cloudflare · diff

git:20260809.e8d3666 to git:20260820.cd23820

51 added, 249 removed. Audit A to A.

---
name: cloudflare
- description: Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF, DDoS), and infrastructure-as-code (Terraform, Pulumi). Use for any Cloudflare development task. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.
+ description: Route an ambiguous or cross-product Cloudflare platform request to the appropriate product, documentation, or narrower local skill. Use when the user needs help choosing among Cloudflare compute, storage, AI, networking, security, media, or infrastructure products. Do not trigger when the request already names a specific Cloudflare product or matches a narrower installed skill.
---
- # Cloudflare Platform Skill
-
- Consolidated skill for building on the Cloudflare platform. Use decision trees below to find the right product, then load detailed references.
-
- Your knowledge of Cloudflare APIs, types, limits, and pricing may be outdated. **Prefer retrieval over pre-training** — the references in this skill are starting points, not source of truth.
-
- ## Retrieval Sources
-
- Fetch the **latest** information before citing specific numbers, API signatures, or configuration options. Do not rely on baked-in knowledge or these reference files alone.
-
- | Source | How to retrieve | Use for |
- |--------|----------------|---------|
- | Cloudflare docs | `cloudflare-docs` search tool or `https://developers.cloudflare.com/` | Limits, pricing, API reference, compatibility dates/flags |
- | Workers types | `npm pack @cloudflare/workers-types` or check `node_modules` | Type signatures, binding shapes, handler types |
- | Wrangler config schema | `node_modules/wrangler/config-schema.json` | Config fields, binding shapes, allowed values |
- | Product changelogs | `https://developers.cloudflare.com/changelog/` | Recent changes to limits, features, deprecations |
-
- When a reference file and the docs disagree, **trust the docs**. This is especially important for: numeric limits, pricing tiers, type signatures, and configuration options.
-
- ## Quick Decision Trees
-
- ### "I need production architecture or a deployment"
-
- ```
- Need to design, migrate, release, or debug a production Cloudflare system?
- └─ Load cloudflare-production-builder for material cross-product decisions
- ├─ Multiple Workers, service bindings, or Containers → model independent rollout axes
- ├─ Durable handoff or background work → define idempotency and repair first
- ├─ Schema or Durable Object lifecycle change → use staged compatibility gates
- └─ Release or rollback → verify exact live identities, not command success
- ```
-
- Never assume independently deployed surfaces converge atomically. Apply the
- production-builder guidance proportionally and load only references relevant to
- the requested operation.
-
- ### "I need feature flags"
-
- ```
- Need feature flags?
- └─ Feature toggles, targeting rules, percentage rollouts → flagship/
- ├─ Evaluate in Workers → Flagship binding (env.FLAGS)
- ├─ Evaluate in Node.js / browser → OpenFeature SDK (@cloudflare/flagship)
- └─ Manage flags via API → Flagship REST API
- ```
-
- ### "I need to run code"
-
- ```
- Need to run code?
- ├─ Serverless functions at the edge → workers/
- ├─ Full-stack web app with Git deploys → pages/
- ├─ Stateful coordination/real-time → durable-objects/
- ├─ Long-running multi-step jobs → workflows/
- ├─ Run containers → containers/
- ├─ Multi-tenant (customers deploy code) → workers-for-platforms/
- ├─ Scheduled tasks (cron) → cron-triggers/
- ├─ Lightweight edge logic (modify HTTP) → snippets/
- ├─ Process Worker execution events (logs/observability) → tail-workers/
- └─ Optimize latency to backend infrastructure → smart-placement/
- ```
-
- ### "I need to store data"
-
- ```
- Need storage?
- ├─ Key-value (config, sessions, cache) → kv/
- ├─ Relational SQL → d1/ (SQLite) or hyperdrive/ (existing Postgres/MySQL)
- ├─ Object/file storage (S3-compatible) → r2/
- ├─ Versioned file trees (repos, build outputs, checkpoints) → artifacts/
- ├─ Message queue (async processing) → queues/
- ├─ Vector embeddings (AI/semantic search) → vectorize/
- ├─ Strongly-consistent per-entity state → durable-objects/ (DO storage)
- ├─ Secrets management → secrets-store/
- ├─ Streaming ETL to R2 → pipelines/
- ├─ Managed Apache Iceberg catalog on R2 → r2-data-catalog/
- ├─ Serverless SQL analytics over Iceberg tables → r2-sql/
- └─ Persistent cache (long-term retention) → cache-reserve/
- ```
-
- ### "I need AI/ML"
-
- ```
- Need AI?
