# Cloudflare Deploy

> Build, configure, and deploy applications and platform resources on Cloudflare. Use when the user wants help with Workers, Pages, Wrangler, storage, AI, networking, security, or related Cloudflare services.

- Skill: `1999azzar/cloudflare-deploy` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add 1999azzar/cloudflare-deploy`
- Raw SKILL.md: https://api.skillmd.com/api/skills/1999azzar/cloudflare-deploy/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: 1999AZZAR (https://skillmd.com/u/1999azzar)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/1999azzar/cloudflare-deploy

---


# Cloudflare Deploy

Use this skill to choose the correct Cloudflare product, inspect the project or infrastructure shape, and then load only the relevant reference folder before making changes or deploying.

## Prerequisites

- The current environment can run terminal commands when needed.
- The user has access to the relevant Cloudflare account.
- The required Cloudflare toolchain is available for the selected workflow, usually `wrangler` via `npx wrangler`.

If authentication or CLI setup is not ready, read [references/setup.md](references/setup.md) before continuing.

## Required Workflow

Follow these steps in order:

### Step 1: Identify the Cloudflare product first

Do not jump straight to deployment commands. First decide which product matches the request:
- `workers` for edge code execution
- `pages` for web app hosting
- `durable-objects`, `kv`, `d1`, `r2`, `queues`, or `vectorize` for data and state
- `workers-ai`, `agents-sdk`, `ai-gateway`, or `ai-search` for AI features
- `waf`, `turnstile`, `api-shield`, or `bot-management` for security
- `tunnel`, `spectrum`, `turn`, `argo-smart-routing`, or related networking tools for connectivity

Use the decision trees below for quick routing, then load only the needed reference directory instead of scanning the entire `references/` tree.

### Step 2: Inspect the local project or target infrastructure

Before changing anything, inspect the relevant files and deployment shape:
- For application deploys: check `package.json`, `wrangler.jsonc`, `wrangler.toml`, `netlify.toml` alternatives if migrating, build scripts, lockfiles, and framework config.
- For Pages: determine the build command and output directory.
- For Workers: determine the entrypoint, bindings, compatibility date, routes, and environments.
- For infrastructure or security tasks: confirm the target account, zone, resource identifiers, and environment.

### Step 3: Verify authentication and tool readiness

Verify auth before `wrangler deploy`, `wrangler pages deploy`, or other Cloudflare CLI operations:

```bash
npx wrangler whoami    # Shows account if authenticated
```

If authentication is missing, stop and use [references/setup.md](references/setup.md). Do not guess credentials, account IDs, or zone IDs.

### Step 4: Load only the matching reference set

After selecting the product, read the relevant reference folder:
- Start with that folder's `README.md`
- Then load `configuration.md`, `api.md`, `patterns.md`, or `gotchas.md` only if needed
- Avoid loading unrelated product references

## Quick Decision Trees

### "I need to run code"

```
Need to run code?
├─ Serverless functions at the edge → workers/
├─ Full-stack web app with Git deploys → pages/
├─ Stateful coordination/real-time → durable-objects/
├─ Long-running multi-step jobs → workflows/
├─ Run containers → containers/
├─ Multi-tenant (customers deploy code) → workers-for-platforms/
├─ Scheduled tasks (cron) → cron-triggers/
├─ Lightweight edge logic (modify HTTP) → snippets/
├─ Process Worker execution events (logs/observability) → tail-workers/
└─ Optimize latency to backend infrastructure → smart-placement/
```

### "I need to store data"

```
Need storage?
├─ Key-value (config, sessions, cache) → kv/
├─ Relational SQL → d1/ (SQLite) or hyperdrive/ (existing Postgres/MySQL)
├─ Object/file storage (S3-compatible) → r2/
├─ Message queue (async processing) → queues/
├─ Vector embeddings (AI/semantic search) → vectorize/
├─ Strongly-consistent per-entity state → durable-objects/ (DO storage)
├─ Secrets management → secrets-store/
├─ Streaming ETL to R2 → pipelines/
└─ Persistent cache (long-term retention) → cache-reserve/
```

### "I need AI/ML"

```
Need AI?
├─ Run inference (LLMs, embeddings, images) → workers-ai/
├─ Vector database for RAG/search → vectorize/
├─ Build stateful AI agents → agents-sdk/
├─ Gateway for any AI provider (caching, routing) → ai-gateway/
└─ AI-powered search widget → ai-search/
```

### "I need networking/connectivity"

```
Need networking?
├─ Expose local service to internet → tunnel/
├─ TCP/UDP proxy (non-HTTP) → spectrum/
├─ WebRTC TURN server → turn/
├─ Private network connectivity → network-interconnect/
├─ Optimize routing → argo-smart-routing/
├─ Optimize latency to backend (not user) → smart-placement/
└─ Real-time video/audio → realtimekit/ or realtime-sfu/
```

