Skip to content

fix(cloudflare/hyperdrive): only contribute the dev origin to local hosts - #1839

Merged
sam-goodwin merged 3 commits into
alchemy-run:mainfrom
DivMode:fix/hyperdrive-deploy-dev-origin
Oct 6, 2026
Merged

sam-goodwin merged 3 commits into
alchemy-run:mainfrom
DivMode:fix/hyperdrive-deploy-dev-origin

Conversation

@DivMode

@DivMode DivMode commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #1836

A Hyperdrive whose origin sits behind Cloudflare Access, with no dev override, now deploys:

const token = yield* Cloudflare.Access.ServiceToken("DbToken", {});
const db = yield* Cloudflare.Hyperdrive.Connection("Db", {
  origin: {
    scheme: "postgres",
    host: "db.example.com", // Access-protected, reached through a Tunnel
    database: "app",
    user: "app",
    password,
    accessClientId: token.clientId.pipe(Output.map(Redacted.make)),
    accessClientSecret: token.clientSecret.pipe(Output.map((s) => s!)),
  },
});
// before: `alchemy deploy` failed with "…requires Cloudflare Access. This is not supported in development mode…"
// after:  deploys; only a local Worker under `alchemy dev` still needs `dev`

ConnectBinding, and the async-Worker env path in WorkerAsyncBindings, always attached the hyperdrives dev-origin record to the host's bind data. That record is an Output.map that throws for an Access-protected origin with no dev override, and Apply evaluates every binding before reconciling the host. Only LocalWorkerProvider reads it, so it is now contributed only when the host Worker runs locally (host.Mode ?? defaultProviderMode is "local"), the same resolution the planner uses and the same gate bindWorkerAsyncBindings applies to Access enrollment.

  • alchemy dev with a local Worker keeps the existing error.
  • An Alchemy.remote() Worker in dev no longer needs a dev origin.
  • Live Workers no longer carry the dev origin in their binding data, so expect one no-op Worker update on the first deploy after upgrading.

Hyperdrive.test.ts deploys a real Access-protected origin: Postgres in Docker behind a Cloudflare Tunnel (cloudflared runs on the test machine), guarded by a self-hosted Access app admitting one service token. An Effect Worker (Hyperdrive.Connect) and an async Worker (env) both bind the Connection without dev and run a query through it. It is skipped when cloudflared or docker is missing.

DivMode and others added 3 commits September 24, 2026 22:45
…osts

`ConnectBinding` (and the async-Worker `env` path in `WorkerAsyncBindings`)
always attached the `hyperdrives` dev-origin record to the host's bind data.
That record is an `Output.map` that throws for an Access-protected origin with
no `dev` override, and Apply evaluates every binding before reconciling the
host, so `alchemy deploy` failed with "...not supported in development mode..."
even though the live Worker provider never reads `hyperdrives`.

The record is now contributed only when the host runs locally
(`host.Mode ?? defaultProviderMode` is "local"), the same resolution the
planner uses and the same gate `bindWorkerAsyncBindings` already applies to
Access enrollment and `maybeQueueShim` to the queue shim.

Fixes alchemy-run#1836

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…gin end to end

Postgres in Docker behind a Cloudflare Tunnel (cloudflared run locally),
guarded by a self-hosted Access app admitting one service token. Both
binding flavors bind the Connection without a dev override and query
through it. Replaces the in-memory ConnectBinding.test.ts.
@alchemy-version-bot

Copy link
Copy Markdown
Contributor

Install the packages built from this commit:

alchemy

pnpm install https://pkg.alchemy.run/alchemy/pr:1839:c5294bd
@alchemy.run (6)
pnpm install https://pkg.alchemy.run/@alchemy.run/better-auth/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@alchemy.run/cloudflare-runtime/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@alchemy.run/frontend-frameworks/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@alchemy.run/node-utils/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@alchemy.run/floci/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@alchemy.run/pkg/pr:1839:c5294bd
@distilled.cloud (16)
pnpm install https://pkg.alchemy.run/@distilled.cloud/core/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/acme/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/aws/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/axiom/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/cloudflare/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/doppler/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/fly-io/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/github/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/hetzner/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/infisical/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/neon/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/prisma/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/planetscale/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/railway/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/stripe/pr:1839:c5294bd
pnpm install https://pkg.alchemy.run/@distilled.cloud/zerossl/pr:1839:c5294bd

Published Oct 6, 2026, 4:29 PM UTC. Expires Oct 13, 2026, 4:29 PM UTC, extended while this pull request is open.

@sam-goodwin
sam-goodwin merged commit 4fa290b into alchemy-run:main Oct 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hyperdrive: deploy requires a dev origin when the origin is protected by Cloudflare Access

2 participants