kamakiri cdn

The CDN feature is in alpha. CDN walks through choosing a provider, the DNS records each one needs, switching and turning the CDN off.

kamakiri cdn cloudflare

kamakiri cdn cloudflare [--no-wait]

Routes the site through Cloudflare, then waits until every domain that serves content is served through Cloudflare over HTTPS. It keeps waiting on a terminal that is not interactive. --no-wait returns as soon as the change is accepted.

Until Cloudflare has registered a hostname, its line reads ⧗ registering with Cloudflare… and no record is shown yet.

A domain Cloudflare reports unhealthy is still serving, so the run ends on a ⚠ live via Cloudflare line counting such domains, and exits 0. A domain that ends in an error state, or in a state this version of the client does not recognise, ends the run with a per-domain breakdown and exits 1.

A site whose content-serving domain is an apex is refused before anything changes, and the command exits 1.

On a site that is on WebAccel, the command switches provider. It turns the CDN off, waits until the site is live without it, then goes live on Cloudflare, opening with Switching CDN from WebAccel to Cloudflare. This routes through direct serving so your site never drops. A switch needs an interactive terminal. With --no-wait, or without one, it only turns the CDN off and prints Once your site is serving directly (kamakiri status), run: kamakiri cdn cloudflare.

kamakiri cdn webaccel

kamakiri cdn webaccel [--token <token>] [--secret <secret>] [--no-wait]

Routes the site through Sakura Web Accelerator, creating a WebAccel resource for each domain in your Sakura account, then waits until every domain is served through WebAccel over HTTPS. It waits and takes --no-wait as kamakiri cdn cloudflare does, and on a Cloudflare site it switches provider the same way.

It takes the token and the secret from the first of these that has them:

  1. --token and --secret;
  2. KAMAKIRI_CDN_TOKEN and KAMAKIRI_CDN_SECRET;
  3. the credentials already stored, on a site that is on WebAccel;
  4. a prompt, with the secret hidden on a terminal.

In CI and in a shared shell, use the environment variables. A command-line argument shows in the process list and in your shell history.

On a first setup the command explains what it will do with the token, and where to create one, before it prompts. A stored token that Sakura now rejects is not reused: the command says so and asks for a new one. When Sakura rejects the credentials you enter, the command names the access the token needs and where to create a new one, and exits 1. The prompts read standard input even when it is not a terminal, so a piped value is taken as the answer, and input that ends before an answer exits 1.

Three states stop the run instead of waiting, and it exits 1 naming each affected domain and what clears it:

Fix the cause and run the command again to resume.

kamakiri cdn none

kamakiri cdn none [--no-wait]

Turns the CDN off and waits until every domain is served directly again, over HTTPS with our certificate. On a site with nothing behind the CDN it prints Traffic goes directly to origin. and returns.

On a terminal that is not interactive, it waits until the change has taken effect on our side, prints the records you need to re-point, and exits 0 without waiting for them. --no-wait returns as soon as the change is accepted, with no records shown.

A stopped wait resumes with kamakiri domain verify <domain> or kamakiri status, not with kamakiri cdn verify. The command exits 1 when the change fails.

kamakiri cdn cleanup

kamakiri cdn cleanup [--no-wait]

Deletes the site’s WebAccel resources that no domain uses any more, and waits until they are gone.

$ kamakiri cdn cleanup
Cleaning up 1 orphaned CDN resource(s)... done.
$ kamakiri cdn cleanup
未使用のCDNリソースを1件削除しています... 完了しました。

It does not check DNS. A resource your domain still points at is deleted, and that domain goes down until you re-point it. CDN gives the safe order.

A resource you already deleted yourself counts as done. When the stored credentials can no longer delete a resource, the line ends blocked., followed by The stored Sakura credentials are no longer valid, so we cannot delete the resource(s). and Remove them in your Sakura panel. The command exits 1 when every remaining resource is blocked this way.

