CDN

The CDN feature is in alpha.

Choosing a provider

A site runs in one CDN mode at a time, and the mode covers every domain that serves content on it. The default is none, where the site is served directly with no CDN in front. kamakiri cdn sets the mode.

Going live on Cloudflare

Run kamakiri cdn cloudflare. It prints the validation records to publish, then waits until every domain is served through Cloudflare over HTTPS.

$ kamakiri cdn cloudflare
✓ CDN set to Cloudflare

Configure your DNS (Cloudflare validation):
    add TXT  _cf-custom-hostname.www.example.com → <token>

  Add the record above at your registrar, then come back.
  Safe to close any time (Ctrl-C). Re-run `kamakiri cdn verify` or `kamakiri status` to resume.

✓ Cloudflare validated (~25m)
✓ DNS pointed at the Cloudflare edge
✓ SSL certificate checked
✓ live via Cloudflare: https://www.example.com
$ kamakiri cdn cloudflare
✓ CDNを Cloudflare に設定しました

DNSを設定してください(Cloudflare の確認用レコード):
    TXTを追加  _cf-custom-hostname.www.example.com → <token>

  上記のレコードをレジストラで追加したら、戻ってきてください。
  いつでも閉じて構いません (Ctrl-C)。`kamakiri cdn verify` または `kamakiri status` を再実行すると再開できます。

✓ Cloudflare の確認が完了しました(約25分)
✓ DNSを Cloudflare のエッジに向けました
✓ SSL証明書を確認しました
✓ Cloudflare 経由で公開中: https://www.example.com

Traffic reaches Cloudflare through the record direct serving already uses, the one pointing your domain at its target: the host under kamakiri-pages.site that Custom domains has you publish. If that record is missing or points elsewhere, the command shows it and keeps waiting.

Cloudflare cannot serve an apex domain such as example.com. When a domain that serves content on the site is an apex, the command refuses before it changes anything. Make a www. subdomain the domain that serves content, and redirect the apex to it, as Custom domains describes. An apex works on WebAccel or with no CDN.

Going live on WebAccel

WebAccel needs a Sakura API token and its secret. Create the token in the Sakura Cloud control panel, under API keys, with access to Web Accelerator only and permission to create and delete resources. In CI, pass the two values in KAMAKIRI_CDN_TOKEN and KAMAKIRI_CDN_SECRET rather than as flags.

Run kamakiri cdn webaccel. It creates a WebAccel resource for each domain, then asks for two records per domain, in order, and waits for each.

$ kamakiri cdn webaccel --token <token> --secret <secret>
CDN set to WebAccel.
✓ WebAccel resource created/updated

Add this DNS record to prove you own the domain (phase 1 of 2):

    _webaccel.shop.example.com  TXT  webaccel=ubol03ca.user.webaccel.jp

  Add the record above at your registrar. This proves ownership only; it does not
  move any traffic yet (the cutover is the next record).
  Safe to close any time (Ctrl-C). Re-run `kamakiri cdn verify` or `kamakiri status` to resume.

✓ domain ownership verified
✓ WebAccel enabled

Add this DNS record to send traffic to WebAccel (phase 2 of 2, the cutover):

    shop.example.com  CNAME  ubol03ca.user.webaccel.jp.

  This is the cutover: once it resolves, public traffic flows to WebAccel and
  WebAccel issues the HTTPS certificate. A brief HTTPS gap is normal while it does.
  Safe to close any time (Ctrl-C). Re-run `kamakiri cdn verify` or `kamakiri status` to resume.

✓ your delivery CNAME is live (traffic now flows to WebAccel)
✓ SSL certificate checked
✓ live via WebAccel: https://shop.example.com
$ kamakiri cdn webaccel --token <token> --secret <secret>
CDNを WebAccel に設定しました。
✓ WebAccel リソースを作成・更新しました

ドメインの所有権を証明するため、次のDNSレコードを追加してください(手順1/2):

    _webaccel.shop.example.com  TXT  webaccel=ubol03ca.user.webaccel.jp

  上記のレコードをレジストラで追加してください。これは所有権の証明のみで、
  トラフィックはまだ移動しません(切り替えは次のレコードです)。
  いつでも閉じて構いません (Ctrl-C)。`kamakiri cdn verify` または `kamakiri status` を再実行すると再開できます。

✓ ドメインの所有権を確認しました
✓ WebAccel を有効にしました

WebAccel へトラフィックを送るため、次のDNSレコードを追加してください(手順2/2、切り替え):

    shop.example.com  CNAME  ubol03ca.user.webaccel.jp.

