Agent skill

Codflow Setup

by bighadj22 in bighadj22/codflow

Setup runbook for CodFlow — an AI agent following it authenticates with Cloudflare, creates the required resources (D1, R2, KV) in the developer's account, binds their real IDs into both…

Apache-2.0Auto-check: notesDevOps & Cloud

Install Codflow Setup

skills CLI
$ npx skills add bighadj22/codflow --skill codflow-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bighadj22/codflow codflow-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/codflow-setup .claude/skills/codflow-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codflow-setup
GitHub stars
343
Token cost
~7.8k tokens
SKILL.md length
3,048 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Setup runbook for CodFlow — an AI agent following it authenticates with Cloudflare, creates the required resources (D1, R2, KV) in the developer's account, binds their real IDs into both…

  • Works in 7 steps: Install Dependencies (one command) → Create Dedicated Cloudflare Resources → Bind Real IDs into BOTH wrangler.toml… → …
  • A developer wants to set up CodFlow (development
  • SKILL.md covers Before Starting — State This…, Prerequisites, Step 1 — Install Dependencies… and Step 2 — Create Dedicated…, plus 9 more sections
  • Calls npm, npx and wrangler; reaches github.com; needs STORE_API_KEY and BETTER_AUTH_SECRET

What it does

Codflow Setup is an agent skill from bighadj22/codflow. Setup runbook for CodFlow — an AI agent following it authenticates with Cloudflare, creates the required resources (D1, R2, KV) in the developer's account, binds their real IDs into both wrangler.toml files, configures secrets, applies migrations and seeds demo data against the remote D1 database, deploys the backend and dashboard to Cloudflare, and deploys the storefront to either Cloudflare Workers or Vercel based on developer choice. Use when a developer wants to set up CodFlow (development or production)…

Its SKILL.md is about 7.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Runbooks and postmortems and Static sites and blogs. It works with Cloudflare Workers, Cloudflare, Vercel and Astro. The repository describes itself as: The open-source, COD-first e-commerce + delivery platform for Algeria built agentic-ready. The licence is Apache-2.0.

When your agent uses it

  • A developer wants to set up CodFlow (development
  • Bind Cloudflare resources
  • Seed sample data
  • Create an admin user

Example prompts

  • “/codflow-setup”

Requirements

  • Node.js
  • A credential in R2_SECRET_ACCESS_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Install Dependencies (one command)
  2. Create Dedicated Cloudflare Resources
  3. Bind Real IDs into BOTH wrangler.toml Files
  4. Generate Keys & Configure Secrets
  5. Migrate & Seed the Cloudflare D1 Database
  6. Deploy in Dependency Order + Smoke Test
  7. Closing Summary (Mandatory)

What it can do on your machine

Read from SKILL.md and the folder at commit ed79aa9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx
    • wrangler
    • curl
    • node
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • sendili.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STORE_API_KEY
    • BETTER_AUTH_SECRET
    • R2_ACCESS_KEY_ID
    • R2_SECRET_ACCESS_KEY
    • MCP_LOGIN_TICKET_SECRET
    • CLOUDFLARE_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codflow Setup loads about 7.8k tokens when it runs. Until then it costs about 159 tokens; SKILL.md has 3,048 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~159
When it runs · the whole SKILL.md, loaded when a task matches
~7.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:151
    `COD_DB_NAME` from `<repo-root>/.env` via `cod-server/scripts/cloud-env.mjs`
  • NoteMentions a .env fileSKILL.md:152
    (precedence: `process.env` > `.env` > default). Set it there:
  • NoteMentions a .env fileSKILL.md:155
    cp .env.example .env      # at the repo root
  • NoteMentions a .env fileSKILL.md:186
    ploy` from `COD_SERVER_URL` in the root `.env`.
  • NoteMentions a .env fileSKILL.md:191
    cd cod-client-astro && cp .env.example .env
  • NoteMentions a .env fileSKILL.md:197
    s final `process.env` pass outranks the `.env` files:
  • NoteMentions a .env fileSKILL.md:200
    wrangler.toml [vars]  >  process.env  >  .env
  • NoteMentions a .env fileSKILL.md:203
    A value in `.env` is silently ignored. Set the production origin in
  • NoteMentions a .env fileSKILL.md:451
    l `[vars]`), and `COD_SERVER_URL` (root `.env` — the theme01

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bighadj22/codflow at commit ed79aa9, republished under its Apache-2.0 licence (© bighadj22). 3,048 words, ~7,779 tokens.

Download SKILL.mdSave it as .claude/skills/codflow-setup/SKILL.md (or your agent's skills folder).
name
codflow-setup
description
Setup runbook for CodFlow — an AI agent following it authenticates with Cloudflare, creates the required resources (D1, R2, KV) in the developer's account, binds their real IDs into both wrangler.toml files, configures secrets, applies migrations and seeds demo data against the remote D1 database, deploys the backend and dashboard to Cloudflare, and deploys the storefront to either Cloudflare Workers or Vercel based on developer choice. Use when a developer wants to set up CodFlow (development or production), bind Cloudflare resources, run migrations, seed sample data, create an admin user, or deploy the platform.