- ├─ Run inference (LLMs, embeddings, images) → workers-ai/
- ├─ Vector database for RAG/search → vectorize/
- ├─ Build stateful AI agents → agents-sdk/
- ├─ Gateway for any AI provider (caching, routing) → ai-gateway/
- └─ AI-powered search widget → ai-search/
- ```
-
- ### "I need networking/connectivity"
-
- ```
- Need networking?
- ├─ Expose local service to internet → tunnel/
- ├─ TCP/UDP proxy (non-HTTP) → spectrum/
- ├─ WebRTC TURN server → turn/
- ├─ Private network connectivity → network-interconnect/
- ├─ Optimize routing → argo-smart-routing/
- ├─ Optimize latency to backend (not user) → smart-placement/
- └─ Real-time video/audio → realtimekit/ or realtime-sfu/
- ```
-
- ### "I need security"
-
- ```
- Need security?
- ├─ Web Application Firewall → waf/
- ├─ DDoS protection → ddos/
- ├─ Bot detection/management → bot-management/
- ├─ API protection → api-shield/
- ├─ CAPTCHA alternative → turnstile/
- └─ Credential leak detection → waf/ (managed ruleset)
- ```
-
- ### "I need media/content"
-
- ```
- Need media?
- ├─ Image optimization/transformation → images/
- ├─ Video streaming/encoding → stream/
- ├─ Browser automation/screenshots → browser-rendering/
- └─ Third-party script management → zaraz/
- ```
-
- ### "I need analytics/metrics data"
-
- ```
- Need analytics?
- ├─ Query across all Cloudflare products (HTTP, Workers, DNS, etc.) → graphql-api/
- ├─ Custom high-cardinality metrics from Workers → analytics-engine/
- ├─ Client-side (RUM) performance data → web-analytics/
- ├─ Workers Logs and real-time debugging → observability/
- ├─ SQL over Iceberg data lake (logs, events) → r2-sql/ (+ pipelines/, r2-data-catalog/)
- └─ Raw logs (Logpush to external tools) → Cloudflare docs
- ```
-
- ### "I need infrastructure-as-code"
-
- ```
- Need IaC? → pulumi/ (Pulumi), terraform/ (Terraform), or api/ (REST API)
- ```
-
- ## Product Index
-
- ### Cross-product production engineering
-
- | Task | Skill |
- |---------|-----------|
- | Architecture, durable handoffs, migrations, releases, rollback, and live verification | `cloudflare-production-builder` |
-
- ### Feature Flags
- | Product | Reference |
- |---------|-----------|
- | Flagship | `references/flagship/` |
+ # Cloudflare Platform Router
- ### Compute & Runtime
- | Product | Reference |
- |---------|-----------|
- | Workers | `references/workers/` |
- | Pages | `references/pages/` |
- | Pages Functions | `references/pages-functions/` |
- | Durable Objects | `references/durable-objects/` |
- | Workflows | `references/workflows/` |
- | Containers | `references/containers/` |
- | Workers for Platforms | `references/workers-for-platforms/` |
- | Cron Triggers | `references/cron-triggers/` |
- | Tail Workers | `references/tail-workers/` |
- | Snippets | `references/snippets/` |
- | Smart Placement | `references/smart-placement/` |
+ Choose the smallest relevant product surface, then use current first-party
+ documentation or a narrower skill. This router is not a local copy of the
+ Cloudflare product manuals.
- ### Storage & Data
- | Product | Reference |
- |---------|-----------|
- | KV | `references/kv/` |
- | D1 | `references/d1/` |
- | R2 | `references/r2/` |
- | Artifacts | `references/artifacts/` |
- | Queues | `references/queues/` |
- | Hyperdrive | `references/hyperdrive/` |
- | DO Storage | `references/do-storage/` |
- | Secrets Store | `references/secrets-store/` |
- | Pipelines | `references/pipelines/` |
- | R2 Data Catalog | `references/r2-data-catalog/` |
- | R2 SQL | `references/r2-sql/` |
+ ## Retrieve current facts
- ### AI & Machine Learning
- | Product | Reference |
- |---------|-----------|
- | Workers AI | `references/workers-ai/` |
- | Vectorize | `references/vectorize/` |
- | Agents SDK | `references/agents-sdk/` |
- | AI Gateway | `references/ai-gateway/` |
- | AI Search | `references/ai-search/` |
+ - [Cloudflare documentation](https://developers.cloudflare.com/) for supported
+ behavior, limits, pricing, and product maturity.
+ - [Cloudflare changelog](https://developers.cloudflare.com/changelog/) for recent
+ launches and breaking changes.
