Prepare Cloudflare Production Deployment
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored…
$ npx skills add bighadj22/codflow --skill codflow-update -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install bighadj22/codflow codflow-update --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/codflow-update .claude/skills/codflow-update && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codflow-update" agent skill from https://github.com/bighadj22/codflow/tree/main/.agents/skills/codflow-update into .claude/skills/codflow-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codflow-update", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/bighadj22/codflow/tree/main/.agents/skills/codflow-updateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add bighadj22/codflow --skill codflow-update -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install bighadj22/codflow codflow-update --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/codflow-update .agents/skills/codflow-update && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codflow-update" agent skill from https://github.com/bighadj22/codflow/tree/main/.agents/skills/codflow-update into .agents/skills/codflow-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codflow-update", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bighadj22/codflow --skill codflow-update -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install bighadj22/codflow codflow-update --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/codflow-update .cursor/skills/codflow-update && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codflow-update" agent skill from https://github.com/bighadj22/codflow/tree/main/.agents/skills/codflow-update into .cursor/skills/codflow-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codflow-update", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/bighadj22/codflow.git --path .agents/skills/codflow-update--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add bighadj22/codflow --skill codflow-update -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install bighadj22/codflow codflow-update --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/codflow-update .gemini/skills/codflow-update && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codflow-update" agent skill from https://github.com/bighadj22/codflow/tree/main/.agents/skills/codflow-update into .gemini/skills/codflow-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codflow-update", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install bighadj22/codflow codflow-updateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add bighadj22/codflow --skill codflow-update -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/codflow-update .github/skills/codflow-update && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codflow-update" agent skill from https://github.com/bighadj22/codflow/tree/main/.agents/skills/codflow-update into .github/skills/codflow-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codflow-update", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bighadj22/codflow --skill codflow-update -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install bighadj22/codflow codflow-update --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/codflow-update .opencode/skills/codflow-update && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codflow-update" agent skill from https://github.com/bighadj22/codflow/tree/main/.agents/skills/codflow-update into .opencode/skills/codflow-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codflow-update", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codflow-updateUpdate runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored…
Codflow Update is an agent skill from bighadj22/codflow. Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored wrangler.toml / .env / .dev.vars files with any template changes (keeping the user's resource IDs, worker names, and domains), creates ONLY the new Cloudflare resources an update introduces, applies new D1 migrations without touching data, and rebuilds + redeploys each updated worker (server, dashboard, or storefront theme) —…
Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Runbooks and postmortems and Plain language and style rules. It works with Cloudflare Workers, Cloudflare, GitHub and Model Context Protocol. The repository describes itself as: The open-source, COD-first e-commerce + delivery platform for Algeria built agentic-ready. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ed79aa9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmwranglercurlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npm, wrangler and curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
BETTER_AUTH_SECRETMCP_LOGIN_TICKET_SECRETSTORE_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codflow Update loads about 6.2k tokens when it runs. Until then it costs about 255 tokens; SKILL.md has 2,930 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ut, syncs the gitignored wrangler.toml / .env / .dev.varskill: their `wrangler.toml` files, root `.env`, and| User config (gitignored) | root `.env`, `cod-client-astro/.env`, both `wrangler.toml`, all `.dev.vars` | **preserved**ate settings into your wrangler.toml and .envtest -f .env && test -f cod-server/wrangler.toml && test -f cod-client-astro/wrangler.toml && echo OKas untracked/modified (`wrangler.toml`, `.env`,`git check-ignore .env cod-server/wrangler.toml` that they are ignored.`.env` key, the live files must be merged by hand (agent) or the next deploy| `.env.example` | `.env` (repo root) |-astro/.env.example` | `cod-client-astro/.env` |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from bighadj22/codflow at commit ed79aa9, republished under its Apache-2.0 licence (© bighadj22). 2,930 words, ~6,237 tokens.