CodFlow Setup — Agent Runbook

CodFlow is a cash-on-delivery (COD) e-commerce platform built on Cloudflare Workers (backend API + dashboard), Astro 7, and D1 SQLite. The storefront (cod-astro/theme01) supports dual deployment targets: Cloudflare Workers or Vercel. This runbook takes a fresh clone to a fully working, verified deployment.

Every setup creates real Cloudflare resources in the developer's account, binds their real IDs into the wrangler.toml files, and migrates and seeds that same database. There is exactly one path — follow it in order and do not skip a gate.

The dashboard is cod-client-astro (Astro, prerendered static + auth worker). The storefront is cod-astro/theme01 (Astro).

Before Starting — State This Contract

State this to the developer before running anything:

*"This setup will create D1 <project>-db, R2 bucket <project>-images, and two KV namespaces in your Cloudflare account <account>, bind their real IDs into both wrangler.toml files, and migrate + seed the D1 database in your account. Nothing is left on placeholder values.

The backend API and dashboard run on Cloudflare Workers. For the customer storefront (cod-astro/theme01), you can deploy to:

  • Vercel (Recommended): Solves Cloudflare Error 1042 (Worker-to-Worker fetch block) when cod-server is on a free *.workers.dev subdomain, provides generous bandwidth and automatic preview deployments.
  • Cloudflare Workers: Keeps all services in one Cloudflare account (requires a custom domain or route for cod-server in production to avoid error 1042)."*

Both cod-server/wrangler.toml and cod-client-astro/wrangler.toml ship with all-zero placeholder resource IDs. After Step 3 of this runbook, no placeholder may remain anywhere in either file — deploys fail or silently break with placeholders.

Prerequisites

  • Node.js ≥ 22.12 and npm.
  • Cloudflare authentication:
    bash
    npx wrangler whoami    # if not logged in: npx wrangler login (browser OAuth)
  • R2 must be enabled on the account (requires a payment card on file, free tier): confirm dash.cloudflare.com → R2 shows enabled before creating buckets.
  • Ports 4321 / 8787 free if services will run locally:
    bash
    lsof -nP -iTCP:4321 -iTCP:8787 -sTCP:LISTEN   # expect no output
    Processes on these ports often belong to ANOTHER checkout's dev servers; identify via ps -p <pid> and confirm with the human before killing.

If whoami lists multiple accounts, ask the developer which one to use and record that account_id.

CRITICAL: Strip stale CLOUDFLARE_ACCOUNT_ID everywhere. If the shell exports CLOUDFLARE_ACCOUNT_ID for an account the OAuth token cannot access, every wrangler command fails with Authentication error [code: 10000] — including npm scripts (which invoke wrangler) and seeders. Shell rc files re-export this variable in every new shell. Prefix EVERY wrangler invocation with env -u CLOUDFLARE_ACCOUNT_ID so it targets the logged-in account, or unset CLOUDFLARE_ACCOUNT_ID once per session. Examples throughout this runbook show the prefix inline where practical.


Step 1 — Install Dependencies (one command)

CodFlow is an npm workspace monorepo: one root package.json, one root package-lock.json. Never create per-package lockfiles.

bash
npm ci        # at the repo root — installs all workspaces

Sanity check (optional): npm ls vite must show a single Vite major across all workspaces (the root overrides pin enforces it).

Step 2 — Create Dedicated Cloudflare Resources

Create fresh, dedicated resources for this CodFlow install. Default project name is codflow; use the developer's preferred prefix (<project>) otherwise.

bash
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler d1 create <project>-db                  # capture database_id
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler r2 bucket create <project>-images
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler kv namespace create RATE_LIMIT          # capture id
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler kv namespace create OAUTH_KV            # capture id (MCP OAuth)

Rules:

  • Always create new resources for this setup. Never bind to a resource that already exists in the account — it may belong to another application or store, and running migrations/seed against it would write into foreign data.
  • Unique names apply to WORKER names, not just resources. Default worker name fields in wrangler configs collide across clones, and deploying silently overwrites another installation. Require the developer to choose a unique prefix (e.g. mystore-server, mystore-dashboard, mystore-theme01) and update the name field in all three wrangler files before first deploy. This prevents cross-clone overwrite.
  • If a resource name is taken, do not reuse the existing resource: choose a fresh, unique name (e.g. append the store name or a short suffix) and create again.
  • Capture the D1 database_id (UUID) and both KV ids (32-hex) from command output. If parsing fails → hard stop, print the raw output, ask the developer. Never fall back to placeholder values.
  • Create two KV namespaces (rate limiting + MCP OAuth provider). Binding names differ per file: cod-server uses RATE_LIMIT + OAUTH_KV; cod-client-astro uses RATE_LIMIT_KV (its own namespace, only the id matters).

