BluTown hostname authority (Option C — split hostnames)¶
Packet: BLUTOWN_HOSTNAME_AUTHORITY_SPLIT_001
IaC: PROJECTS/iac/cloudflare/tunnels/bluefly-platform-routes.yaml
Hostname map (Oracle bluefly-platform)¶
| Hostname | Owner | Origin | Role |
|---|---|---|---|
blutown.blueflyagents.com |
BluTown/dashboard (Next.js) |
http://127.0.0.1:3000 |
Read-only operator projection |
gascity.blueflyagents.com |
gt dashboard |
http://127.0.0.1:8081 |
Native Gas City convoy dashboard |
adash.blueflyagents.com |
AgentDash Drupal | http://127.0.0.1:3013 |
Drupal admin dashboard |
Auth¶
- Cloudflare Access on all three hostnames (
access_required). - Secrets: 1Password +
.op-envviaop run— never commit tokens. - A naked 403 on public URLs without an Access session is not an origin failure.
Oracle deploy (Next.js — blutown hostname)¶
ssh [email protected]
cd ~/gt/blutown/dashboard # or synced BluTown/dashboard tree
export GT_TOWN_ROOT=/home/ubuntu/gt
npm ci && npm run build
HOSTNAME=127.0.0.1 PORT=3000 npx next start -H 127.0.0.1 -p 3000
Use 127.0.0.1 only — contractplane-ai docker already binds 100.103.48.75:3000.
systemd (Oracle): blutown-dashboard.service in /home/ubuntu/gt/blutown/mayor/rig/dashboard.
Tunnel ingress must point blutown.blueflyagents.com → http://127.0.0.1:3000.
Oracle deploy (gt dashboard — gascity hostname)¶
# systemd: gt-dashboard.service
gt dashboard --bind 0.0.0.0 --port 8081
Tunnel ingress must point gascity.blueflyagents.com → http://127.0.0.1:8081.
opsDash¶
dashboard/opsDash/ is deprecated mock (Vite + fixtures). Do not deploy. Port patterns into this Next app only.
Live tunnel drift (correct in CF dashboard)¶
If Cloudflare shows the wrong origins, fix immediately:
| Hostname | Wrong (observed) | Correct |
|---|---|---|
blutown.blueflyagents.com |
http://localhost:8081 |
http://localhost:3000 |
gascity.blueflyagents.com |
http://localhost:3013 |
http://localhost:8081 |
3013 is adash only — never gascity. 8081 is gt dashboard only — never blutown.
Regenerate and sync from IaC:
cd PROJECTS/iac
npm run generate:routes:oracle
TUNNEL_ROUTES_PATH=config-templates/tunnel-routes.json \
op run --account blueflyiollc --env-file=.../.op-env -- \
node ../agent-docker/k8s/cloudflared-oracle/sync-tunnel-config.mjs
Health checks¶
# Origin (Oracle)
curl -sI http://127.0.0.1:3000
curl -sI http://127.0.0.1:8081
# Public (may 403 without Access)
curl -sI https://blutown.blueflyagents.com/
curl -sI https://gascity.blueflyagents.com/