.claude/skills/codflow-update/SKILL.md (or your agent's skills folder).CodFlow self-hosters cloned the repo and completed setup with the
codflow-setup skill: their wrangler.toml files, root .env, and
.dev.vars files are filled with THEIR resource IDs and secrets and are all
gitignored. This runbook brings such an install to the latest upstream
code incrementally — no re-running setup, no re-creating resources, no
data loss.
This skill ships inside the repo (.agents/skills/codflow-update/), so a
plain git pull delivers it. The very first time, the developer can pull once
by hand (git pull origin main) and then ask their agent to run this skill;
every update after that is fully agent-driven.
Source of truth: updates come from https://github.com/bighadj22/codflow,
branch main. Every fetch/merge in this runbook targets that repository
and branch — never a fork, never another branch.
The developer running this may be a non-developer ("vibe coder") who set CodFlow up with an agent and never touched git or wrangler themselves. After completing EACH step below, stop and tell the user what just happened, in plain language, before starting the next step:
"✅ Step 2 of 8 done: I downloaded the latest CodFlow code (14 new versions since yours, including a fix for order tracking). Your files — database, images, settings, passwords — were not touched. Next: I'll check if the new version needs new settings added to your config files."
Do not stay silent across multiple steps and summarize at the end — the user must be able to follow the update as it happens.
| Category | Files | Update behavior |
|---|---|---|
| Tracked code | everything except the rows below | replaced by git merge |
| Migration files | cod-server/src/db/migrations/ | new files arrive; applied incrementally |
| User config (gitignored) | root .env, cod-client-astro/.env, both wrangler.toml, all .dev.vars | preserved; only merged with new template keys (Step 3) |
| Cloudflare resources | D1, R2 bucket, KV namespaces, worker names | preserved; only new bindings get new resources (Step 4) |
| Worker secrets | BETTER_AUTH_SECRET, MCP_LOGIN_TICKET_SECRET, STORE_API_KEY, R2 keys | preserved, never regenerated; only new secrets are added (Step 4) |
| Database data | all rows in the user's D1 | preserved; migrations are additive; never re-seed a live store |
State this to the developer before running anything:
"This update will fetch the latest CodFlow code and merge it into your checkout, merge any new template settings into your wrangler.toml and .env files while keeping your resource IDs, worker names, and domains, apply any new D1 migrations to your database (existing data is untouched), and redeploy the affected workers. Nothing is re-created from scratch, no secrets are regenerated, and no demo data is re-seeded."
This must be an existing install. Verify, from the repo root:
test -f .env && test -f cod-server/wrangler.toml && test -f cod-client-astro/wrangler.toml && echo OKIf any is missing, STOP — this is not a completed setup. Run the
codflow-setup skill instead.
Correct upstream remote.
git remote get-url origin # expect .../bighadj22/codflow.gitIf origin points elsewhere (a fork, another copy), ask the developer
where they track CodFlow updates. If upstream is not configured:
git remote add upstream https://github.com/bighadj22/codflow.gitand use upstream in place of origin throughout this runbook.
Cloudflare auth still valid.
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler whoamiSame trap as setup: if the shell exports a stale CLOUDFLARE_ACCOUNT_ID
the OAuth token cannot access, EVERY wrangler command fails with
Authentication error [code: 10000]. Prefix every wrangler invocation with
env -u CLOUDFLARE_ACCOUNT_ID (done throughout below).