Step 3 — Bind Real IDs into BOTH wrangler.toml Files

bash
cp cod-server/wrangler.toml.example cod-server/wrangler.toml
cp cod-client-astro/wrangler.toml.example cod-client-astro/wrangler.toml

Files: cod-server/wrangler.toml and cod-client-astro/wrangler.toml.

  • [[d1_databases]]: set database_id (same database in both files).
  • [[kv_namespaces]]: set ids.
  • [[r2_buckets]]: confirm bucket_name matches the bucket created in Step 2.

Then read both files back and verify no placeholder remains anywhere, including [env.production] blocks:

bash
grep -rn "00000000-0000\|00000000000000000000000000000000" \
  cod-server/wrangler.toml cod-client-astro/wrangler.toml
# expected: no matches — fix any hit before continuing

Set the D1 database name once: the scripts are not hardcoded — the seeders, the migration wrapper (cod-server/scripts/d1.mjs) and the R2 setup all read COD_DB_NAME from <repo-root>/.env via cod-server/scripts/cloud-env.mjs (precedence: process.env > .env > default). Set it there:

bash
cp .env.example .env      # at the repo root
# COD_DB_NAME=<your database name>
# COD_SERVER_URL=https://<your api domain>  # required BEFORE theme01 deploy —
#   npm run deploy refuses a localhost value (the default) without --force-local

The database_name / database_id in each wrangler.toml still has to match the database you created — those are wrangler's own config, not script input. Confirm no script or config still pins the sample name:

bash
grep -r "codflow-os-db" --exclude-dir=node_modules --exclude-dir=.git
# expected: only .env.example defaults and documentation, zero script hits

Confirm the filled wrangler.toml files are not tracked by git:

bash
git status cod-server/wrangler.toml cod-client-astro/wrangler.toml
# expected: nothing listed (both ignored)

If either file appears in git status, stop — the .gitignore is not applied correctly. Do not continue until both are untracked.

While editing, also replace the example domains in [vars] / [env.production.vars] (WORKER_URL, BETTER_AUTH_URL, WORKER_SELF_URL, PUBLIC_APP_URL, PUBLIC_API_URL, PUBLIC_TRUSTED_ORIGINS) with the developer's real URLs when they are known; localhost defaults are correct for local runs. The storefront's COD_SERVER_URL is NOT set in cod-astro/theme01/wrangler.jsonc — it is injected at deploy time by npm run deploy from COD_SERVER_URL in the root .env.

Also create the dashboard's build-time client env:

bash
cd cod-client-astro && cp .env.example .env

Leave PUBLIC_API_URL out of that file. It is inlined into the browser bundle by astro:env/client, but the Cloudflare adapter pushes wrangler values and .dev.vars into process.env, and Astro loads env with an empty prefix, so Vite's final process.env pass outranks the .env files:

.dev.vars  >  wrangler.toml [vars]  >  process.env  >  .env

A value in .env is silently ignored. Set the production origin in cod-client-astro/wrangler.toml [vars], and the local one in .dev.vars (PUBLIC_API_URL=http://localhost:8787).

Step 3b — Configure R2 for Image Uploads

This step requires values only the developer can retrieve from the Cloudflare dashboard. The agent must ask for them — do not guess or skip.

Agent instructions

Ask the developer for these four things before proceeding:

  1. The media subdomain they want to use for serving images (e.g. media.yourdomain.com). They must add this as a custom domain on the R2 bucket first:

    Cloudflare dashboard → R2 → <project>-images → Settings → Custom Domains → Connect Domain → enter the subdomain → wait for Active.

  2. Their Cloudflare Account ID (Cloudflare dashboard → top-right account menu, or any Workers page sidebar).

  3. An R2 API token created specifically for this bucket:

    Cloudflare dashboard → R2 → Manage R2 API Tokens → Create API Token → Permissions: Object Read & Write → Bucket: <project>-images → Create.

    This shows two values once — copy both:

    • Access Key ID
    • Secret Access Key

Once the developer provides all four values, continue with the steps below.


1. Give the developer the CORS JSON to paste

Tell the developer to set the CORS policy on the bucket manually:

Cloudflare dashboard → R2 → <project>-images → Settings → CORS Policy → Add CORS policy → paste this JSON (replacing the dashboard domain):

json
[
  {
    "AllowedOrigins": [
      "https://<dashboard-domain>",
      "http://localhost:4321"
    ],
    "AllowedMethods": ["PUT", "GET", "HEAD"],
    "AllowedHeaders": ["Content-Type", "Content-Length"],
    "ExposeHeaders": ["ETag"],
    "MaxAgeSeconds": 3600
  }
]

Wait for the developer to confirm it is saved before continuing.

