The execution plan that turns the July 9 stack-fit analysis into a rollout: which of the 14 SaaS apps + BOO + client sites adopt which Bunny product, the shared-zone architecture that keeps cost flat as apps join, and the estimated bill now and at scale.
Storage: Situational โ Adopt. Bunny Storage now has S3-compatible access + presigned URLs (public preview), so apps can write to it with any standard S3 SDK. Combined with the still-open "user uploads aren't backed up or CDN-delivered" gap in the data-protection matrix, it's now the delivery layer for app media and uploads. B2 remains the backup of record โ replication is not backup (deletes propagate).
CDN pull zones: Situational โ Adopt for Coolify sites. The 7/9 doc deferred CDN/WAF to a planned Cloudflare front that was never deployed (feature-parity tracker: CDN โฌ, WAF โฌ). Rather than keep waiting, put Bunny pull zones (+ free Shield Basic) in front of the Coolify-hosted client sites now. Rule: one edge per site โ never stack Bunny and Cloudflare on the same domain. If Cloudflare gets adopted later, it's a per-site swap.
Overlap ruling needed (App-Boundaries style): Bunny Shield's edge rules cover part of what the Compliee security-monitoring spec scoped to CrowdSec. Decide which layer owns "attack blocking" before building both โ recommendation: Bunny Shield = network/edge filtering (infra), Compliee/CrowdSec = the client-facing security product + reporting. They can coexist, but the ruling should be written into APP_BOUNDARIES.md.
The trick that keeps cost flat: don't create a zone per app. Optimizer is billed per pull zone (~$9.50/mo each) โ one shared media zone means all 15+ apps split a single fee. Apps are separated by folder path and per-app S3 keys, not by zone.
Zone ID 1657587 ยท primary NY + replica LA ยท upload host ny.storage.bunnycdn.com. Folder per app: /displayee/ /posttee/ /addee/ /aprovee/โฆ Access keys live in the Bunny dashboard โ zone โ FTP & API Access; park them in Doppler. โ ๏ธ Created via API โ verify the S3-Compatibility toggle in the dashboard; if it can't be enabled post-creation, either recreate the zone before it holds data or use the native Storage API (simple HTTP PUT).
Pull zone ID 6155330, origin = the storage zone, Optimizer ON (WebP + manipulation engine โ the $9.50/mo is now metering against trial credit). Next: CNAME media.boommedia.us โ boom-media.b-cdn.net and add it as a custom hostname + free SSL in the dashboard.
One small pull zone per Coolify-hosted client site (origin = 24.199.95.101 via Traefik). Edge caching, bandwidth offload, free Shield Basic. Created as each site gets its real domain (the pending domain-assignment task).
Plus the two already-decided pieces: Stream (Library 698905, live on Displayee โ extend per app/client as video appears) and a Magic Containers pilot for Compliee's Playwright scanner (scale-to-zero; solves "can't run on Vercel" without loading the shared droplet). Explicit non-uses: Bunny Database (data layer = Supabase), Bunny DNS (low value), Bunny Storage as backup (that's B2), and live camera WHEP streams (WebRTC can't be CDN-cached โ MediaMTX stays direct on the droplet).
What each app actually uses Bunny for. Shared = the boom-media storage zone + optimized pull zone above (no new cost per app). Priority reflects build status โ apps that are live and media-heavy first.
| App | Bunny products | What it's used for | Priority |
|---|---|---|---|
| Displayeedigital signage + video + cameras | Stream โ live Shared storage/CDN Optimizer | Client videos (live today). Add signage images, menus, posters & thumbnails to the shared zone so screens pull from the edge, not the droplet/Supabase. Cameras stay on MediaMTX. | LIVE + EXPAND |
| Aproveeapprovals + video timeline review | Stream Shared storage/CDN | Host the review videos behind the new timecode-comment feature on Stream (adaptive playback beats raw files); proof images/PDF previews via shared zone with presigned URLs. | NOW |
| BOO + client sites~9 Coolify apps + boo-v2 | Site pull zones Optimizer Stream Shield Basic (free) | Edge cache + bandwidth offload for every Coolify-hosted site as domains are assigned; Optimizer on image-heavy restaurant menus/heroes; testimonial & hero videos on Stream. | NOW |
| Postteesocial scheduler | Shared storage (S3) Optimizer Stream | User-uploaded post media lands in /posttee/ via S3 SDK; platform APIs fetch from CDN URLs; video posts via Stream. | NEXT |
| Addeead creative | Shared storage/CDN Optimizer | Generated ad creative stored once, resized/cropped per placement by Optimizer URL params instead of rendering every variant. | NEXT |
