npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

canopycms-cdk

v0.0.41

Published

AWS CDK constructs and EC2 worker for CanopyCMS deployment

Readme

canopycms-cdk

AWS CDK constructs and EC2 worker for deploying CanopyCMS.

What's Included

CDK Constructs

CanopyCmsService — Core infrastructure (required):

  • VPC (2 AZs, public + private subnets, no NAT Gateway)
  • EFS filesystem with /workspace access point
  • Lambda function (Docker image, EFS mount, private subnet, no internet)
  • Lambda Function URL (for CloudFront origin)
  • EC2 Worker (t4g.nano spot in ASG, public subnet, EFS mount)
  • Security groups and IAM roles (least-privilege)

CanopyCmsDistribution — CloudFront + DNS (optional):

  • ACM certificate with DNS validation
  • CloudFront distribution with Lambda Function URL origin
  • Route53 A/AAAA alias records
  • Cache policies: no-cache for API/editor, long-cache for static assets

Use CanopyCmsDistribution if you don't have existing CloudFront infrastructure. Otherwise, use the functionUrl output from CanopyCmsService and wire it into your own CloudFront setup.

EC2 Worker

The worker/ directory contains the EC2 worker entrypoint for AWS deployments. It:

  • Reads secrets from AWS Secrets Manager
  • Wires up the Clerk-specific auth cache refresher
  • Starts the CmsWorker daemon from canopycms core

The CmsWorker class itself lives in canopycms/worker/cms-worker and is cloud-agnostic. This package re-exports it for convenience.

Usage

import { CanopyCmsService, CanopyCmsDistribution } from 'canopycms-cdk'
import { DockerImageAsset } from 'aws-cdk-lib/aws-ecr-assets'

// Core infrastructure
const cmsService = new CanopyCmsService(this, 'CmsService', {
  cmsDockerImage: lambda.DockerImageCode.fromImageAsset('.'),
  secretsArns: [githubTokenSecret.secretArn, clerkSecretKeySecret.secretArn],
  environment: {
    CLERK_JWT_KEY: clerkJwtKey,
    CANOPY_BOOTSTRAP_ADMIN_IDS: adminIds,
  },
})

// Optional: turnkey CloudFront + DNS
const cmsDist = new CanopyCmsDistribution(this, 'CmsDist', {
  functionUrl: cmsService.functionUrl,
  domainName: 'cms.docs.example.org',
  hostedZoneDomain: 'example.org',
})

Architecture

CloudFront → Lambda Function URL → Lambda (VPC, no internet)
                                        ↕ EFS
                                   EC2 Worker (internet) → GitHub

Lambda handles all CMS operations using local EFS storage. The EC2 worker handles internet-requiring operations (GitHub push/PR, auth cache refresh). They communicate via the shared EFS filesystem.

See ARCHITECTURE.md for details.

Cost

| Resource | Monthly Cost | | ----------------------------- | --------------- | | EC2 t4g.nano spot (ASG 1/1/1) | ~$1.50 | | Lambda (editors only) | ~$1-5 | | EFS (small repo) | ~$1 | | CloudFront (low traffic) | ~$1 | | Total | ~$5-9/month |

What Adopters Provide

| Responsibility | Why | | ------------------------------------------------------- | --------------------- | | Docker image (from their app) | App-specific | | Secrets Manager entries | Site-specific secrets | | CloudFront + DNS (if not using CanopyCmsDistribution) | Existing infra varies | | GitHub Actions CI/CD | CI/CD patterns vary |