2. Set MEDIA_DOMAIN in wrangler.toml

Update MEDIA_DOMAIN in cod-server/wrangler.toml [vars] and [env.production] to the media subdomain the developer provided. No scheme — hostname only:

toml
MEDIA_DOMAIN = "media.yourdomain.com"
3. Set R2 secrets on the cod-server worker

After cod-server is deployed (Step 6), set the three secrets using the values the developer provided. Use stdin redirect — never echo secrets into the shell:

bash
printf '<CF_ACCOUNT_ID>' | env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put CF_ACCOUNT_ID --name <server-worker-name>
printf '<R2_ACCESS_KEY_ID>' | env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put R2_ACCESS_KEY_ID --name <server-worker-name>
printf '<R2_SECRET_ACCESS_KEY>' | env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put R2_SECRET_ACCESS_KEY --name <server-worker-name>

Also add them to cod-server/.dev.vars for local dev:

CF_ACCOUNT_ID=<value>
R2_ACCESS_KEY_ID=<value>
R2_SECRET_ACCESS_KEY=<value>
MEDIA_DOMAIN=media.yourdomain.com
4. Set MEDIA_DOMAIN on the storefront and redeploy

After theme01 is deployed (Step 6):

  • If storefront is on Cloudflare Workers:
    bash
    printf 'media.yourdomain.com' | env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put MEDIA_DOMAIN --name <theme01-worker-name>
    cd cod-astro/theme01 && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy
  • If storefront is on Vercel:
    bash
    cd cod-astro/theme01 && printf "media.yourdomain.com" | npx vercel env add MEDIA_DOMAIN production
    npx vercel --prod
5. Redeploy cod-server with updated MEDIA_DOMAIN
bash
cd cod-server && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy
Verify
bash
# presignedUrl must appear and publicUrl must start with https://media.yourdomain.com/
curl -s -X POST https://<api-domain>/api/images/presign \
  -H "Content-Type: application/json" \
  -H "X-API-Key: <admin-api-key>" \
  -d '{"contentType":"image/jpeg"}'

If publicUrl starts with the Worker URL instead of the media domain, MEDIA_DOMAIN is not set or the worker was not redeployed after setting it.


Step 4 — Generate Keys & Configure Secrets

Generate the keys once and keep them:

bash
node -e "console.log(require('crypto').randomBytes(32).toString('base64'))"   # BETTER_AUTH_SECRET
node -e "console.log(require('crypto').randomBytes(24).toString('base64url'))" # STORE_API_KEY
node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"       # MCP_LOGIN_TICKET_SECRET

Deploy workers BEFORE setting secrets: In non-interactive sessions, wrangler secret put against a nonexistent worker fails or hangs on the create prompt. Either deploy each worker first (Step 6), or wait until after deploy to set secrets. When setting secrets, provide values via stdin redirect from a chmod-600 temp file — never use echo or heredocs, which leak secrets into shell history and process lists:

bash
# After cod-server is deployed:
cd cod-server
echo "<BETTER_AUTH_SECRET_value>" > /tmp/secret.txt && chmod 600 /tmp/secret.txt
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put BETTER_AUTH_SECRET < /tmp/secret.txt
echo "<MCP_LOGIN_TICKET_SECRET_value>" > /tmp/secret.txt
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put MCP_LOGIN_TICKET_SECRET < /tmp/secret.txt
rm /tmp/secret.txt

# After cod-client-astro is deployed — SAME two values (must match cod-server):
cd ../cod-client-astro
echo "<BETTER_AUTH_SECRET_value>" > /tmp/secret.txt && chmod 600 /tmp/secret.txt
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put BETTER_AUTH_SECRET < /tmp/secret.txt
echo "<MCP_LOGIN_TICKET_SECRET_value>" > /tmp/secret.txt
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put MCP_LOGIN_TICKET_SECRET < /tmp/secret.txt
rm /tmp/secret.txt

# theme01: STORE_API_KEY (same string the seeder will hash in Step 5)
# If deploying storefront to Cloudflare Workers:
#   echo "<STORE_API_KEY_value>" > /tmp/secret.txt && chmod 600 /tmp/secret.txt
#   env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put STORE_API_KEY < /tmp/secret.txt --name <theme01-worker-name>
#   rm /tmp/secret.txt
# If deploying storefront to Vercel:
#   cd cod-astro/theme01 && printf "<STORE_API_KEY_value>" | npx vercel env add STORE_API_KEY production

For services that will also run locally, create .dev.vars from each package's .dev.vars.example with the same key values (.dev.vars is gitignored).

Keep STORE_API_KEY at hand: Step 5 seeds its hash into the database, so the storefront secret and the seeded hash must come from the identical string.

