Bumps the github-actions-minor-patch group with 3 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action), [docker/login-action](https://github.com/docker/login-action) and [docker/build-push-action](https://github.com/docker/build-push-action). Updates `docker/setup-buildx-action` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd...d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5) Updates `docker/login-action` from 4.1.0 to 4.2.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/4907a6ddec9925e35a0a9e82d7399ccc52663121...650006c6eb7dba73a995cc03b0b2d7f5ca915bee) Updates `docker/build-push-action` from 7.1.0 to 7.2.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](https://github.com/docker/build-push-action/compare/bcafcacb16a39f128d818304e6c9c0c18556b85f...f9f3042f7e2789586610d6e8b85c8f03e5195baf) --- updated-dependencies: - dependency-name: docker/setup-buildx-action dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-minor-patch - dependency-name: docker/login-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-minor-patch - dependency-name: docker/build-push-action dependency-version: 7.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
paseo-relay
Self-hosted Paseo relay.
This repository packages the upstream getpaseo/paseo @getpaseo/relay/cloudflare adapter as a thin deployment wrapper. It does not implement a custom relay protocol, admin API, or auth layer. The runtime contract stays aligned with upstream Paseo while this repo owns deployment, validation, and operational packaging.
What This Repo Provides
- A minimal Worker entrypoint that re-exports the upstream relay worker and
RelayDurableObject - Durable Object wiring through Wrangler
- Local validation with Bun, TypeScript, Vitest, and Wrangler dry-runs
- An OCI image that runs the bundled Worker on
workerd - GitHub Actions for PR validation,
mainbranch deploys, and OCI publishing
Runtime Contract
The public runtime surface is intentionally small:
GET /healthreturns200with{"status":"ok"}GET /ws?...handles relay and WebSocket traffic
This repo does not add any repo-specific API endpoints.
Quick Start
Prerequisites
- Bun
1.3.12 - Docker, if you want to build or run the OCI image
- A Cloudflare account, if you want to deploy the Worker
Install
bun install
Run validation
bun run check
This runs:
- Worker type generation
- TypeScript checks
- Vitest Worker tests
- Generated type drift checks
wrangler deploy --dry-run
Local Worker development
bun run dev
Build and run the OCI image
bun run oci:build
bun run oci:run
The OCI image exposes the relay on port 8080.
Run the prebuilt OCI image
Prebuilt images are published to GHCR:
docker pull ghcr.io/xixu-me/paseo-relay:main
docker run --rm -p 8080:8080 -v paseo-relay-data:/var/lib/paseo-relay/do ghcr.io/xixu-me/paseo-relay:main
Cloudflare Deployment
wrangler.jsonc is the source of truth for the Worker deployment:
- entrypoint:
src/index.ts - Durable Object binding:
RELAY - Durable Object class:
RelayDurableObject - SQLite-backed Durable Object migration:
v1
Deploy with:
bun run deploy
Note
workers.devis useful for initial verification, but the intended production path is a custom domain.
Connecting a Paseo Daemon
Paseo expects relay endpoints in host:port form.
Warning
Do not use
https://relay.example.comhere. Userelay.example.com:443.
Example:
export PASEO_RELAY_ENDPOINT="relay.example.com:443"
export PASEO_RELAY_PUBLIC_ENDPOINT="relay.example.com:443"
PASEO_RELAY_ENDPOINTis the address the daemon connects toPASEO_RELAY_PUBLIC_ENDPOINTis the address embedded into pairing links and QR codes
Testing
The Worker test suite covers:
/healthreturns200- unknown paths return
404 - missing
serverIdreturns400 - invalid relay version returns
400 - non-WebSocket relay requests are rejected
- valid WebSocket upgrade requests succeed
The OCI validation path additionally checks:
- container startup
/healthover HTTP- a v2 WebSocket upgrade smoke test against the containerized runtime
CI/CD
The repository uses four workflows:
validate-reusable.yml: the single validation source of truthci.yml: runs validation for pull requests and merge groupsrelease.yml: validates, then deploys frommainand publishes the OCI imageauto-merge.yml: enables auto-merge only for Dependabot PRs labeleddependencies
Release behavior
- pushes to
mainthat change release-relevant files run validation, then deploy the Worker and publishghcr.io/xixu-me/paseo-relay:main - manual
workflow_dispatchruns can selectively deploy the Worker and/or publish the OCI image
Required secrets
Worker deployment requires:
CLOUDFLARE_API_TOKENCLOUDFLARE_ACCOUNT_ID
OCI publishing uses the built-in GITHUB_TOKEN.
OCI Notes
The image is built from the Worker bundle generated by Wrangler and served by workerd. Prebuilt images are published as ghcr.io/xixu-me/paseo-relay:main. The runtime image:
- listens on
:8080 - persists Durable Object state under
/var/lib/paseo-relay/do - runs as a non-root user
Design Goals
- Stay as close as possible to the upstream Paseo relay architecture
- Keep repository-owned logic limited to deployment, validation, and packaging
- Make Worker and OCI paths testable through the same contract