Boom Media
Bunny.net Ecosystem Rollout & Cost Plan

Bunny.net across every app that can use it โ€” with real monthly costs.

The execution plan that turns the July 9 stack-fit analysis into a rollout: which of the 14 SaaS apps + BOO + client sites adopt which Bunny product, the shared-zone architecture that keeps cost flat as apps join, and the estimated bill now and at scale.

Boom Media SaaS · 2026-07-14 · companion to bunny-net-stack-fit.html
What Changed Since the 7/9 Analysis

Three upgrades to the earlier verdicts

๐Ÿ”

Storage: Situational โ†’ Adopt. Bunny Storage now has S3-compatible access + presigned URLs (public preview), so apps can write to it with any standard S3 SDK. Combined with the still-open "user uploads aren't backed up or CDN-delivered" gap in the data-protection matrix, it's now the delivery layer for app media and uploads. B2 remains the backup of record โ€” replication is not backup (deletes propagate).

๐Ÿ”

CDN pull zones: Situational โ†’ Adopt for Coolify sites. The 7/9 doc deferred CDN/WAF to a planned Cloudflare front that was never deployed (feature-parity tracker: CDN โฌœ, WAF โฌœ). Rather than keep waiting, put Bunny pull zones (+ free Shield Basic) in front of the Coolify-hosted client sites now. Rule: one edge per site โ€” never stack Bunny and Cloudflare on the same domain. If Cloudflare gets adopted later, it's a per-site swap.

โš ๏ธ

Overlap ruling needed (App-Boundaries style): Bunny Shield's edge rules cover part of what the Compliee security-monitoring spec scoped to CrowdSec. Decide which layer owns "attack blocking" before building both โ€” recommendation: Bunny Shield = network/edge filtering (infra), Compliee/CrowdSec = the client-facing security product + reporting. They can coexist, but the ruling should be written into APP_BOUNDARIES.md.

The Shared-Zone Architecture

Three Bunny resources serve the whole ecosystem

The trick that keeps cost flat: don't create a zone per app. Optimizer is billed per pull zone (~$9.50/mo each) โ€” one shared media zone means all 15+ apps split a single fee. Apps are separated by folder path and per-app S3 keys, not by zone.

1 ยท Storage Zone โ€” โœ… LIVE 2026-07-14

๐Ÿ—„๏ธ boom-media

Zone ID 1657587 ยท primary NY + replica LA ยท upload host ny.storage.bunnycdn.com. Folder per app: /displayee/ /posttee/ /addee/ /aprovee/โ€ฆ Access keys live in the Bunny dashboard โ†’ zone โ†’ FTP & API Access; park them in Doppler. โš ๏ธ Created via API โ€” verify the S3-Compatibility toggle in the dashboard; if it can't be enabled post-creation, either recreate the zone before it holds data or use the native Storage API (simple HTTP PUT).

2 ยท Media Pull Zone โ€” โœ… LIVE 2026-07-14

๐ŸŒ boom-media.b-cdn.net

Pull zone ID 6155330, origin = the storage zone, Optimizer ON (WebP + manipulation engine โ€” the $9.50/mo is now metering against trial credit). Next: CNAME media.boommedia.us โ†’ boom-media.b-cdn.net and add it as a custom hostname + free SSL in the dashboard.

3 ยท Site Pull Zones

๐Ÿ›ก๏ธ Per client site

One small pull zone per Coolify-hosted client site (origin = 24.199.95.101 via Traefik). Edge caching, bandwidth offload, free Shield Basic. Created as each site gets its real domain (the pending domain-assignment task).

๐Ÿ“‹

Plus the two already-decided pieces: Stream (Library 698905, live on Displayee โ€” extend per app/client as video appears) and a Magic Containers pilot for Compliee's Playwright scanner (scale-to-zero; solves "can't run on Vercel" without loading the shared droplet). Explicit non-uses: Bunny Database (data layer = Supabase), Bunny DNS (low value), Bunny Storage as backup (that's B2), and live camera WHEP streams (WebRTC can't be CDN-cached โ€” MediaMTX stays direct on the droplet).

Per-App Adoption Matrix

All 14 SaaS apps + BOO + client sites

What each app actually uses Bunny for. Shared = the boom-media storage zone + optimized pull zone above (no new cost per app). Priority reflects build status โ€” apps that are live and media-heavy first.