Step 5 — Migrate & Seed the Cloudflare D1 Database

Remote migrations are mandatory. All schema and demo data go against the D1 created in Step 2 (remote), not an emulated copy. Both local and remote migrations must run:

bash
cd cod-server
env -u CLOUDFLARE_ACCOUNT_ID npm run db:migrate:local   # REQUIRED first: seed-admin writes local + remote
env -u CLOUDFLARE_ACCOUNT_ID npm run db:migrate:remote  # MANDATORY: deployed sign-in 500s without this
env -u CLOUDFLARE_ACCOUNT_ID STORE_API_KEY=<generated-store-key> npm run db:seed:remote   # demo store متجر التطوير + catalog

cd ../cod-client-astro
ADMIN_EMAIL=admin@example.com ADMIN_NAME=Admin npm run seed:admin:remote

Notes:

  • db:migrate:local must run before seed-admin: the script seeds the emulated local D1 first and needs its schema to exist.
  • db:migrate:remote is MANDATORY before any deployed sign-in attempt — without it, Better Auth 1.7 schema requirements fail (field "alg" does not exist in "jwkss"), producing 500 errors.
  • The seeder writes better-auth ≥ 1.7 credential rows (issuer = 'local:credential', account_id = user id) — re-run it after any password reset request for the seeded admin.
  • Verify the seeder reports all statements executed and note the admin email/password and API key output — they appear once.

Step 6 — Deploy in Dependency Order + Smoke Test

Deploy the services in order: Backend API first, then Dashboard, then Storefront.

6.1 Deploy Backend & Dashboard (Cloudflare Workers)
bash
cd cod-server          && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy
cd ../cod-client-astro && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy     # wrangler deploy (builds first: npm run build)
6.2 Deploy Storefront (cod-astro/theme01)

Deploy the storefront to either Cloudflare Workers OR Vercel based on developer preference:

Option A: Deploy Storefront to Cloudflare Workers
bash
cd cod-astro/theme01 && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy     # astro build && wrangler deploy

[!NOTE] workers.dev limitation (Error 1042): Cloudflare blocks Worker→Worker fetch() between two *.workers.dev hosts. If cod-server is deployed on *.workers.dev, a storefront on *.workers.dev cannot load products from it. For a Cloudflare-hosted storefront in production, put cod-server on a custom domain/route and update COD_SERVER_URL.

Deploying the storefront to Vercel bypasses Cloudflare Error 1042 completely and takes advantage of Vercel's global Edge network and instant preview branches. See the dedicated storefront-vercel skill for full details.

Using Vercel CLI:

bash
cd cod-astro/theme01
npx vercel link                                     # link or create project
printf "vercel" | npx vercel env add DEPLOY_TARGET production
printf "https://<your-cod-server-url>" | npx vercel env add COD_SERVER_URL production
printf "<your-raw-store-api-key>" | npx vercel env add STORE_API_KEY production
# If MEDIA_DOMAIN was configured:
printf "<media.yourdomain.com>" | npx vercel env add MEDIA_DOMAIN production

npx vercel --prod                                   # builds with npm run build:vercel and deploys

After deploy, replace localhost URL vars with real deployed URLs and redeploy: Once workers are live, set PUBLIC_APP_URL / PUBLIC_API_URL / PUBLIC_TRUSTED_ORIGINS (cod-client-astro wrangler.toml [vars]), WORKER_URL, WORKER_SELF_URL, BETTER_AUTH_URL (cod-server wrangler.toml [vars]), and COD_SERVER_URL (root .env — the theme01 deploy script reads it) to the actual deployed URLs, then redeploy affected workers. PUBLIC_API_URL is baked into the client bundle at build time, so the dashboard must be rebuilt after changing it; npm run deploy does that and aborts if the built bundle still points at a loopback address. Skipping this causes browser sign-in failures (R6/R7).

Smoke-test after each deploy; do not continue past a failing check:

ComponentCheckExpectation
cod-servercurl -s -o /dev/null -w "%{http_code}" https://<workers-url>/api/docs200
dashboard sign-in APIcurl -s -X POST https://<dashboard-url>/api/auth/sign-in/email -H "Content-Type: application/json" -H "Origin: https://<dashboard-url>" -d '{"email":"<admin>","password":"<pass>"}'200 + user JSON (401 = credentials/schema issue, 500 = config, 403 INVALID_ORIGIN = R6 not applied)
dashboard UIopen the dashboard URLlogin page loads
storefront (CF or Vercel)open the storefront URLhomepage renders

CRITICAL — Origin header in sign-in tests: Plain curl omits the Origin header; Better Auth skips its origin check and returns 200, while every real browser request gets 403 INVALID_ORIGIN (which the UI masks as "Invalid email or password"). The canonical sign-in check MUST send -H "Origin: https://<dashboard-url>" and expect 200 + user JSON. If browser login fails but curl without Origin passes, the dashboard origin is missing from PUBLIC_TRUSTED_ORIGINS — apply R6, redeploy, and retest with the Origin header.

