OpportunitiesEntities
Docs
    Ring Platform

    Decentralized Self-building Future

    Sign In
    Entities
    Opportunities
    Store
    Docs
    Platform Concepts
    RING EconomySonoratek LLCGlobal ImpactAI Meets Web3
    Get Started
    Quick StartCalculatorRoadmap
    Privacy|Contact
    v1.104.17|Sonoratek LLC

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)
    Ring Logo

    Loading documentation...

    Preparing Ring content

    Ring Logo

    Loading documentation...

    Preparing Ring content

    Ring Logo

    Loading documentation...

    Preparing Ring content

    Ring CDN (RingFileBase edge)

    Use Founder / Developer tabs in the docs sidebar to filter this page. Uploads are documented under RingFileBase; this page covers public delivery. Ring File Cabinet public galleries (/{username}/img) serve visibility=public items from stable CDN /files/{uuid} URLs.

    Ring CDN is the read path for objects stored by RingFileBase: an NGINX edge (ring-filebase-cdn) that proxies GET /files/<key> to MinIO (or RGW) with caching headers. Browsers and crawlers never need MinIO credentials. Keys include originals (/files/{uuid}) and derivatives (/files/{uuid}_v_thumb.webp, /files/{uuid}_v_video_frame_0_480.webp, …) — same {fileId}_v_* scheme as RingFileBase.

    LayerComponentNamespace (typical)
    Edgering-filebase-cdn Deployment + Ingressring-filebase
    Originminio-servicering-filebase-minio
    Writerring-filebase-apiring-filebase

    Public hosts follow cdn.<clone-domain> (examples in empire: cdn.ring-platform.org, cdn.greenfood.live, cdn.vikka.ua).

    Why this matters for your clone

    Users and search engines load product photos, avatars, and generated media from a stable CDN hostname, not from your app pods. That keeps Next.js free of large static payloads, lets you cache aggressively, and lets you place edges closer to members (US / EU / UA) without changing application code.

    Typical scenarios

    White-label brand CDN

    Map cdn.yourdomain → your MinIO bucket via Ingress + NGINX map $host $target_bucket.

    Marketplace media

    Store product images once via RingFileBase; serve forever from CDN URLs stored in Postgres.

    File Cabinet /img

    Curated public gallery items embed CDN /files/{uuid} (+ _v_* derivatives) — no HMAC/TTL signed URLs in current adapter.

    Request path

    Verified config surfaces

    PathRole
    infrastructure/k3s-3/ring-filebase/10-cdn-config.yamlNGINX map $host $target_bucket + /files/ location
    infrastructure/ring-file-base/k8s/ring-filebase/cdn-*-ingress.yamlPer-domain Ingress + TLS
    infrastructure/ring-file-base/k8s/ring-filebase/20-cdn-deployment.yamlCDN Deployment
    App ConfigMapRINGBASE_PUBLIC_URL, optional REFMAGIC_CDN_INTERNAL_URL (in-cluster CDN)

    Host → bucket map (pattern)

    CDN config maps Host header to MinIO bucket name, then proxies:

    /files/<key> → http://minio_backend/<bucket>/<key>

    Example mapping used in empire configs:

    Related documentation

    Related documentation

    RingFileBase (object storage API)

    Prerequisite: authenticated uploads and file() / RingBaseAdapter before public CDN reads.

    Ring File Cabinet

    Same-workflow: member gallery curation → public /{username}/img via CDN /files/{uuid}; private bytes use ACL download proxy.

    Environment Configuration

    Depends-on: RINGBASE_PUBLIC_URL and storage-related env for clones.

    Performance Optimization

    See-also: caching and edge considerations for clones.

    Ring CDN (RingFileBase edge)

    Use Founder / Developer tabs in the docs sidebar to filter this page. Uploads are documented under RingFileBase; this page covers public delivery. Ring File Cabinet public galleries (/{username}/img) serve visibility=public items from stable CDN /files/{uuid} URLs.

    Ring CDN is the read path for objects stored by RingFileBase: an NGINX edge (ring-filebase-cdn) that proxies GET /files/<key> to MinIO (or RGW) with caching headers. Browsers and crawlers never need MinIO credentials. Keys include originals (/files/{uuid}) and derivatives (/files/{uuid}_v_thumb.webp, /files/{uuid}_v_video_frame_0_480.webp, …) — same {fileId}_v_* scheme as RingFileBase.

    LayerComponentNamespace (typical)
    Edgering-filebase-cdn Deployment + Ingressring-filebase
    Originminio-servicering-filebase-minio
    Writerring-filebase-apiring-filebase

    Public hosts follow cdn.<clone-domain> (examples in empire: cdn.ring-platform.org, cdn.greenfood.live, cdn.vikka.ua).

