboard-staticuses Static Assets Public (Next.js/_next/static,_next/image, favicon must be unauthenticated so the page renders).
Service token: exzen-tcg-dashboard-worker (used by exzen-tcg-staging non-identity policy).
Current notes¶
- Operator UIs are protected by Cloudflare Access; only webhook/static paths are proxied open.
- The orphaned
sneakydunkWorker was deleted (its only callerSNEAKYDUNK_.gshad already been removed). - The dead
ai.exzentcg.com/ "Ollama" route was fully removed (DNS, tunnel, NPM, and Access) — no such backend existed. - Zone TLS is hardened:
ssl=strict,always_use_https=on,min_tls_version=1.2,tls_1_3=on,security_level=high. - There is currently no active uptime monitoring; the old Uptime/status route was confirmed stale and removed. Backups/monitoring remain open risks.