Diagnose unclear failures with wrangler tail: Run env -u CLOUDFLARE_ACCOUNT_ID npx wrangler tail <worker-name> --format pretty in the background, have the human retry the failing operation, then read the log — the true error surfaces there, not in UI text.

workers.dev limitation (error 1042): Cloudflare blocks Worker→Worker fetch() between two *.workers.dev hosts. A storefront deployed to workers.dev cannot load products from a cod-server also on workers.dev. For a production storefront, put cod-server on a custom domain/route and point COD_SERVER_URL at it (or wire a Service Binding), then re-deploy theme01 and confirm /products shows the seeded catalog. Local development is unaffected.

Show full SKILL.md (1,079 more words)Show less

Step 6b — Optional: Transactional Email (Sendili)

Offer this to the developer after the smoke tests pass; skip entirely if they decline — the feature is inert by default (no store_email_config row).

  1. Ask the developer to: create a sendili.com account, buy credits, verify their sending domain (DNS records in the Sendili dashboard), and create an API key (sk_live_…).
  2. In the deployed dashboard: sign in as admin → Settings → Email Sending → paste the key (domains auto-load) → set the from address by typing the local part (support, notify…) and picking the verified domain → toggle Enable email sending → Save.
  3. Verify: Test connection shows Connection OK with the domain listed; then invite a team member with an email the developer can check and confirm the invite email arrives (sign-in link + temporary password), and that the invited member can sign in.
  4. Docs: docs/EMAIL-SENDING.md (feature guide) and docs/adr/0001-sendili-key-at-rest.md (key storage decision).

No wrangler secrets, no worker config — the key lives in D1 (store_email_config, applied by migration 0013 in Step 5) and is masked in every API response.

Step 7 — Closing Summary (Mandatory)

Print a resource inventory:

Tell the developer how to get future updates: "When CodFlow publishes an update, just ask your AI agent to 'update CodFlow' — it will follow the codflow-update runbook (shipped in this repo), which pulls the latest code from https://github.com/bighadj22/codflow main, merges it into this install without re-running setup, keeps your resources, secrets, and data intact, and redeploys. You never repeat this runbook from scratch."

ResourceNameIDBound inVerified by
D1<project>-db<uuid>cod-server/wrangler.toml, cod-client-astro/wrangler.tomld1 create output + Step 3 grep
R2<project>-imagesn/a (name-bound)cod-server/wrangler.tomlr2 bucket create confirmation
KV (rate limit)rate-limit namespace<32-hex>cod-server + cod-client-astro wrangler.tomlkv namespace create output
KV (MCP OAuth)oauth namespace<32-hex>cod-server/wrangler.tomlkv namespace create output
Storefront TargetCloudflare / Verceln/acod-astro/theme01Deployed URL smoke test

Credentials file delivery (mandatory): Write credentials to a chmod-600 markdown file OUTSIDE git-tracked directories (e.g. ~/codflow-credentials.md or /tmp/codflow-setup-<timestamp>.md). Place every value inside a fenced code block so humans can copy-paste them without trailing-space login failures. Extract values programmatically from .dev.vars or source files; never retype from memory. Delete temporary secret files afterward. Show credentials in chat output at most once.

Example credentials file structure:

markdown
# CodFlow Setup Credentials — <project-name>

## Admin User
- **Email:** `admin@example.com`
- **Password:**
  <actual-password>
  ```

API Keys

  • BETTER_AUTH_SECRET:
    <base64-value>
  • MCP_LOGIN_TICKET_SECRET:
    <hex-value>
  • STORE_API_KEY:
    <base64url-value>

Deployed URLs

  • Dashboard: https://<dashboard-url>
  • API Server: https://<cod-server-url>
  • Storefront: https://<theme01-url> (Cloudflare Workers or Vercel)

Security: This file contains sensitive credentials. Store it securely and delete after transferring values to a password manager.


---

## Running the Stack Locally During Development

The `npm run dev` scripts execute Workers on the local machine with
Miniflare-emulated storage persisted to `<repo-root>/.wrangler-shared` — they
do not read the deployed D1. To boot all three services locally:

```bash
cd cod-server && npm run db:migrate:local && STORE_API_KEY=<key> npm run db:seed:local
cd ../cod-client-astro && ADMIN_EMAIL=… ADMIN_NAME=Admin npm run seed:admin

Then start one terminal per service:

PackageDirectoryCommandURL
API Servercod-servernpm run devhttp://localhost:8787 (docs at /api/docs)
Dashboardcod-client-astronpm run devhttp://localhost:4321
Storefrontcod-astro/theme01npm run devhttp://localhost:4321 — run astro dev --port 4322 when the dashboard is up

Localhost→localhost is unaffected by the workers.dev limitation: the storefront renders the full seeded catalog locally.

The storefront directory is cod-astro/theme01 — bare cod-astro/ has no scripts.