    Why this matters for your clone

    Users and search engines load product photos, avatars, and generated media from a stable CDN hostname, not from your app pods. That keeps Next.js free of large static payloads, lets you cache aggressively, and lets you place edges closer to members (US / EU / UA) without changing application code.

    Typical scenarios

    White-label brand CDN

    Map cdn.yourdomain → your MinIO bucket via Ingress + NGINX map $host $target_bucket.

    Marketplace media

    Store product images once via RingFileBase; serve forever from CDN URLs stored in Postgres.

    File Cabinet /img

    Curated public gallery items embed CDN /files/{uuid} (+ _v_* derivatives) — no HMAC/TTL signed URLs in current adapter.

    Request path

    Verified config surfaces

    PathRole
    infrastructure/k3s-3/ring-filebase/10-cdn-config.yamlNGINX map $host $target_bucket + /files/ location
    infrastructure/ring-file-base/k8s/ring-filebase/cdn-*-ingress.yamlPer-domain Ingress + TLS
    infrastructure/ring-file-base/k8s/ring-filebase/20-cdn-deployment.yamlCDN Deployment
    App ConfigMapRINGBASE_PUBLIC_URL, optional REFMAGIC_CDN_INTERNAL_URL (in-cluster CDN)

    Host → bucket map (pattern)

    CDN config maps Host header to MinIO bucket name, then proxies:

    /files/<key> → http://minio_backend/<bucket>/<key>

    Example mapping used in empire configs:

    Related documentation

    Related documentation

    RingFileBase (object storage API)

    Prerequisite: authenticated uploads and file() / RingBaseAdapter before public CDN reads.

    Ring File Cabinet

    Same-workflow: member gallery curation → public /{username}/img via CDN /files/{uuid}; private bytes use ACL download proxy.

    Environment Configuration

    Depends-on: RINGBASE_PUBLIC_URL and storage-related env for clones.

    Performance Optimization

    See-also: caching and edge considerations for clones.

    Ring CDN (RingFileBase edge)

    Use Founder / Developer tabs in the docs sidebar to filter this page. Uploads are documented under RingFileBase; this page covers public delivery. Ring File Cabinet public galleries (/{username}/img) serve visibility=public items from stable CDN /files/{uuid} URLs.

    Ring CDN is the read path for objects stored by RingFileBase: an NGINX edge (ring-filebase-cdn) that proxies GET /files/<key> to MinIO (or RGW) with caching headers. Browsers and crawlers never need MinIO credentials. Keys include originals (/files/{uuid}) and derivatives (/files/{uuid}_v_thumb.webp, /files/{uuid}_v_video_frame_0_480.webp, …) — same {fileId}_v_* scheme as RingFileBase.

    LayerComponentNamespace (typical)
    Edgering-filebase-cdn Deployment + Ingressring-filebase
    Originminio-servicering-filebase-minio
    Writerring-filebase-apiring-filebase

    Public hosts follow cdn.<clone-domain> (examples in empire: cdn.ring-platform.org, cdn.greenfood.live, cdn.vikka.ua).

    Why this matters for your clone

    Users and search engines load product photos, avatars, and generated media from a stable CDN hostname, not from your app pods. That keeps Next.js free of large static payloads, lets you cache aggressively, and lets you place edges closer to members (US / EU / UA) without changing application code.

    Typical scenarios

    White-label brand CDN

    Map cdn.yourdomain → your MinIO bucket via Ingress + NGINX map $host $target_bucket.

    Marketplace media

    Store product images once via RingFileBase; serve forever from CDN URLs stored in Postgres.

    File Cabinet /img

    Curated public gallery items embed CDN /files/{uuid} (+ _v_* derivatives) — no HMAC/TTL signed URLs in current adapter.

    Request path

    Verified config surfaces

    PathRole
    infrastructure/k3s-3/ring-filebase/10-cdn-config.yamlNGINX map $host $target_bucket + /files/ location
    infrastructure/ring-file-base/k8s/ring-filebase/cdn-*-ingress.yamlPer-domain Ingress + TLS
    infrastructure/ring-file-base/k8s/ring-filebase/20-cdn-deployment.yamlCDN Deployment
    App ConfigMapRINGBASE_PUBLIC_URL, optional REFMAGIC_CDN_INTERNAL_URL (in-cluster CDN)

    Host → bucket map (pattern)

    CDN config maps Host header to MinIO bucket name, then proxies:

    /files/<key> → http://minio_backend/<bucket>/<key>

    Example mapping used in empire configs:

    Related documentation

    Related documentation

    RingFileBase (object storage API)

    Prerequisite: authenticated uploads and file() / RingBaseAdapter before public CDN reads.