  これが切り替えです。解決されると公開トラフィックが WebAccel へ流れ、
  WebAccel がHTTPS証明書を発行します。その間、HTTPSが短時間途切れることがあります。
  いつでも閉じて構いません (Ctrl-C)。`kamakiri cdn verify` または `kamakiri status` を再実行すると再開できます。

✓ 配信用CNAMEが有効になりました(トラフィックは WebAccel へ流れています)
✓ SSL証明書を確認しました
✓ WebAccel 経由で公開中: https://shop.example.com

The TXT record proves you own the domain and moves no traffic. The second record is the cutover: it points your domain at the WebAccel Subdomain assigned to it, and HTTPS may fail for a short while as WebAccel issues the certificate. At an apex the second record must be an ALIAS or ANAME. If your registrar cannot publish one at the apex, use a www. subdomain.

Switching provider

Run the other provider’s command: kamakiri cdn cloudflare on a WebAccel site, or kamakiri cdn webaccel on a Cloudflare site. The switch passes through direct serving, so the site is briefly served without a CDN and never goes down. Leaving WebAccel, the command first asks you to point each domain back at its target, then shows the records the new provider needs.

Run the switch in an interactive terminal. With --no-wait, or without a terminal, the command only turns the CDN off and prints the command to run once the site is serving directly.

Turning the CDN off

Run kamakiri cdn none. What you change in DNS depends on the provider you leave.

Leaving WebAccel, each domain points at its WebAccel Subdomain, so point it back at its target: a CNAME for a subdomain, and an ALIAS, an ANAME or the A records for an apex. The WebAccel resource keeps serving until the new record takes effect, so there is no gap.

$ kamakiri cdn none
✓ CDN deactivated
  The WebAccel resource(s) for www.example.com remain in your Sakura account.
  Run `kamakiri cdn cleanup` to delete them (repoint your DNS off them first, or those domains go down).

Configure your DNS:
  www.example.com  CNAME  → h1lc-qpb6r87d79wfblfj.c1.kamakiri-pages.site.

www.example.com
  Update the DNS record above at your registrar, then come back.
  Safe to close any time (Ctrl-C). Re-run `kamakiri domain verify www.example.com` or `kamakiri status` to resume.

✓ DNS propagated
✓ SSL certificate provisioned
✓ live: https://www.example.com

(note: if your browser shows an error, DNS might not have propagated close to you)
$ kamakiri cdn none
✓ CDNを無効にしました
  www.example.com の WebAccel リソースはお使いのさくらのクラウドアカウントに残ります。
  `kamakiri cdn cleanup` を実行すると削除できます(先にDNSを向け直してください。そのままだと該当ドメインが停止します)。

DNSを設定してください:
  www.example.com  CNAME  → h1lc-qpb6r87d79wfblfj.c1.kamakiri-pages.site.

www.example.com
  上記のDNSレコードをレジストラで更新したら、戻ってきてください。
  いつでも閉じて構いません (Ctrl-C)。`kamakiri domain verify www.example.com` または `kamakiri status` を再実行すると再開できます。

✓ DNSの反映を確認しました
✓ SSL証明書を発行しました
✓ 公開中: https://www.example.com

(ブラウザでエラーが表示される場合、お近くまでDNSが反映されていない可能性があります)

If you turn WebAccel on again later, it reuses the same resource and the same Subdomain, so you point the domain back at the Subdomain it had.

Leaving Cloudflare, your record already points at the target, so you change nothing, and the site serves directly again on its own.

Deleting WebAccel resources

A WebAccel resource stays in your Sakura account, and Sakura keeps charging for it, until you delete it. Turning the CDN off, switching provider, removing a domain and tearing the site down all leave it in place. kamakiri cdn and kamakiri status show how many resources are waiting.

kamakiri cdn cleanup deletes them without checking DNS. A resource your domain still points at is deleted all the same, and that domain goes down until you re-point it. To take a site off WebAccel and delete its resources, run the steps in this order:

  1. kamakiri cdn none, and re-point each domain.
  2. kamakiri domain verify <domain>, to confirm the domain is live without the CDN.
  3. kamakiri cdn cleanup.

A resource left by a removed domain, or by a switch to Cloudflare, is already unused, so kamakiri cdn cleanup alone deletes it. Running kamakiri cdn none for it would take the whole site off its CDN.

Run these steps before kamakiri teardown. Once the site is gone, the only way to delete the resource is the Sakura Cloud control panel.

Cloudflare leaves nothing to delete: its hostname is removed automatically once no domain uses it.

Caches and deploys

While a CDN is on, a deploy or a rollback purges the CDN cache itself, and its ✓ live line means visitors get the new files through the CDN. To flush the cache without deploying, run kamakiri cdn purge.

When a domain stops serving through the CDN

If a live domain’s delivery record stops pointing where it was assigned, kamakiri cdn and kamakiri status show that domain as a warning, with the record to restore. The site keeps serving on its current configuration meanwhile. Fix the record, then run kamakiri domain verify <domain>, which re-checks DNS and waits until the domain is live again.