Troubleshooting

ProblemCauseSolution
Deploy fails with placeholder-looking binding errorsResource IDs were never replaced in wrangler.tomlRe-run the Step 3 verification greps; bind real IDs.
grep finds placeholders inside [env.production] blocksProduction block edited incompletelyReplace every all-zero database_id / KV id occurrence in the file.
theme01 dev dies: Missing field 'moduleType'Dual Vite majorsRoot package.json overrides pin vite to ^8.2.2 (root-only — npm ignores child overrides). rm -rf node_modules && npm ci; npm ls vite must show one major.
Storefront deployed on Cloudflare but products emptyWorker→Worker fetch between two *.workers.dev hosts blocked (CF error 1042)Put cod-server on a custom domain/route, set COD_SERVER_URL, redeploy theme01. Or deploy storefront to Vercel instead.
Storefront on Vercel shows empty products / network errorCOD_SERVER_URL missing or protocol omittedEnsure COD_SERVER_URL in Vercel project env starts with https:// and points to the live cod-server worker.
Storefront on Vercel order creation fails with 401STORE_API_KEY mismatchEnsure STORE_API_KEY on Vercel matches the identical raw key seeded into D1 during Step 5.
Storefront on Vercel fails build: missing adapterDEPLOY_TARGET=vercel not setSet DEPLOY_TARGET=vercel in Vercel env or build command npm run build:vercel.
Sign-in returns 500 Secondary-storage rate limiting requires SecondaryStorage.incrementauth server swapped back to withCloudflare({ kv }) shortcutKeep the full custom secondaryStorage in cod-client-astro/src/lib/auth/server.ts; better-auth-cloudflare@0.3.1 lacks increment.
Sign-in returns 401 with correct credentialsAdmin row predates better-auth 1.7 semantics (missing issuer, account_id = email)Apply migration 0010, re-run npm run seed:admin:remote.
get-session 500: field "alg" does not exist in "jwkss"Migration 0011 missing on that databaseRun npm run db:migrate:remote (or :local).
Sign-in works but every API call returns 401BETTER_AUTH_SECRET differs between cod-server and cod-client-astro — the dashboard-issued JWT fails cod-server's JWKS verificationSet the identical secret on both workers.
theme01 boots then wedges/crashes at first render: optimized dependencies changed. reloadingLate SSR dep discovery races the workerd reload (astro#16933)Keep vite.environments.ssr.optimizeDeps (noDiscovery: true + excludes) in astro.config.mjs.
Address already in use :8787Another checkout's wrangler holds the port (see Prerequisites port preflight)Identify via ps -p <pid>, confirm with human, then kill that process tree.
Another astro dev server is already runningAstro 7 dev lockfile left behindnpx astro dev stop (or kill the stale process).
Astro behaves unexpectedly under an agent (backgrounded, JSON output)Astro auto-enables background+JSON mode when AGENT, CLAUDE_CODE_*, or OPENCODE env vars are presentHumans get foreground behavior; agents should use npx astro dev status / logs / stop.
wrangler login fails in headless/SSHNo GUI browser availableRun npx wrangler login on a local machine, or configure CLOUDFLARE_API_TOKEN in the environment.
wrangler r2 bucket create failsR2 subscription not enabled on Cloudflare accountNavigate to dash.cloudflare.com → R2, add a payment card to activate the Free Tier, then retry.
Local D1 split-brain / missing tablesWrangler ran without --persist-toAlways run local migrations and commands with --persist-to ../.wrangler-shared. cod-client-astro's astro dev reads the same path via the adapter's persistState.
Better Auth 500 on sign-inBETTER_AUTH_SECRET missingEnsure BETTER_AUTH_SECRET is set in cod-client-astro/.dev.vars (local) or via wrangler secret put (production).
Image uploads fail in browserR2 CORS not configured for PUT requestsCloudflare dashboard → R2 → bucket → Settings → CORS Policy. Add the JSON from Step 3b with your dashboard domain in AllowedOrigins.
Presign returns 500 with missing credentials errorCF_ACCOUNT_ID, R2_ACCESS_KEY_ID, or R2_SECRET_ACCESS_KEY not set on the WorkerRun wrangler secret put for all three on the cod-server worker, then redeploy.
publicUrl points to Worker URL instead of media domainMEDIA_DOMAIN not set in wrangler.toml or worker not redeployed after setting itSet MEDIA_DOMAIN in [vars] and redeploy cod-server. For theme01 image resizing, also set MEDIA_DOMAIN as a secret on the storefront worker (or Vercel env) and redeploy.

© bighadj22, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/codflow-setup of bighadj22/codflow.

Open the folder on GitHubat commit ed79aa9

Compare with similar skills

Codflow Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codflow Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codflow Setup this skillbighadj22/codflow343—~7.8kAutomated safety check: NotesApache-2.0
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
Observability Triageevery-app/open-seo23k—~1.7kAutomated safety check: PassMIT
Devops SpecialistCaoMeiYouRen/caomei-auth220—~446Automated safety check: NotesMIT
Frontmcp Deploymentagentfront/frontmcp146—~9.2kAutomated safety check: NotesApache-2.0
Cloudflare Pagessickn33/agentic-awesome-skills47k2 repos~2.4kAutomated safety check: PassMIT

Similar skills

  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Observability Triage

    every-app/open-seo

    Triage OpenSEO production errors in Cloudflare Workers Observability — verified query recipes, counting gotchas, and a known-noise filter list applied automatically.