AppBunny productsWhat it's used forPriority
Displayeedigital signage + video + camerasStream โœ“ live Shared storage/CDN OptimizerClient videos (live today). Add signage images, menus, posters & thumbnails to the shared zone so screens pull from the edge, not the droplet/Supabase. Cameras stay on MediaMTX.LIVE + EXPAND
Aproveeapprovals + video timeline reviewStream Shared storage/CDNHost the review videos behind the new timecode-comment feature on Stream (adaptive playback beats raw files); proof images/PDF previews via shared zone with presigned URLs.NOW
BOO + client sites~9 Coolify apps + boo-v2Site pull zones Optimizer Stream Shield Basic (free)Edge cache + bandwidth offload for every Coolify-hosted site as domains are assigned; Optimizer on image-heavy restaurant menus/heroes; testimonial & hero videos on Stream.NOW
Postteesocial schedulerShared storage (S3) Optimizer StreamUser-uploaded post media lands in /posttee/ via S3 SDK; platform APIs fetch from CDN URLs; video posts via Stream.NEXT
Addeead creativeShared storage/CDN OptimizerGenerated ad creative stored once, resized/cropped per placement by Optimizer URL params instead of rendering every variant.NEXT
Bloggyblog/contentOptimizer StreamPost images through the optimized zone (Core Web Vitals / SEO win โ€” Bloggy's whole pitch); embedded video via Stream.NEXT
ComplieeADA scanningMagic Containers Shared storagePlaywright scanner as a scale-to-zero container (the "can't run on Vercel" fix); scan screenshots + PDF reports to the shared zone.NEXT ยท pilot
QRcodeeQR codesShared storage/CDNGenerated QR PNGs/SVGs served from the edge โ€” tiny files, high hit rates, near-zero cost.LATER
Assisteeremote supportStreamOnboarding/how-to tutorial videos. RustDesk relay traffic stays off Bunny (real-time, not cacheable).LATER
Localeycitations + reviewsOptimizer Shared storageReview photos and citation/business images optimized on delivery to BOO + Dashee portals.LATER
Replyeechatbot + live chat ยท VercelShared storage (S3)Chat file attachments via presigned URLs โ€” offloads Supabase Storage egress. (App itself stays on Vercel.)LATER
RankeeSEOShared storage/CDNReport assets + generated OG images. Light user.LATER
Rewardeeloyalty engineShared storage/CDNReward/gift-card artwork + email images. Light user.LATER
Dasheeclient dashboardsInherits onlyDisplays Displayee/Localey/camera content โ€” consumes their Bunny URLs. No direct adoption needed.INHERITS
Signneee-signaturesCautionSigned/executed documents stay in Supabase Storage + B2 (audit-trail custody โ€” don't scatter legal docs across a CDN). Only non-sensitive template previews may use the shared zone.MOSTLY SKIP
Docs hub + boommedia.usstatic sitesSite pull zoneCache the password-protected docs hub + marketing site at the edge.LATER
Cost to Run

Unit pricing & the estimated monthly bill

Bunny is pure pay-as-you-go (โ‰ˆ$1/mo account minimum). Unit prices below are the published rates as of mid-2026 โ€” verify at bunny.net/pricing before budgeting, and note Magic Containers / S3-compat are newer products whose pricing can move.

ProductUnit price (est.)Your driverEst. now /moEst. at ~50 clients /mo
Stream~$0.01/GB-mo stored + ~$0.005/GB deliveredClient videos (Displayee, Aprovee review, BOO heroes). Fixing the 18โ†’5 Mbps export cuts this 3ร—.$1โ€“3$10โ€“25
Storage zone~$0.01/GB-mo per replica region (std tier)App media + uploads, ~10โ€“30 GB ร— 2โ€“3 regions$0.50โ€“1$5โ€“10
CDN traffic~$0.01/GB (NA/EU standard tier)All pull-zone delivery (media + client sites)$1โ€“3$10โ€“20
Optimizer~$9.50/mo per pull zone (flat)1ร— on the shared media zone (the whole point of the shared architecture). Add per-site only for image-heavy client sites that measurably need it.$9.50$9.50โ€“28.50
Shield BasicFree per pull zone (Advanced ~$9.50/zone if ever needed)Edge protection on client-site zones$0$0
Magic ContainersUsage-based (vCPU + RAM hours)Compliee scanner pilot, scale-to-zero$5โ€“15$15โ€“40
Edge ScriptingPer-request, pennies at this volumeSigned-URL minting for Stream/Storage (later)$0โ€“1$1โ€“3
DNS / Databaseโ€”Not adopted$0$0
~$12โ€“18
Phase 1โ€“2 (media stack + client-site zones), per month
~$17โ€“33
Full rollout incl. Compliee containers pilot, per month
~$50โ€“125
At ~50 active clients with heavy media, per month
๐Ÿ’ณ

The $49.15 trial credit covers roughly 2โ€“3 months of the full rollout โ€” enough to prove every piece (including the containers pilot) before a dollar of real spend. Compare: equivalent Cloudflare Pro + Mux/Vimeo + image CDN would run $60โ€“200/mo.

Execution Order

Rollout, step by step

Phase 1 โœ…

Create the shared media backbone โ€” DONE 2026-07-14 (via API)

Storage zone boom-media (ID 1657587, NY+LA) and pull zone boom-media.b-cdn.net (ID 6155330, Optimizer ON) are live. Remaining: verify the S3-Compatibility toggle in the dashboard (API creation may not set it โ€” recreate before first upload if needed), CNAME media.boommedia.us, put zone keys in Doppler, and rotate the account API key (it was shared in chat).

Phase 2

First consumers: Displayee assets + Aprovee review video

Point Displayee signage images/posters at the shared zone; move Aprovee's timeline-review videos onto Stream. Both features are already built โ€” this is config + upload-path changes, and it establishes the reusable pattern.

Phase 3

Client-site pull zones, ride-along with domain assignment

The 8 Coolify sites still need real domains (STATUS_TRACKER to-do). As each domain is assigned, route it through a Bunny pull zone โ†’ origin droplet. One combined task instead of two passes. Free Shield Basic on each.

Phase 4

Posttee / Addee / Bloggy uploads onto S3-compatible storage

Swap their upload targets to the shared zone via S3 SDK (folder + key per app). Presigned URLs for private media. Add the zone to the B2 backup sync โ€” Bunny replicates for delivery; B2 keeps the restore copy.

Phase 5

Compliee scanner pilot on Magic Containers

Containerize the Playwright scanner, deploy scale-to-zero, benchmark cost per scan vs. parking it on the boom-hosting droplet. Keep whichever is cheaper โ€” the droplet fallback remains valid.

Gate

Before real spend: the two rulings

(1) Write the Bunny-Shield-vs-Compliee/CrowdSec ownership ruling into APP_BOUNDARIES.md. (2) Confirm the edge decision โ€” Bunny pull zones now, Cloudflare only as a future per-site swap, never both on one domain.