How it works
Upload → queue → FFmpeg → expire.
This is what actually happens when you run one of the tools.
1. Upload straight to private storage
Your browser asks for a short-lived upload session and sends the file directly to Google Cloud Storage. The app server never handles the bytes — which is why this stays cheap enough to give away.
2. One job runs at a time
Confirming the upload enqueues a dispatch through Cloud Tasks. A single global worker slot is reserved transactionally, so a burst of traffic queues instead of stampeding. Repeating the same request returns the same job rather than starting a second one.
3. A worker runs FFmpeg
A Cloud Run Job picks up exactly one attempt, runs FFmpeg with argument arrays (never shell strings) built from validated parameters, and heartbeats while it works. Cancelling stops the process. A failed attempt retries at most twice, and a superseded worker cannot publish over a newer one's result.
4. Download, then it goes away
The input is deleted as soon as processing succeeds. The result stays downloadable for about 90 minutes; storage lifecycle rules then remove it. “Delete now” removes everything immediately.
What is not built yet. Being straight about it: there is no per-day job cap. A result is served for about 90 minutes; Delete now removes it at once, and storage deletes anything left over within a day. If a worker crashes mid-job, no reconciliation sweep picks it back up yet — run the tool again.
The stack: Next.js standalone (website) · FastAPI media API · Firestore job state · private GCS buckets (australia-southeast1) · Cloud Tasks dispatch · Cloud Run Jobs workers. No public buckets anywhere.