Skip to content

Security: aaquib90/vibesdk-production

Security

SECURITY.md

Security Guide for VibeSDK Production

πŸ” Environment Variables Security

βœ… DO:

  • Use wrangler login for authentication (recommended)
  • Set sensitive values via Cloudflare Dashboard
  • Use environment variables for local development
  • Keep .prod.vars and .dev.vars files secure

❌ NEVER:

  • Commit API tokens to version control
  • Share API tokens in chat/email
  • Use production tokens in development
  • Store secrets in plain text files

πŸš€ Deployment Options

Option 1: OAuth Authentication (Recommended)

npx wrangler login
npx wrangler deploy

Option 2: Environment Variables

export CLOUDFLARE_API_TOKEN="your-token"
npx wrangler deploy

Option 3: Cloudflare Dashboard

  • Set secrets via Cloudflare Dashboard
  • Use wrangler deploy without API token

πŸ”§ Required Permissions

Your Cloudflare API token needs:

  • Account:Read
  • Workers:Edit
  • Zone:Read (for custom domains)
  • R2:Edit
  • D1:Edit
  • KV:Edit
  • Durable Objects:Edit
  • Workers for Platforms:Edit
  • AI Gateway:Edit

πŸ“ Current Configuration Status

βœ… Preview domain configured: vibesdk-production.workers.dev βœ… Preview URLs enabled βœ… Security practices implemented ⚠️ Docker required for full deployment

There aren't any published security advisories