Previews on Laravel Cloud
Serve project previews and shells through a Cloudflare Worker when OneDrop runs on Laravel Cloud with Blaxel or Runtime sandboxes.
Serve project previews and shells through a Cloudflare Worker when OneDrop runs on Laravel Cloud with Blaxel or Runtime sandboxes.
On a server, Caddy serves each project’s preview and shell at its own address and checks every request with OneDrop (Previews and shells on a server). Laravel Cloud has no Caddy, so a Cloudflare Worker does the same job in front of the sandbox’s provider:
| Address | Goes to |
|---|---|
preview-<sandbox id>.<domain> | The project’s app, on Blaxel or Runtime |
shell-<sandbox id>.<domain> | The project’s web terminal |
Blaxel and Runtime protect private previews with a cookie on their own domain. Browsers limit cookies for another site shown inside a page, so inside OneDrop’s Preview tab:
Through the Worker, the browser only deals with addresses and cookies under your own domain, and the provider’s token never reaches it.
preview-<id>.<domain>/__zap/enter with a short-lived token. The Worker asks OneDrop to check it, and OneDrop sets that address’s own cookie. The app’s login cookie never reaches these addresses.Only the Worker can ask OneDrop where a sandbox lives: it proves itself with a shared secret.
You need your domain’s DNS on Cloudflare, with a proxied wildcard record (*.<domain>). Keep your app’s own records (the root, www, docs) on DNS only.
bash openssl rand -hex 32 Edit infra/cloudflare/preview-gateway/wrangler.toml for your domain
(routes, APP_URL, GATEWAY_DOMAIN), then, with a Cloudflare API
token that can edit Workers scripts and routes: bash cd infra/cloudflare/preview-gateway npx wrangler deploy npx wrangler secret put GATEWAY_SECRET
On Laravel Cloud, set SANDBOX_GATEWAY_DOMAIN to your domain and
SANDBOX_GATEWAY_SECRET to the same secret (as a Secrets Manager
secret), then redeploy.
The Worker’s own tests run with node --test infra/cloudflare/preview-gateway/worker.test.mjs.