This guide is for your deployment repository (a fork or copy of FlareMo). The workflow is .github/workflows/deploy-cloudflare.yml. It only runs from a manual Run workflow click; pushes do not publish. The upstream repository realchendahuang/FlareMo never runs this job.
The maintained paths remain local pnpm deploy, or the Deploy to Cloudflare button with Workers Builds. Do not put BETTER_AUTH_SECRET or FLAREMO_BOOTSTRAP_SECRET in the workflow file, issues, PRs, chat, or workflow_dispatch inputs: GitHub stores those form values in the run record. Keep them in repository Settings → Secrets.
- The deployment repository includes
.github/workflows/deploy-cloudflare.yml. - The Cloudflare account has Workers enabled and an account-level
*.workers.devsubdomain. - Two distinct random secrets of at least 32 characters, stored in a password manager first:
openssl rand -base64 48
openssl rand -base64 48Use them as BETTER_AUTH_SECRET (session signing) and FLAREMO_BOOTSTRAP_SECRET (one-time /setup passphrase). GitHub cannot show a saved Secret again.
Open API Tokens → Create Token. Start from Edit Cloudflare Workers and add:
- Account → D1 → Edit
- Account → Workers R2 Storage → Edit
- Account → Queues → Edit
- Account → Vectorize → Edit
- Account → Workers Scripts → Edit (usually included)
The Account ID is on the right side of the Cloudflare dashboard home page.
In the deployment repository, open Settings → Actions → General:
- Allow GitHub Actions.
- If you also use the update flow to open upgrade PRs: grant read/write workflow permissions and allow Actions to create pull requests. Deploy-only runs only need contents read.
Open Settings → Secrets and variables → Actions and add:
| Name | Required | Purpose |
|---|---|---|
CLOUDFLARE_API_TOKEN |
Yes | Token from step 1 |
CLOUDFLARE_ACCOUNT_ID |
Yes | Cloudflare account ID |
BETTER_AUTH_SECRET |
Yes if you need login | ≥32 characters; synced to the Worker secret store |
FLAREMO_BOOTSTRAP_SECRET |
Yes if you need /setup |
≥32 characters, different from the previous value |
Do not set:
FLAREMO_D1_DATABASE_ID: the workflow creates or reuses D1flaremoby name.FLAREMO_PUBLIC_URL: if empty, it becomeshttps://flaremo.<account workers.dev subdomain>.workers.dev.WRANGLER_JSONC: only if you already have a fullwrangler.jsoncthat cannot be generated from the example.
For a custom domain, bind it to the Worker in Cloudflare, set repository Variable FLAREMO_PUBLIC_URL to that origin (for example https://notes.example.com, no path), then run the workflow again.
Open Actions → Deploy to Cloudflare → Run workflow:
- On the first attempt, enable
dry_run: build, Wrangler dry-run, and a read-only check of the D1 / R2 / Queue / Vectorize resources plus API token permissions. Nothing is created; remote D1 migration, publish, and secret sync are skipped. Missing resources or insufficient token permissions are reported right here. - Leave
provisionenabled: create missing D1, R2, Queue, and Vectorize resources. Existing names are skipped. - After dry-run succeeds, run again without
dry_run, withprovisionstill enabled.
A production run will:
- Generate a job-local
wrangler.jsoncfromwrangler.jsonc.example(not committed). - Create or reuse D1
flaremo, R2flaremo-attachments, queuesflaremo-member-removalandflaremo-data-export, and Vectorize indexesflaremo-memosandflaremo-memories(1024 dimensions, cosine). - If
FLAREMO_PUBLIC_URLis unset, writehttps://flaremo.<subdomain>.workers.dev. - Run
pnpm deploy: build the web app, apply remote D1 migrations, publish the Worker. - Copy GitHub Secrets
BETTER_AUTH_SECRETandFLAREMO_BOOTSTRAP_SECRETonto the Worker. Logs show***. - Smoke check: request
FLAREMO_PUBLIC_URLto confirm the Worker serves traffic, retrying for about a minute; a site that stays unreachable marks the run red.
If those two GitHub Secrets are missing, the sync step skips and deploy still finishes; /setup and login will fail until you add the Secrets and run again without dry_run, or add them in Cloudflare Dashboard → Worker → Settings → Variables and Secrets.
The deploy log or Cloudflare Dashboard → Worker flaremo shows an origin such as:
https://flaremo.<subdomain>.workers.dev
Open https://<that origin>/setup and enter:
- Setup secret: the
FLAREMO_BOOTSTRAP_SECRETvalue - Username, display name, email, and an initial password (8–128 characters)
Success redirects to /login and public signup closes. Do not paste secrets or passwords into issues, PRs, logs, or chat.
| Situation | What to do |
|---|---|
| You changed application code | Push the default branch, then run Deploy to Cloudflare. You can uncheck provision once resources exist. |
| Upstream published a stable release | Follow the update guide to run Prepare FlareMo update, review and merge the PR, then run Deploy to Cloudflare. Merging the PR does not publish when you use this workflow. |
| Rotate auth secrets | Change the GitHub Secrets and run a production deploy (overwrites the Worker secrets). |
| Switch to a custom domain | Bind the domain in Cloudflare, set Variable FLAREMO_PUBLIC_URL, deploy again. |
This workflow never publishes on push. Every production deploy is a Run workflow click.
Prepare FlareMo update only opens an upgrade PR and does not hold Cloudflare credentials. Publishing is still Deploy to Cloudflare, local pnpm deploy, or Workers Builds.
These cannot be set in the FlareMo UI. Add them in Cloudflare when you need the feature:
| Item | When |
|---|---|
FLAREMO_RECOVERY_SECRET |
Break-glass owner password reset without email; delete or rotate after use |
FLAREMO_ASR_DASHSCOPE_API_KEY |
Default DashScope voice capture |
| Tencent ASR secret ID / key | When FLAREMO_ASR_PROVIDER is tencent |
| VAPID public/private keys | Web Push; these are vars, not secrets, and need a redeploy |
| Telegram / Cloudflare Access secrets | When those integrations are enabled |
- No
Deploy to Cloudflareworkflow: you are on the wrong repository, or the file is not on the default branch. - workers.dev subdomain lookup fails: register the account subdomain under Workers in the Cloudflare dashboard.
/setupfails: the two auth GitHub Secrets are missing or invalid, or the last run wasdry_runonly.- Queue / Vectorize / D1 create fails: the API token is missing permissions from step 1.
provisionstill checked on later deploys: existing names are skipped; that is expected.
The local equivalents (with Wrangler logged in) are pnpm provision:remote, pnpm deploy, and pnpm secrets:sync. The full CLI path is in the deployment guide.