    Ring File Cabinet

    Same-workflow: member gallery curation → public /{username}/img via CDN /files/{uuid}; private bytes use ACL download proxy.

    Environment Configuration

    Depends-on: RINGBASE_PUBLIC_URL and storage-related env for clones.

    Performance Optimization

    See-also: caching and edge considerations for clones.

    Generative media

    ImageConductor / VideoConductor outputs should land on RingFileBase so OG and newsroom assets use CDN URLs.

    Ops backup

    CDN is a cache — back up the MinIO/RGW bucket, not only the NGINX PVC.

    Founder checklist
    1. DNS cdn.<domain> → cluster ingress IP(s).
    2. TLS certificate on the CDN Ingress.
    3. App RINGBASE_PUBLIC_URL=https://cdn.<domain>.
    4. Confirm a known /files/... URL returns 200 in the browser.
    HostBucket
    cdn.ring-platform.orgring-filebase
    cdn.greenfood.livering-filebase
    cdn.vikka.uaring-vikka-ua

    Object keys are whatever ring-filebase-api wrote (some deployed API images still prefix keys with a project segment such as ring-greenfood-live/<uuid>). The CDN path is always /files/ + that key.

    App wiring

    VariablePurpose
    RINGBASE_PUBLIC_URLAbsolute origin embedded in upload responses (https://cdn.<domain>)
    REFMAGIC_CDN_INTERNAL_URLOptional in-cluster fetch (http://ring-filebase-cdn.ring-filebase.svc.cluster.local)
    CDN_URLOptional legacy/commented flag in env.local.template — prefer RINGBASE_PUBLIC_URL for RingFileBase

    Edge zones (empire reference)

    Ringdom operates CDN edges as a geo set (documented in AI-CONTEXT cdn-edge-architecture): US (k3s-1 / Ashburn), EU (Finland), UA (k8s). Each zone runs local MinIO + CDN proxy; DNS may publish multiple A/AAAA records for cdn.*. Your clone may use one zone only — still use the same /files/ contract.

    Operator steps

    1. 1

      Create bucket + public read for CDN

      MinIO objects are often uploaded with private ACL. The CDN proxy needs anonymous GetObject (or equivalent signed fetch) on the bucket, or browsers see 403 XML from MinIO through NGINX.

    2. 2

      Deploy CDN + Ingress

      Apply CDN ConfigMaps, Deployment, Service, and cdn.<domain> Ingress with cert-manager TLS. Confirm server_name includes your host.

    3. 3

      Point the app at the public origin

      Set RINGBASE_PUBLIC_URL=https://cdn.<domain> so RingBaseAdapter / API responses emit CDN URLs. Restart the Ring Deployment after ConfigMap changes.

    4. 4

      Verify

      Expect 200. 403 → bucket policy / ACL. 404 → wrong bucket map or key prefix.

    Security notes

    • CDN is read-only for /files/ — uploads go through RingFileBase API with Bearer auth.
    • Do not expose MinIO console or S3 API publicly unless you intend to; keep minio-service ClusterIP.
    • Flat /files/<id> keys reduce directory enumeration versus dated folder trees (see RingFileBase security hardening notes in AI-CONTEXT).

    Generative media

    ImageConductor / VideoConductor outputs should land on RingFileBase so OG and newsroom assets use CDN URLs.

    Ops backup

    CDN is a cache — back up the MinIO/RGW bucket, not only the NGINX PVC.

    Founder checklist
    1. DNS cdn.<domain> → cluster ingress IP(s).
    2. TLS certificate on the CDN Ingress.
    3. App RINGBASE_PUBLIC_URL=https://cdn.<domain>.
    4. Confirm a known /files/... URL returns 200 in the browser.
    HostBucket
    cdn.ring-platform.orgring-filebase
    cdn.greenfood.livering-filebase
    cdn.vikka.uaring-vikka-ua

    Object keys are whatever ring-filebase-api wrote (some deployed API images still prefix keys with a project segment such as ring-greenfood-live/<uuid>). The CDN path is always /files/ + that key.

    App wiring

    VariablePurpose
    RINGBASE_PUBLIC_URLAbsolute origin embedded in upload responses (https://cdn.<domain>)
    REFMAGIC_CDN_INTERNAL_URLOptional in-cluster fetch (http://ring-filebase-cdn.ring-filebase.svc.cluster.local)
    CDN_URLOptional legacy/commented flag in env.local.template — prefer RINGBASE_PUBLIC_URL for RingFileBase

    Edge zones (empire reference)

    Ringdom operates CDN edges as a geo set (documented in AI-CONTEXT cdn-edge-architecture): US (k3s-1 / Ashburn), EU (Finland), UA (k8s). Each zone runs local MinIO + CDN proxy; DNS may publish multiple A/AAAA records for cdn.*. Your clone may use one zone only — still use the same /files/ contract.

