⏳ This skill is pending AI review.

Scores will appear once the review pipeline completes.

version unknown

cloudflare-os-operator

@cloudflare⭐ 306 stars

Guides cloudflare/cloudflare-os-starter setup, Cloudflare Access, deployment.jsonc, storage, AI, observability, custom Gatekeepers, deployment, verification, troubleshooting, rollback, and pinned-submodule upgrades. Use only for deployments created from the Cloudflare OS Deployment Starter, not standalone Cloudflare OS checkouts.

Choose how to use this skill

You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.

1. Native installer

This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.

Do not guess an installer command or replace an existing version without reviewing the diff.

2. Complete package recommended

Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.

No complete ProSkills package is published for this listing yet.

3. Prompt-only

Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.

Need only the instruction file?

Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.

No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.

—/10

// RATINGS

⭐GitHub Stars
⭐⭐⭐ 306 on GitHubGitHub ↗

Popular

🟢ProSkills Score
—
📍

Not yet listed on ClawHub or SkillsMP

// README

[!IMPORTANT] Cloudflare OS is early-access software. Pin upstream releases, review changes, and verify the trust boundary before every production upgrade.

Four steps

  1. Install the dependencies and run pnpm exec wrangler login.
  2. Fill in deployment.jsonc: account ID, Worker names, hostname, Access audience, admin emails.
  3. Run pnpm check, then pnpm deploy.
  4. Open /admin and set the site name, logo, and accent color; branding needs no redeploy.

Deploy and Customization expand each step. Everything else on this page is optional reading.

Overview

This repository adds deployment controls around a pinned Cloudflare OS release without modifying the upstream source.

ControlWhat you own
BrandingSite name, logo, and accent color, changed in /admin without a deploy
IdentityThe sign-in method and administrator allowlist; this starter deploys Cloudflare Access mode
RoutingA production Custom Domain or a workers.dev evaluation route
DataExisting KV/R2 resources or automatic provisioning
IntegrationsWrapper-owned Gatekeepers and service bindings without patching upstream
AIA Workers AI model catalog through AI Gateway out of the box, with no API token; which providers and which gateway
OperationsStructured logs, traces, explicit error reports, validation, deployment order, and upgrades

Architecture

The deployment is six Workers. A router owns the public route and serves the frontend, proxying /api to the Workshop backend and /gatekeeper/<name> to whichever Gatekeeper the binding name matches; the Workshop, the Context, Scheduler and custom Gatekeepers, and the Error Reporter sit behind it with no route of their own, reachable only over service bindings.

The deploy command derives temporary Wrangler files from upstream base configs, builds the frontend in Cloudflare Access mode, deploys the private Error Reporter, the Gatekeepers and the Workshop before the router that binds them, and removes generated files even on failure. Secrets never enter tracked configuration.

If you only want branding

A hosted flow deploys the same upstream release to your Cloudflare account without this repository. It builds nothing locally, configures sign-in and your admin emails for you, and leaves the whole /admin surface intact: site name, logo, accent color, announcements, agent instructions, featured blueprints, and which connectors your users can reach. Built-in Gatekeepers such as GitHub and Google are still yours to connect with your own OAuth credentials.

Anything past that needs your own code or settings, which is what this repository is for: custom Gatekeepers, customized error reporting, your own Worker names, reusing storage you already have, choosing how much logging to keep, and a pinned version you upgrade when you decide. Hosted deployments also run on a workers.dev address, so deploy from here if you want the app on your own domain, or the email Gatekeeper, which needs a zone. Come back when branding stops being enough.

Deploy

1. Prepare the workspace

Install Node.js 24.19 or newer (the deploy scripts are TypeScript run directly by node), pnpm 11.17, and authenticate Wrangler:

git submodule update --init
pnpm install
pnpm --dir cloudflare-os install
pnpm exec wrangler login

Your account needs Workers, KV, R2, Browser Rendering, and Dynamic Worker Loaders. It also needs Workers AI and AI Gateway, which the default model catalog runs on; only turning that catalog off makes them dispensable. Artifacts is optional.

2. Configure sign-in

Cloudflare OS supports several sign-in methods. This starter deploys Cloudflare Access mode, which verifies identity before a request reaches the Worker. See Sign-in methods for the alternatives and what switching involves.

  1. Choose a public hostname in an active Cloudflare zone, such as os.example.com.
  2. Create a self-hosted Access application for that hostname.
  3. Copy its application audience tag.
  4. Open deployment.jsonc and replace the active placeholders. Every control is annotated in place.

The hostname belongs to the router, the only Worker here with a public route. Wrangler creates its DNS and TLS at deploy time. For an evaluation without a zone, switch the annotated route to { "workersDev": true } and set publicBaseUrl to the resulting origin.

3. Validate and deploy

pnpm check
pnpm deploy

With resource values left as null, Wrangler creates the three KV namespaces and R2 bucket automatically and reconnects them on later deploys. Set expli

// HOW IT'S BUILT

KEY FILES

.agents/skills/cloudflare-os-operator/SKILL.mdREADME.md

// REPO STATS

306 stars