Deploy to Deno Deploy

Drop on Deno Deploy, with a Cloudflare D1 database and an S3-compatible bucket for files, like Cloudflare R2 or Amazon S3.

Deploy with the button

The official Deno button clones Drop into your GitHub account and opens the new-app flow. deno.jsonc sets installation, the Deno build, the server entrypoint, and D1 migrations before deployment.

  1. Create a D1 database and account API token.
  2. Create an R2 bucket:

    npx wrangler r2 bucket create my-drop

    Under R2, Manage API tokens, create a token with Object Read and Write permission for that bucket. Keep its access key id and secret access key.

  3. Choose an organization and app name. Create the GitHub OAuth app with callback https://<app>.<org>.deno.net/api/auth/callback/github.
  4. Before deploying, open Edit Environment Variables and add all settings below. Make the D1 settings available to build and runtime; S3_BUCKET, S3_ENDPOINT, and S3_REGION must be available to the build. Put GitHub credentials, the auth secret, admin ids, and S3 access keys in the production runtime context.

Use a separate D1 database and bucket in preview contexts, or turn previews off. Deno runs pre-deploy migrations for each timeline.

DatabaseD1 over HTTP
FilesR2 S3 API
Rate limitsPer instance
Code imagesSVG
Code image cleanupNone

Settings

VariableWhat it is
GITHUB_CLIENT_IDYour GitHub OAuth app's client ID.
GITHUB_CLIENT_SECRETA client secret from the same app.
BETTER_AUTH_SECRETSigns sessions and agent tokens. One per deployment: openssl rand -base64 32
DROP_ADMINSGitHub user ids that join as Admin, comma-separated: gh api users/<login> --jq .id
CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_API_TOKENCloudflare account id and an account API token with D1 edit access.
CLOUDFLARE_D1_DATABASE_ID, CLOUDFLARE_D1_DATABASE_NAMEYour D1 database id and name.
S3_BUCKETThe bucket you created, my-drop in the command above. Read at build time.
S3_ENDPOINThttps://<account-id>.r2.cloudflarestorage.com for R2. Read at build time.
S3_REGIONauto for R2. Read at build time.
AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEYThe bucket's access key.

Database

Cloudflare D1 over HTTPS. pnpm db:migrate:d1 skips migrations already applied. The GitHub flow runs it as a pre-deploy command. For a local build, run it before publishing.

On Deno Deploy

  • Code images are SVG only: PNG needs Cloudflare Browser Run.
  • Rate limits count in memory per isolate, so they're looser than on Cloudflare.
  • Nothing deletes expired code images: ViteHub has no scheduled jobs on Deno Deploy yet. They stop being served after five minutes, but stay in the bucket; a lifecycle rule on code-images/ cleans them up.