    Operator steps

    1. 1

      Create bucket + public read for CDN

      MinIO objects are often uploaded with private ACL. The CDN proxy needs anonymous GetObject (or equivalent signed fetch) on the bucket, or browsers see 403 XML from MinIO through NGINX.

    2. 2

      Deploy CDN + Ingress

      Apply CDN ConfigMaps, Deployment, Service, and cdn.<domain> Ingress with cert-manager TLS. Confirm server_name includes your host.

    3. 3

      Point the app at the public origin

      Set RINGBASE_PUBLIC_URL=https://cdn.<domain> so RingBaseAdapter / API responses emit CDN URLs. Restart the Ring Deployment after ConfigMap changes.

    4. 4

      Verify

      Expect 200. 403 → bucket policy / ACL. 404 → wrong bucket map or key prefix.

    Security notes

    • CDN is read-only for /files/ — uploads go through RingFileBase API with Bearer auth.
    • Do not expose MinIO console or S3 API publicly unless you intend to; keep minio-service ClusterIP.
    • Flat /files/<id> keys reduce directory enumeration versus dated folder trees (see RingFileBase security hardening notes in AI-CONTEXT).

    Generative media

    ImageConductor / VideoConductor outputs should land on RingFileBase so OG and newsroom assets use CDN URLs.

    Ops backup

    CDN is a cache — back up the MinIO/RGW bucket, not only the NGINX PVC.

    Founder checklist
    1. DNS cdn.<domain> → cluster ingress IP(s).
    2. TLS certificate on the CDN Ingress.
    3. App RINGBASE_PUBLIC_URL=https://cdn.<domain>.
    4. Confirm a known /files/... URL returns 200 in the browser.
    HostBucket
    cdn.ring-platform.orgring-filebase
    cdn.greenfood.livering-filebase
    cdn.vikka.uaring-vikka-ua

    Object keys are whatever ring-filebase-api wrote (some deployed API images still prefix keys with a project segment such as ring-greenfood-live/<uuid>). The CDN path is always /files/ + that key.

    App wiring

    VariablePurpose
    RINGBASE_PUBLIC_URLAbsolute origin embedded in upload responses (https://cdn.<domain>)
    REFMAGIC_CDN_INTERNAL_URLOptional in-cluster fetch (http://ring-filebase-cdn.ring-filebase.svc.cluster.local)
    CDN_URLOptional legacy/commented flag in env.local.template — prefer RINGBASE_PUBLIC_URL for RingFileBase

    Edge zones (empire reference)

    Ringdom operates CDN edges as a geo set (documented in AI-CONTEXT cdn-edge-architecture): US (k3s-1 / Ashburn), EU (Finland), UA (k8s). Each zone runs local MinIO + CDN proxy; DNS may publish multiple A/AAAA records for cdn.*. Your clone may use one zone only — still use the same /files/ contract.

    Operator steps

    1. 1

      Create bucket + public read for CDN

      MinIO objects are often uploaded with private ACL. The CDN proxy needs anonymous GetObject (or equivalent signed fetch) on the bucket, or browsers see 403 XML from MinIO through NGINX.

    2. 2

      Deploy CDN + Ingress

      Apply CDN ConfigMaps, Deployment, Service, and cdn.<domain> Ingress with cert-manager TLS. Confirm server_name includes your host.

    3. 3

      Point the app at the public origin

      Set RINGBASE_PUBLIC_URL=https://cdn.<domain> so RingBaseAdapter / API responses emit CDN URLs. Restart the Ring Deployment after ConfigMap changes.

    4. 4

      Verify

      Expect 200. 403 → bucket policy / ACL. 404 → wrong bucket map or key prefix.

    Security notes

    • CDN is read-only for /files/ — uploads go through RingFileBase API with Bearer auth.
    • Do not expose MinIO console or S3 API publicly unless you intend to; keep minio-service ClusterIP.
    • Flat /files/<id> keys reduce directory enumeration versus dated folder trees (see RingFileBase security hardening notes in AI-CONTEXT).
    1. Docs
    2. /Integrations
    3. /Ring CDN (RingFileBase edge)

    Updated Jul 21, 20264 min listen

    1. Docs
    2. /Integrations
    3. /Ring CDN (RingFileBase edge)

    Updated Jul 21, 20264 min listen

    1. Docs
    2. /Integrations
    3. /Ring CDN (RingFileBase edge)

    Updated Jul 21, 20264 min listen