### "I need security"

```
Need security?
├─ Web Application Firewall → waf/
├─ DDoS protection → ddos/
├─ Bot detection/management → bot-management/
├─ API protection → api-shield/
├─ CAPTCHA alternative → turnstile/
└─ Credential leak detection → waf/ (managed ruleset)
```

### "I need media/content"

```
Need media?
├─ Image optimization/transformation → images/
├─ Video streaming/encoding → stream/
├─ Browser automation/screenshots → browser-rendering/
└─ Third-party script management → zaraz/
```

### "I need infrastructure-as-code"

```
Need IaC? → pulumi/ (Pulumi), terraform/ (Terraform), or api/ (REST API)
```

## Product Index

### Compute & Runtime
| Product | Reference |
|---------|-----------|
| Workers | `references/workers/` |
| Pages | `references/pages/` |
| Pages Functions | `references/pages-functions/` |
| Durable Objects | `references/durable-objects/` |
| Workflows | `references/workflows/` |
| Containers | `references/containers/` |
| Workers for Platforms | `references/workers-for-platforms/` |
| Cron Triggers | `references/cron-triggers/` |
| Tail Workers | `references/tail-workers/` |
| Snippets | `references/snippets/` |
| Smart Placement | `references/smart-placement/` |

### Storage & Data
| Product | Reference |
|---------|-----------|
| KV | `references/kv/` |
| D1 | `references/d1/` |
| R2 | `references/r2/` |
| Queues | `references/queues/` |
| Hyperdrive | `references/hyperdrive/` |
| DO Storage | `references/do-storage/` |
| Secrets Store | `references/secrets-store/` |
| Pipelines | `references/pipelines/` |
| R2 Data Catalog | `references/r2-data-catalog/` |
| R2 SQL | `references/r2-sql/` |

### AI & Machine Learning
| Product | Reference |
|---------|-----------|
| Workers AI | `references/workers-ai/` |
| Vectorize | `references/vectorize/` |
| Agents SDK | `references/agents-sdk/` |
| AI Gateway | `references/ai-gateway/` |
| AI Search | `references/ai-search/` |

### Networking & Connectivity
| Product | Reference |
|---------|-----------|
| Tunnel | `references/tunnel/` |
| Spectrum | `references/spectrum/` |
| TURN | `references/turn/` |
| Network Interconnect | `references/network-interconnect/` |
| Argo Smart Routing | `references/argo-smart-routing/` |
| Workers VPC | `references/workers-vpc/` |

### Security
| Product | Reference |
|---------|-----------|
| WAF | `references/waf/` |
| DDoS Protection | `references/ddos/` |
| Bot Management | `references/bot-management/` |
| API Shield | `references/api-shield/` |
| Turnstile | `references/turnstile/` |

### Media & Content
| Product | Reference |
|---------|-----------|
| Images | `references/images/` |
| Stream | `references/stream/` |
| Browser Rendering | `references/browser-rendering/` |
| Zaraz | `references/zaraz/` |

### Real-Time Communication
| Product | Reference |
|---------|-----------|
| RealtimeKit | `references/realtimekit/` |
| Realtime SFU | `references/realtime-sfu/` |

### Developer Tools
| Product | Reference |
|---------|-----------|
| Wrangler | `references/wrangler/` |
| Miniflare | `references/miniflare/` |
| C3 | `references/c3/` |
| Observability | `references/observability/` |
| Analytics Engine | `references/analytics-engine/` |
| Web Analytics | `references/web-analytics/` |
| Sandbox | `references/sandbox/` |
| Workerd | `references/workerd/` |
| Workers Playground | `references/workers-playground/` |

### Infrastructure as Code
| Product | Reference |
|---------|-----------|
| Pulumi | `references/pulumi/` |
| Terraform | `references/terraform/` |
| API | `references/api/` |

### Other Services
| Product | Reference |
|---------|-----------|
| Email Routing | `references/email-routing/` |
| Email Workers | `references/email-workers/` |
| Static Assets | `references/static-assets/` |
| Bindings | `references/bindings/` |
| Cache Reserve | `references/cache-reserve/` |

## Troubleshooting

### Network Access

If Cloudflare CLI operations fail due to DNS or outbound network restrictions, rerun them with the host's elevated or unrestricted network mode when available.

### Authentication Problems

Use [references/setup.md](references/setup.md) and `references/wrangler/auth.md` when:
- `npx wrangler whoami` fails
- the account is wrong
- token-based auth is needed for CI or headless environments

### Scope Problems

If the request is broad, narrow it before acting:
- which Cloudflare product
- which account or zone
- which environment
- whether the task is read-only, configuration, migration, or deployment

