Cloudflare routing
The API uses the existing igris-coolify tunnel on Igris.
| Setting | Value |
|---|---|
| API DNS | Proxied CNAME api.pulsar.investments |
| CNAME target | 9b020927-546b-4a69-9d14-afba6025f2c2.cfargotunnel.com |
| Tunnel hostname | api.pulsar.investments |
| Tunnel service | http://edge-caddy:80 |
| Normal Caddy upstream | coolify-proxy:80 |
Cloudflare terminates TLS for HTTPS and WSS. Internal traffic stays on Docker networks. Caddy preserves the hostname so Coolify can select the backend. The temporary recovery upstream is recorded in the incident note.
Caddy configuration lives at /home/woosal/dev/edge/Caddyfile on Igris. The public API route blocks /api/diag and its child paths because the legacy diagnostic response can expose connection details.
Vercel hosts pulsar.investments. Cloudflare R2 serves bank icons from the finance-assets bucket at https://cdn.pulsar.investments. Set the backend's CDN_BASE_URL to this URL.
