Bumps the bun-minor-patch group with 4 updates: @getpaseo/relay, [@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler). Updates `@getpaseo/relay` from 0.1.90 to 0.1.96 Updates `@cloudflare/vitest-pool-workers` from 0.16.13 to 0.16.15 - [Release notes](https://github.com/cloudflare/workers-sdk/releases) - [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/vitest-pool-workers/CHANGELOG.md) - [Commits](https://github.com/cloudflare/workers-sdk/commits/@cloudflare/vitest-pool-workers@0.16.15/packages/vitest-pool-workers) Updates `@types/node` from 25.9.2 to 25.9.3 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `wrangler` from 4.98.0 to 4.100.0 - [Release notes](https://github.com/cloudflare/workers-sdk/releases) - [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.100.0/packages/wrangler) --- updated-dependencies: - dependency-name: "@getpaseo/relay" dependency-version: 0.1.96 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: bun-minor-patch - dependency-name: "@cloudflare/vitest-pool-workers" dependency-version: 0.16.15 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: bun-minor-patch - dependency-name: "@types/node" dependency-version: 25.9.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: bun-minor-patch - dependency-name: wrangler dependency-version: 4.100.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: bun-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
paseo-relay
Self-hosted Paseo relay.
This repository packages the upstream getpaseo/paseo @getpaseo/relay/cloudflare adapter as a thin deployment wrapper. It does not implement a custom relay protocol, admin API, or auth layer. The runtime contract stays aligned with upstream Paseo while this repo owns deployment, validation, and operational packaging.
What This Repo Provides
- A minimal Worker entrypoint that re-exports the upstream relay worker and
RelayDurableObject - Durable Object wiring through Wrangler
- Local validation with Bun, TypeScript, Vitest, and Wrangler dry-runs
- An OCI image that runs the bundled Worker on
workerd - GitHub Actions for PR validation,
mainbranch deploys, and OCI publishing
Runtime Contract
The public runtime surface is intentionally small:
GET /healthreturns200with{"status":"ok"}GET /ws?...handles relay and WebSocket traffic
This repo does not add any repo-specific API endpoints.
Quick Start
Prerequisites
- Bun
1.3.12 - Docker, if you want to build or run the OCI image
- A Cloudflare account, if you want to deploy the Worker
Install
bun install
Run validation
bun run check
This runs:
- Worker type generation
- TypeScript checks
- Vitest Worker tests
- Generated type drift checks
wrangler deploy --dry-run
Local Worker development
bun run dev
Build and run the OCI image
bun run oci:build
bun run oci:run
The OCI image exposes the relay on port 8080.
Run the prebuilt OCI image
Prebuilt images are published to GHCR:
docker pull ghcr.io/xixu-me/paseo-relay:main
docker run --rm -p 8080:8080 -v paseo-relay-data:/var/lib/paseo-relay/do ghcr.io/xixu-me/paseo-relay:main
Cloudflare Deployment
wrangler.jsonc is the source of truth for the Worker deployment:
- entrypoint:
src/index.ts - Durable Object binding:
RELAY - Durable Object class:
RelayDurableObject - SQLite-backed Durable Object migration:
v1
Deploy with:
bun run deploy
Note
workers.devis useful for initial verification, but the intended production path is a custom domain.
Connecting a Paseo Daemon
Paseo expects relay endpoints in host:port form.
Warning
Do not use
https://relay.example.comhere. Userelay.example.com:443.
Example:
export PASEO_RELAY_ENDPOINT="relay.example.com:443"
export PASEO_RELAY_PUBLIC_ENDPOINT="relay.example.com:443"
PASEO_RELAY_ENDPOINTis the address the daemon connects toPASEO_RELAY_PUBLIC_ENDPOINTis the address embedded into pairing links and QR codes
Testing
The Worker test suite covers:
/healthreturns200- unknown paths return
404 - missing
serverIdreturns400 - invalid relay version returns
400 - non-WebSocket relay requests are rejected
- valid WebSocket upgrade requests succeed
The OCI validation path additionally checks:
- container startup
/healthover HTTP- a v2 WebSocket upgrade smoke test against the containerized runtime
CI/CD
The repository uses four workflows:
validate-reusable.yml: the single validation source of truthci.yml: runs validation for pull requests and merge groupsrelease.yml: validates, then deploys frommainand publishes the OCI imageauto-merge.yml: enables auto-merge only for Dependabot PRs labeleddependencies
Release behavior
- pushes to
mainthat change release-relevant files run validation, then deploy the Worker and publishghcr.io/xixu-me/paseo-relay:main - manual
workflow_dispatchruns can selectively deploy the Worker and/or publish the OCI image
Required secrets
Worker deployment requires:
CLOUDFLARE_API_TOKENCLOUDFLARE_ACCOUNT_ID
OCI publishing uses the built-in GITHUB_TOKEN.
OCI Notes
The image is built from the Worker bundle generated by Wrangler and served by workerd. Prebuilt images are published as ghcr.io/xixu-me/paseo-relay:main. The runtime image:
- listens on
:8080 - persists Durable Object state under
/var/lib/paseo-relay/do - runs as a non-root user
Design Goals
- Stay as close as possible to the upstream Paseo relay architecture
- Keep repository-owned logic limited to deployment, validation, and packaging
- Make Worker and OCI paths testable through the same contract