Provide a minimal, cost-free-at-dev-scale public Telegram ingress that crosses the observed Telegram-to-Yandex public-edge reachability gap and durably hands accepted updates to Yandex Workflows.
Estimate
3 SP / 2 engineering days
Risk: medium
Scope
Add a minimal Cloudflare Worker on dev-api-sessionless.triborg.dev.
Accept only POST /telegram/webhook.
Verify X-Telegram-Bot-Api-Secret-Token from a Cloudflare secret binding.
Validate Telegram update JSON and enforce a bounded request size.
Forward the unchanged body to a Yandex Workflows execution capability held in a second secret binding.
Return success only after Workflows returns a valid execution ID; return non-2xx on timeout or handoff failure so Telegram retries.
Provision the Yandex Workflows bridge and a bounded retry policy for its API Gateway call.
Keep Worker source/configuration versioned and pin Wrangler.
Add an explicit operator deployment script; keep Cloudflare token and both runtime bindings outside Git and Terraform state.
Document DNS/certificate ownership and the split Yandex Terraform + Wrangler deployment procedure.
Non-goals
YDB/YMQ/worker business-flow verification.
Canary promotion or rollback.
Monitoring alert creation.
Any AI harness or subscription credential implementation.
Verification
Unit tests cover path, method, secret, JSON, size, upstream failure and acknowledgement validation.
A Wrangler dry-run bundle runs in mirrored CI.
Missing/wrong Telegram secrets are rejected live.
getWebhookInfo reports the Cloudflare hostname, zero pending updates and no new timeout.
A synthetic Telegram update creates one successful Yandex Workflow execution without exposing payloads or credentials.
Acceptance criteria
The Worker adds no business state and emits no payload/credential logs.
Cloudflare secret values never enter Git, plans, state, argv or CI output.
Direct Yandex public endpoints are not used as Telegram webhook destinations.
Failure before durable Workflows acceptance remains retryable by Telegram.
The implementation stays within the cloud-dev 100 RUB/month budget at expected traffic.
Parent and architecture
Outcome
Provide a minimal, cost-free-at-dev-scale public Telegram ingress that crosses the observed Telegram-to-Yandex public-edge reachability gap and durably hands accepted updates to Yandex Workflows.
Estimate
Scope
dev-api-sessionless.triborg.dev.POST /telegram/webhook.X-Telegram-Bot-Api-Secret-Tokenfrom a Cloudflare secret binding.Non-goals
Verification
getWebhookInforeports the Cloudflare hostname, zero pending updates and no new timeout.Acceptance criteria