Deploy to Netlify
Drop on Netlify Functions, with a Cloudflare D1 database, Netlify Blobs for files, and a scheduled function that deletes expired code images.
| Database | D1 over HTTP |
| Files | Netlify Blobs |
| Rate limits | Per instance |
| Code images | SVG |
| Code image cleanup | Scheduled function |
| Live | Not deployed yet |
What you need
- A Netlify account.
- A Cloudflare account and Wrangler (
pnpm exec wrangler login). - Node.js 24 and pnpm.
- A GitHub OAuth app with the callback
https://<your-site>.netlify.app/api/auth/callback/github, or your own domain.
Deploy
Get the code and create the site:
npx giget gh:vite-hub/drop my-drop cd my-drop pnpm install npx netlify login npx netlify sites:create --name my-dropnetlify.tomlalready setsDROP_HOST=netlify, Node.js 24, and the build command.Create the D1 database and copy its id into the environment:
pnpm exec wrangler d1 create vitehub-drop-netlify # copy the id into CLOUDFLARE_D1_DATABASE_IDApply the migrations:
CLOUDFLARE_D1_DATABASE_NAME=vitehub-drop-netlify pnpm db:migrate:d1Add the settings:
npx netlify env:set CLOUDFLARE_ACCOUNT_ID … npx netlify env:set CLOUDFLARE_API_TOKEN … --secret npx netlify env:set CLOUDFLARE_D1_DATABASE_ID … npx netlify env:set CLOUDFLARE_D1_DATABASE_NAME vitehub-drop-netlify npx netlify env:set GITHUB_CLIENT_ID … npx netlify env:set GITHUB_CLIENT_SECRET … --secret npx netlify env:set BETTER_AUTH_SECRET "$(openssl rand -base64 32)" --secret npx netlify env:set DROP_ADMINS …Netlify Blobs needs no setup: the functions get their credentials from Netlify.
Build and deploy:
npx netlify deploy --build --prodTo deploy on every push instead, link the repository in the Netlify dashboard. It builds with the same
netlify.toml.Run the smoke test:
DROP_URL=https://my-drop.netlify.app pnpm test:e2e:deployed
Settings
| Variable | What it is |
|---|---|
| GITHUB_CLIENT_ID | Your GitHub OAuth app's client ID. |
| GITHUB_CLIENT_SECRET | A client secret from the same app. |
| BETTER_AUTH_SECRET | Signs sessions and agent tokens. One per deployment: openssl rand -base64 32 |
| DROP_ADMINS | GitHub user ids that join as Admin, comma-separated: gh api users/<login> --jq .id |
| CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_API_TOKEN | Cloudflare account id and an account API token with D1 edit access. |
| CLOUDFLARE_D1_DATABASE_ID, CLOUDFLARE_D1_DATABASE_NAME | The id and name of vitehub-drop-netlify. |
| CLOUDFLARE_API_TOKEN | Cloudflare account API token with D1 edit access. |
| DROP_HOST | netlify. Set in netlify.toml. |
Database
Cloudflare D1 over HTTPS. pnpm db:migrate:d1 applies new migrations and skips the ones already applied; run it before you deploy a schema change.
On Netlify
- Code images are SVG only: PNG needs Cloudflare Browser Run.
- Rate limits count in memory per function instance, so they're looser than on Cloudflare.
- Files go to a Netlify Blobs store, and Drop serves them at
/f/after checking access. - A scheduled function deletes expired code images every hour.