Deploy to Netlify

Drop on Netlify Functions, with a Cloudflare D1 database, Netlify Blobs for files, and a scheduled function that deletes expired code images.

DatabaseD1 over HTTP
FilesNetlify Blobs
Rate limitsPer instance
Code imagesSVG
Code image cleanupScheduled function
LiveNot deployed yet

What you need

  • A Netlify account.
  • A Cloudflare account and Wrangler (pnpm exec wrangler login).
  • Node.js 24 and pnpm.
  • A GitHub OAuth app with the callback https://<your-site>.netlify.app/api/auth/callback/github, or your own domain.

Deploy

  1. Get the code and create the site:

    npx giget gh:vite-hub/drop my-drop
    cd my-drop
    pnpm install
    npx netlify login
    npx netlify sites:create --name my-drop

    netlify.toml already sets DROP_HOST=netlify, Node.js 24, and the build command.

  2. Create the D1 database and copy its id into the environment:

    pnpm exec wrangler d1 create vitehub-drop-netlify   # copy the id into CLOUDFLARE_D1_DATABASE_ID

    Apply the migrations:

    CLOUDFLARE_D1_DATABASE_NAME=vitehub-drop-netlify pnpm db:migrate:d1
  3. Add the settings:

    npx netlify env:set CLOUDFLARE_ACCOUNT_ID …
    npx netlify env:set CLOUDFLARE_API_TOKEN … --secret
    npx netlify env:set CLOUDFLARE_D1_DATABASE_ID …
    npx netlify env:set CLOUDFLARE_D1_DATABASE_NAME vitehub-drop-netlify
    npx netlify env:set GITHUB_CLIENT_ID …
    npx netlify env:set GITHUB_CLIENT_SECRET … --secret
    npx netlify env:set BETTER_AUTH_SECRET "$(openssl rand -base64 32)" --secret
    npx netlify env:set DROP_ADMINS …

    Netlify Blobs needs no setup: the functions get their credentials from Netlify.

  4. Build and deploy:

    npx netlify deploy --build --prod

    To deploy on every push instead, link the repository in the Netlify dashboard. It builds with the same netlify.toml.

  5. Run the smoke test:

    DROP_URL=https://my-drop.netlify.app pnpm test:e2e:deployed

Settings

VariableWhat it is
GITHUB_CLIENT_IDYour GitHub OAuth app's client ID.
GITHUB_CLIENT_SECRETA client secret from the same app.
BETTER_AUTH_SECRETSigns sessions and agent tokens. One per deployment: openssl rand -base64 32
DROP_ADMINSGitHub user ids that join as Admin, comma-separated: gh api users/<login> --jq .id
CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_API_TOKENCloudflare account id and an account API token with D1 edit access.
CLOUDFLARE_D1_DATABASE_ID, CLOUDFLARE_D1_DATABASE_NAMEThe id and name of vitehub-drop-netlify.
CLOUDFLARE_API_TOKENCloudflare account API token with D1 edit access.
DROP_HOSTnetlify. Set in netlify.toml.

Database

Cloudflare D1 over HTTPS. pnpm db:migrate:d1 applies new migrations and skips the ones already applied; run it before you deploy a schema change.

On Netlify

  • Code images are SVG only: PNG needs Cloudflare Browser Run.
  • Rate limits count in memory per function instance, so they're looser than on Cloudflare.
  • Files go to a Netlify Blobs store, and Drop serves them at /f/ after checking access.
  • A scheduled function deletes expired code images every hour.