| Bloggyblog/content | Optimizer Stream | Post images through the optimized zone (Core Web Vitals / SEO win โ Bloggy's whole pitch); embedded video via Stream. | NEXT |
| ComplieeADA scanning | Magic Containers Shared storage | Playwright scanner as a scale-to-zero container (the "can't run on Vercel" fix); scan screenshots + PDF reports to the shared zone. | NEXT ยท pilot |
| QRcodeeQR codes | Shared storage/CDN | Generated QR PNGs/SVGs served from the edge โ tiny files, high hit rates, near-zero cost. | LATER |
| Assisteeremote support | Stream | Onboarding/how-to tutorial videos. RustDesk relay traffic stays off Bunny (real-time, not cacheable). | LATER |
| Localeycitations + reviews | Optimizer Shared storage | Review photos and citation/business images optimized on delivery to BOO + Dashee portals. | LATER |
| Replyeechatbot + live chat ยท Vercel | Shared storage (S3) | Chat file attachments via presigned URLs โ offloads Supabase Storage egress. (App itself stays on Vercel.) | LATER |
| RankeeSEO | Shared storage/CDN | Report assets + generated OG images. Light user. | LATER |
| Rewardeeloyalty engine | Shared storage/CDN | Reward/gift-card artwork + email images. Light user. | LATER |
| Dasheeclient dashboards | Inherits only | Displays Displayee/Localey/camera content โ consumes their Bunny URLs. No direct adoption needed. | INHERITS |
| Signneee-signatures | Caution | Signed/executed documents stay in Supabase Storage + B2 (audit-trail custody โ don't scatter legal docs across a CDN). Only non-sensitive template previews may use the shared zone. | MOSTLY SKIP |
| Docs hub + boommedia.usstatic sites | Site pull zone | Cache the password-protected docs hub + marketing site at the edge. | LATER |
Bunny is pure pay-as-you-go (โ$1/mo account minimum). Unit prices below are the published rates as of mid-2026 โ verify at bunny.net/pricing before budgeting, and note Magic Containers / S3-compat are newer products whose pricing can move.
| Product | Unit price (est.) | Your driver | Est. now /mo | Est. at ~50 clients /mo |
|---|---|---|---|---|
| Stream | ~$0.01/GB-mo stored + ~$0.005/GB delivered | Client videos (Displayee, Aprovee review, BOO heroes). Fixing the 18โ5 Mbps export cuts this 3ร. | $1โ3 | $10โ25 |
| Storage zone | ~$0.01/GB-mo per replica region (std tier) | App media + uploads, ~10โ30 GB ร 2โ3 regions | $0.50โ1 | $5โ10 |
| CDN traffic | ~$0.01/GB (NA/EU standard tier) | All pull-zone delivery (media + client sites) | $1โ3 | $10โ20 |
| Optimizer | ~$9.50/mo per pull zone (flat) | 1ร on the shared media zone (the whole point of the shared architecture). Add per-site only for image-heavy client sites that measurably need it. | $9.50 | $9.50โ28.50 |
| Shield Basic | Free per pull zone (Advanced ~$9.50/zone if ever needed) | Edge protection on client-site zones | $0 | $0 |
| Magic Containers | Usage-based (vCPU + RAM hours) | Compliee scanner pilot, scale-to-zero | $5โ15 | $15โ40 |
| Edge Scripting | Per-request, pennies at this volume | Signed-URL minting for Stream/Storage (later) | $0โ1 | $1โ3 |
| DNS / Database | โ | Not adopted | $0 | $0 |
The $49.15 trial credit covers roughly 2โ3 months of the full rollout โ enough to prove every piece (including the containers pilot) before a dollar of real spend. Compare: equivalent Cloudflare Pro + Mux/Vimeo + image CDN would run $60โ200/mo.
Storage zone boom-media (ID 1657587, NY+LA) and pull zone boom-media.b-cdn.net (ID 6155330, Optimizer ON) are live. Remaining: verify the S3-Compatibility toggle in the dashboard (API creation may not set it โ recreate before first upload if needed), CNAME media.boommedia.us, put zone keys in Doppler, and rotate the account API key (it was shared in chat).
Point Displayee signage images/posters at the shared zone; move Aprovee's timeline-review videos onto Stream. Both features are already built โ this is config + upload-path changes, and it establishes the reusable pattern.
The 8 Coolify sites still need real domains (STATUS_TRACKER to-do). As each domain is assigned, route it through a Bunny pull zone โ origin droplet. One combined task instead of two passes. Free Shield Basic on each.
Swap their upload targets to the shared zone via S3 SDK (folder + key per app). Presigned URLs for private media. Add the zone to the B2 backup sync โ Bunny replicates for delivery; B2 keeps the restore copy.
Containerize the Playwright scanner, deploy scale-to-zero, benchmark cost per scan vs. parking it on the boom-hosting droplet. Keep whichever is cheaper โ the droplet fallback remains valid.
(1) Write the Bunny-Shield-vs-Compliee/CrowdSec ownership ruling into APP_BOUNDARIES.md. (2) Confirm the edge decision โ Bunny pull zones now, Cloudflare only as a future per-site swap, never both on one domain.