Configure Fastly on Zephyr

Overview

Fastly is available as a Bring Your Own Cloud (BYOC) deployment integration. Zephyr provisions and updates a Fastly Compute service in your Fastly account while your organization retains control of the account, domain, DNS, and API credential.

Prerequisites

Info
  • A Zephyr account
  • A Fastly account on the paid Usage plan with Compute available
  • A registered root domain whose DNS records you can manage

Configure and enable Fastly

Open the Fastly custom integration form

After signing in:

  1. Use the organization selector at the top of the dashboard to select the organization that should own the integration.
  2. Select Settings.
  3. Select Deployment Integrations.
  4. Select + Add integration, then select Fastly. The Fastly custom integration creation form opens.

Basic Info

  • Name: Enter a recognizable name between 3 and 100 characters. It can contain letters, digits, spaces, hyphens, underscores, and apostrophes.
  • Unique identifier: Enter a value between 3 and 50 characters using lowercase letters, digits, hyphens, and underscores. Zephyr uses this identifier in URLs, and it cannot be changed after the integration is created.
  • Set integration as default: Enable this option to use Fastly for deployments that do not select another integration.

Select Continue.

Configure DNS Record

Zephyr uses ze.example.com and *.ze.example.com for a root domain of example.com. Configure Fastly's TLS subscription first, then add the records at your DNS provider:

  1. In Fastly, open Domains > TLS management > Subscriptions and select Create subscription.
  2. Add ze.example.com and *.ze.example.com, submit the subscription, and wait for Fastly to display the verification CNAME records.
  3. At your DNS provider, add the verification CNAME records shown by Fastly.
  4. After Fastly verifies the domains, add these routing records:
NameTypeTarget
ze.example.comCNAMEt.sni.global.fastly.net
*.ze.example.comCNAMEt.sni.global.fastly.net

Use the target Fastly displays if it differs from the example above. See Fastly's domain documentation for more information.

You can select Test DNS in Zephyr to check the records. This check is optional: it does not validate the Fastly API token and does not prevent you from selecting Continue.

API Token

Create a Fastly API token

Open Fastly's API token management page. If you belong to more than one Fastly account, switch to the account where Zephyr should create the Compute service. Then:

  1. Go to Account > API tokens and select Create token.
  2. Reauthenticate when Fastly prompts you.
  3. Choose Automation token. Fastly recommends automation tokens for non-human deployment systems, but only a Fastly Superuser can create one.
  4. If an automation token is unavailable, create a User token instead. A user token inherits its creator's role and lifecycle, so the creator must be an Engineer or Superuser.
  5. Configure the token:
SettingValueWhy
Namezephyr-cloud, or another descriptive nameIdentifies the credential in Fastly
RoleEngineer for an automation tokenAllows Zephyr to create and manage the Compute service
TLS managementOffZephyr does not call Fastly TLS APIs
ScopeGlobal API access (global)Read-only and purge scopes cannot provision the service, package, domains, or service versions
Service accessAll services in the accountThe Zephyr-managed service does not exist when you create the token
ExpirationFastly's default 90 days, unless your organization requires a shorter lifetimeLimits credential lifetime while allowing planned rotation
  1. Create the token and copy its value immediately. Fastly displays the secret only once. Fastly's API token guide explains the token types and settings in more detail.
Secure and rotate the credential

Save the token in a password manager. Never commit it to version control or share it. Paste only the token value into Zephyr.

Fastly tokens cannot be edited, and an expired token returns HTTP 401. Track its expiration and replace the credential in Zephyr before revoking the old token. Revoking it first breaks later provisioning retries, settings reprovisioning, and worker updates; Zephyr does not rotate it automatically.

Enter the Fastly settings in Zephyr

In the Fastly custom integration creation form, confirm that the correct organization is selected at the top of the dashboard. Then complete the API Token panel:

  • API token: Paste the token value copied from Fastly.
  • Domain: Enter the root domain, such as example.com. Do not enter a URL or the derived ze.example.com hostname.

Select Continue. Zephyr validates the credential through provisioning rather than a separate token preflight.

Configure Worker

The final panel states that Deploy URL routing is managed automatically. Review the configuration and select Finish.

Zephyr returns to the integrations list and shows setup in progress while it polls Fastly. The integration becomes active after provisioning succeeds, or failed if Fastly rejects the request. An active result confirms that the token worked.

Configuration inputs

Name

A display name between 3 and 100 characters. Letters, digits, spaces, hyphens, underscores, and apostrophes are allowed.

Unique identifier

A URL identifier between 3 and 50 characters, using lowercase letters, digits, hyphens, and underscores. It is immutable after creation.

Set integration as default

Makes this integration the default for deployments that do not explicitly select another integration.

API token

The Fastly token value. Zephyr never redisplays the stored token while editing. Leave this field blank to retain the existing credential, or enter a new token to replace it and reprovision the integration.

Domain

The registered root domain, such as example.com, without a protocol, path, or ze. prefix. It is immutable after creation.

Replacing a credential

Replacing the API token reprovisions the integration. Zephyr does not revoke the old Fastly token or delete the previous Fastly service and related resources. Revoke and remove those resources in Fastly after the replacement is active.

What Zephyr creates

For example.com, Zephyr uploads the Compute package, activates the service version, and creates:

  • Compute service ze-worker-example-com
  • Domains ze.example.com and *.ze.example.com
  • Config store config with the jwt-secret entry
  • KV stores ze_envs, ze_files, and ze_snapshots

Troubleshooting

Zephyr reports Fastly provisioning failures generically. If the integration is marked failed, check:

  • The token is an automation token with the Engineer role, or a user token owned by an Engineer or Superuser.
  • The token has Global API access (global) and access to all account services.
  • The token has not expired or been revoked.
  • Domain contains only the registered root domain, such as example.com.

Correct the integration settings and retry provisioning. Test DNS checks DNS records only; it does not validate the API token. TLS subscriptions and certificate validation remain managed in Fastly.