With nothing to delete it prints Nothing to clean up. No orphaned CDN resources for this site. --no-wait returns once the deletion is accepted.

kamakiri cdn verify

kamakiri cdn verify

Re-attaches to the go-live of kamakiri cdn cloudflare or kamakiri cdn webaccel after a Ctrl-C, or from another machine, and waits as they do. It changes nothing, and unlike kamakiri domain verify it does not ask for a fresh check. It takes no flags.

On a site with no CDN it prints two lines and exits 0: No CDN configured. Run `kamakiri cdn cloudflare` or `kamakiri cdn webaccel` to add one. and If you just ran `kamakiri cdn none`, use `kamakiri status` to watch the site return to direct serving.

kamakiri cdn credentials

kamakiri cdn credentials [--token <token>] [--secret <secret>] [--no-wait]

Replaces the stored WebAccel token and secret, and changes nothing else.

$ kamakiri cdn credentials --token <token> --secret <secret>
Rotating WebAccel credentials... done.
$ kamakiri cdn credentials --token <token> --secret <secret>
WebAccel の認証情報を更新しています... 完了しました。

It reads the values from the flags, then KAMAKIRI_CDN_TOKEN and KAMAKIRI_CDN_SECRET, then a prompt with the secret hidden. It never falls back to the stored credentials. The environment variables keep the secret out of the process list and your shell history. As with kamakiri cdn webaccel, a piped value is taken as the answer, and input that ends before an answer exits 1.

The site must already be on WebAccel. Otherwise the command exits 1 with this site has no WebAccel configuration to update. Run "kamakiri cdn webaccel" first.

The command waits until Sakura has checked the new credentials. When they are rejected the line ends failed. and the command exits 1. --no-wait returns as soon as the change is accepted.

Failing credentials also show up later in kamakiri cdn and kamakiri status. The site keeps serving either way, since delivery does not depend on them, but purges fail until the credentials are fixed, and so does the CDN step of a deploy’s wait.

kamakiri cdn status

kamakiri cdn status

Prints the site’s CDN mode and a row per domain that serves content, the canonical domain and its aliases. Bare kamakiri cdn does the same.

$ kamakiri cdn
CDN:  cloudflare
  www.example.com  ✓ via Cloudflare
$ kamakiri cdn
CDN:  cloudflare
  www.example.com  ✓ Cloudflare 経由

A domain still waiting on Cloudflare validation lists the records to add under its row. A domain whose delivery record no longer points where it was assigned shows a warning with the record to restore.

Two lines can appear above the rows. One says the WebAccel API credentials are failing and names kamakiri cdn credentials. The other counts the resources awaiting kamakiri cdn cleanup, and how many of them are blocked on invalid credentials. That count also appears on a site with no CDN.

The command takes no flags, waits for nothing, and exits 0. kamakiri status shows the same rows.

kamakiri cdn purge

kamakiri cdn purge [--no-wait]

Flushes the CDN cache for every domain, and waits until the provider has accepted a purge of the current deploy for each one. A deploy or a rollback already does this on its own.

$ kamakiri cdn purge
✓ caches flushed (~1m)
$ kamakiri cdn purge
✓ キャッシュをクリアしました(約1分)

It exits 1 on a site with no CDN (site has no CDN configured. Run "kamakiri cdn <cloudflare|webaccel>" first), on a site that has never been deployed (site has no published content to purge. Run "kamakiri deploy <path>" first), and when the provider refuses the purge for a reason only you can fix, such as rejected credentials or a deleted resource. That last case prints a line saying what to do.

--no-wait returns once the purge is accepted, with CDN purge queued (--no-wait). The flush continues in the background; check kamakiri status.

Waiting and exit status

Ctrl-C stops the wait, not the work, which carries on on our side. kamakiri cdn verify or kamakiri status picks a go-live back up, from this machine or another. A wait stopped with Ctrl-C exits 130.

Every command exits 0 once what it waits for has happened, or, with --no-wait, once the request is accepted. Besides the cases above, every command exits 1 when there is no credential or the API key is rejected, when no site is linked, when the server no longer supports this version of the client, when a request fails or is refused, and on a flag or argument it does not take.

At the token prompt, Ctrl-C exits 130. At the hidden secret prompt, Ctrl-C exits 1, and Ctrl-D is read as a character, not as the end of input.