Deploy to Vercel
Drop on Vercel Functions, with a Cloudflare D1 database, a private Vercel Blob store for files, and a Vercel Cron Job that deletes expired code images.
| Database | D1 over HTTP |
| Files | Vercel Blob |
| Rate limits | Per instance |
| Code images | SVG |
| Code image cleanup | Vercel Cron Job |
Settings
| Variable | What it is |
|---|---|
| GITHUB_CLIENT_ID | Your GitHub OAuth app's client ID. |
| GITHUB_CLIENT_SECRET | A client secret from the same app. |
| BETTER_AUTH_SECRET | Signs sessions and agent tokens. One per deployment: openssl rand -base64 32 |
| DROP_ADMINS | GitHub user ids that join as Admin, comma-separated: gh api users/<login> --jq .id |
| DROP_HOST | vercel. Read at build time. |
| CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_API_TOKEN | Cloudflare account id and an account API token with D1 edit access. |
| CLOUDFLARE_D1_DATABASE_ID, CLOUDFLARE_D1_DATABASE_NAME | Your D1 database id and name. |
| BLOB_READ_WRITE_TOKEN | Added by Vercel when you connect the Blob store. |
Database
Cloudflare D1 over HTTPS. pnpm db:migrate:d1 skips migrations already applied. The configured Vercel build runs it after building. Disable previews or give them a separate D1 database.
On Vercel
- Code images are SVG only: PNG needs Cloudflare Browser Run.
- Rate limits count in memory per function instance, so they're looser than on Cloudflare.
- Files go to a private Blob store, and Drop serves them at
/f/after checking access. - A Vercel Cron Job deletes expired code images once a day, which works on the Hobby plan. Expired images stop being served immediately.