+ - The installed Wrangler configuration schema and package `.d.ts` files for the
+ project's actual build contract.
- ### Networking & Connectivity
- | Product | Reference |
- |---------|-----------|
- | Tunnel | `references/tunnel/` |
- | Spectrum | `references/spectrum/` |
- | TURN | `references/turn/` |
- | Network Interconnect | `references/network-interconnect/` |
- | Argo Smart Routing | `references/argo-smart-routing/` |
- | Workers VPC | `references/workers-vpc/` |
+ Do not infer current API signatures, limits, pricing, or availability from this
+ router.
- ### Security
- | Product | Reference |
- |---------|-----------|
- | WAF | `references/waf/` |
- | DDoS Protection | `references/ddos/` |
- | Bot Management | `references/bot-management/` |
- | API Shield | `references/api-shield/` |
- | Turnstile | `references/turnstile/` |
+ ## Route the request
- ### Media & Content
- | Product | Reference |
- |---------|-----------|
- | Images | `references/images/` |
- | Stream | `references/stream/` |
- | Browser Rendering | `references/browser-rendering/` |
- | Zaraz | `references/zaraz/` |
+ | Need | Start with |
+ | --- | --- |
+ | Stateless edge or full-stack compute | Workers, Pages, or Pages Functions |
+ | Per-key coordination, realtime state, or alarms | Durable Objects |
+ | Long-running steps or asynchronous delivery | Workflows or Queues |
+ | Containers or isolated code execution | Containers or Sandbox SDK |
+ | Key/value configuration or cache-like data | KV |
+ | Relational SQLite data | D1 |
+ | Existing PostgreSQL/MySQL acceleration | Hyperdrive |
+ | Objects and files | R2 |
+ | Versioned file trees or Git-compatible artifacts | Artifacts |
+ | Vector search or model inference | Vectorize or Workers AI |
+ | Stateful AI agents | Cloudflare Agents SDK |
+ | AI-provider routing and observability | AI Gateway |
+ | Feature flags | Flagship |
+ | Public hostname to a private origin | Cloudflare Tunnel |
+ | Private access, filtering, or SASE | Cloudflare One skills |
+ | CAPTCHA or form bot protection | Turnstile |
+ | Image or video delivery | Images or Stream |
+ | Browser automation | Browser Rendering |
+ | Infrastructure as code | Terraform, Pulumi, or Cloudflare API |
- ### Real-Time Communication
- | Product | Reference |
- |---------|-----------|
- | RealtimeKit | `references/realtimekit/` |
- | Realtime SFU | `references/realtime-sfu/` |
+ When several products appear viable, ask what consistency, latency, lifecycle,
+ data shape, and operator interface the application actually needs. Do not select
+ a product merely because it is newer or appears elsewhere in the stack.
- ### Developer Tools
- | Product | Reference |
- |---------|-----------|
- | Wrangler | `references/wrangler/` |
- | Miniflare | `references/miniflare/` |
- | C3 | `references/c3/` |
- | Observability | `references/observability/` |
- | GraphQL Analytics API | `references/graphql-api/` |
- | Analytics Engine | `references/analytics-engine/` |
- | Web Analytics | `references/web-analytics/` |
- | Sandbox | `references/sandbox/` |
- | Workerd | `references/workerd/` |
- | Workers Playground | `references/workers-playground/` |
+ ## Prefer narrower skills
- ### Infrastructure as Code
- | Product | Reference |
- |---------|-----------|
- | Pulumi | `references/pulumi/` |
- | Terraform | `references/terraform/` |
- | API | `references/api/` |
+ - `cloudflare-production-builder` for material production architecture,
+ migrations, deployment, rollback, or live verification.
+ - `durable-objects` for Durable Object design and implementation.
+ - `agents-sdk` for applications using Cloudflare's `agents` package.
+ - `workers-best-practices` for Workers-specific authoring or review.
+ - `wrangler` for exact CLI or configuration work.
+ - `cloudflare-email-service`, `turnstile-spin`, `sandbox-sdk`, and
+ `cloudflare-do-turn-based-multiplayer` for their named domains.
+ - `cloudflare-one` and `cloudflare-one-migrations` for Zero Trust and SASE.
- ### Other Services
- | Product | Reference |
- |---------|-----------|
- | Email Routing | `references/email-routing/` |
- | Email Workers | `references/email-workers/` |
- | Static Assets | `references/static-assets/` |
- | Bindings | `references/bindings/` |
- | Cache Reserve | `references/cache-reserve/` |
+ Load only the skill that owns the active decision. A cross-product request does
+ not require every product skill.