    23k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Devops Specialist

    CaoMeiYouRen/caomei-auth

    修改 Docker、CI/CD、部署配置、环境变量、运行时参数、构建脚本和发布流程时使用。优先覆盖 Docker、Vercel、Cloudflare 与 GitHub Actions 场景。用户提到 deploy、Dockerfile、workflow、CI、CD、environment variables、build pipeline、release config 时都应触发。

    220 GitHub stars~446 tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Frontmcp Deployment

    agentfront/frontmcp

    A skill your agent uses when deploying, building for production, packaging, or shipping a FrontMCP server.

    146 GitHub stars~9.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Cloudflare Pages

    sickn33/agentic-awesome-skills

    Deploy static sites and full-stack apps on Cloudflare Pages with previews, functions, and custom domains.

    47k GitHub starsUsed in 2 repos~2.4k tokens
    DevOps & CloudAuto-check passed
  • Ecosystem Usage

    evloghq/evlog

    Measure agent-facing traffic to the evlog docs site (MCP transport, raw Markdown, discovery paths) with Vercel Observability, and read it without inflating it.

    1.9k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from bighadj22/codflow

All 11 skills in this repo
  • Wires an app to the Yalidine (Guepex) Algerian courier API: parcels, zone lookups, delivery fees and verified delivery-status webhooks.

    343 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bundles Meta's official Pixel and Conversions API documentation so tracking changes, event deduplication and conversion events are checked against the real spec.

    343 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • CodFlow Change Workflow

    bighadj22/codflow

    A step-by-step workflow for changing the CodFlow repository: read the AGENTS.md contract, respect package boundaries, verify before claiming done and keep PRs small.

    343 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Guides an agent through eight customer tools in a cash-on-delivery CRM for Algerian e-commerce: search, profiles, phone lookup, order history, groups, tags and deletion.

    343 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Guides connecting and maintaining the EcoTrack courier adapter in CodFlow, one API shared by 82 Algerian couriers, using the official API reference and a rollout plan.

    343 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • defineRoute Route Builder

    bighadj22/codflow

    Creates new API endpoints, and converts older ones, with the defineRoute() pattern used in cod-server, including auth strategies, scopes and OpenAPI output.

    343 GitHub stars~924 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Codflow Setup

What does Codflow Setup do?

Setup runbook for CodFlow — an AI agent following it authenticates with Cloudflare, creates the required resources (D1, R2, KV) in the developer's account, binds their real IDs into both…. Codflow Setup is an agent skill from bighadj22/codflow.toml files, configures secrets, applies migrations and seeds demo data against the remote D1 database, deploys the backend and dashboard to Cloudflare, and deploys the storefront to either Cloudflare Workers or Vercel based on developer choice.

When should I use Codflow Setup?

Codflow Setup fits situations like: A developer wants to set up CodFlow (development; bind Cloudflare resources; seed sample data; create an admin user.

How do I install Codflow Setup in Claude Code?

Run `npx skills add bighadj22/codflow --skill codflow-setup -a claude-code`. Or copy the skill folder (.agents/skills/codflow-setup in bighadj22/codflow) into .claude/skills/codflow-setup in your project. Claude Code loads it when a task matches its description.

How do I install Codflow Setup in Codex?

Run `npx skills add bighadj22/codflow --skill codflow-setup -a codex`. Or copy the skill folder (.agents/skills/codflow-setup in bighadj22/codflow) into .agents/skills/codflow-setup in your project. Codex loads it when a task matches its description.

Can I use Codflow Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bighadj22/codflow --skill codflow-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codflow-setup, .gemini/skills/codflow-setup, .github/skills/codflow-setup and .opencode/skills/codflow-setup in your project.

What does Codflow Setup need to run?

Going by SKILL.md and its folder, Codflow Setup needs the command-line tools its instructions call (npm, npx, wrangler, curl, node and git) and credentials named STORE_API_KEY, BETTER_AUTH_SECRET, R2_ACCESS_KEY_ID and R2_SECRET_ACCESS_KEY. Our summary lists: Node.js; A credential in R2_SECRET_ACCESS_KEY.

Does Codflow Setup access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: sendili.com. This is read from the text; nothing was executed.

Is Codflow Setup safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Codflow Setup use?

Codflow Setup is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codflow Setup use?

About 7.8k tokens (SKILL.md is roughly 31k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codflow Setup?

Skills that share tags, products or a category with Codflow Setup: Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), Observability Triage (every-app/open-seo, 23k stars), Devops Specialist (CaoMeiYouRen/caomei-auth, 220 stars) and Frontmcp Deployment (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codflow Setup?

bighadj22 (a GitHub user) maintains it in bighadj22/codflow, which has 343 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 6, 2026.

Source: bighadj22/codflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.