Clean working tree.
git status --porcelainwrangler.toml, .env,
.dev.vars) are expected and fine — confirm with
git check-ignore .env cod-server/wrangler.toml that they are ignored.reset --hard on your
own. Present the git status list to the developer and offer:git stash push -m "local edits before codflow update" -- <files> (pop
after the update, expect conflicts if the same lines changed upstream),Record the rollback point (mandatory).
git rev-parse --short HEAD | tee /tmp/codflow-update-old-head
git describe --tags HEAD 2>/dev/null || echo "(untagged)"Keep this for Step 8. Cloudflare also keeps each worker's previous deployment, so workers can be rolled back independently of the database.
git fetch origin main --tags
git rev-list --count HEAD..origin/main # commits behind
git log --oneline HEAD..origin/main # what's incomingIf the count is 0, the code is already current — but the install may still
be stale (pulled but never migrated/deployed). Do NOT exit yet: run the
assessment table below plus migrations list in Step 5; if everything is
clean, report "fully up to date" and stop.
Capture the assessment BEFORE merging — after the merge these diff ranges are empty. Fill this in and show the resulting plan to the developer:
| Check | Command | If anything listed → |
|---|---|---|
| Migrations | git diff --name-only HEAD..origin/main -- cod-server/src/db/migrations | Step 5 is mandatory |
| Dependencies | git diff --name-only HEAD..origin/main -- package.json package-lock.json | npm ci in Step 2 |
| Server config template | git diff --name-only HEAD..origin/main -- cod-server/wrangler.toml.example | Step 3 merge |
| Dashboard config templates | git diff --name-only HEAD..origin/main -- cod-client-astro/wrangler.toml.example cod-client-astro/.env.example | Step 3 merge |
| Root env template | git diff --name-only HEAD..origin/main -- .env.example | Step 3 merge |
| New secrets/env surface | git diff HEAD..origin/main -- cod-server/src/types/env.ts (also skim CHANGELOG.md, README.md, and skill diffs for secret put mentions) | Step 4 |
| Server code | git diff --name-only HEAD..origin/main -- cod-server cod-shared | deploy cod-server (Step 6) |
| Dashboard code | git diff --name-only HEAD..origin/main -- cod-client-astro | rebuild + deploy dashboard (Step 6) |
| Storefront code | git diff --name-only HEAD..origin/main -- cod-astro/theme01 | deploy theme01 (Step 6) |
If CHANGELOG.md changed, read its new sections and summarize the
user-visible changes for the developer before proceeding.
Present the plan ("I will merge N commits, apply migrations X–Y, add var Z to both wrangler.toml files, and redeploy cod-server + dashboard") and get a go-ahead. Migrations and redeploys touch their live store — never surprise them.
git merge --ff-only origin/main--ff-only succeeds when the checkout has no local commits — the normal
self-host case. If it refuses, the developer has local commits:
git log --oneline origin/main..HEAD shows them. Offer to
git rebase origin/main or stop and let the developer decide. Do not force
the merge.npm ciMissing field 'moduleType',
a second Vite major crept in: rm -rf node_modules && npm ci, then
npm ls vite must show a single major (the root overrides pin enforces
it).This is the step self-hosters miss. git pull updates
wrangler.toml.example and .env.example, but NEVER the user's live
gitignored files. When upstream adds a binding, a [vars] key, or a new
.env key, the live files must be merged by hand (agent) or the next deploy
breaks or the feature silently fails.
Work over these pairs:
| Template (tracked, just updated) | Live file (gitignored, user's) |
|---|---|
cod-server/wrangler.toml.example | cod-server/wrangler.toml |
cod-client-astro/wrangler.toml.example | cod-client-astro/wrangler.toml |
.env.example | .env (repo root) |
cod-client-astro/.env.example | cod-client-astro/.env |
<pkg>/.dev.vars.example (each package) | <pkg>/.dev.vars |
Into a directory OUTSIDE the repo (survives resets, never hits git):
BK="$HOME/.codflow-backups/$(date +%Y%m%d-%H%M%S)" && mkdir -p "$BK" && \
cp .env cod-client-astro/.env cod-server/wrangler.toml cod-client-astro/wrangler.toml "$BK/" && \
cp cod-server/.dev.vars cod-client-astro/.dev.vars cod-astro/theme01/.dev.vars "$BK/" 2>/dev/null; ls -la "$BK"Report this path to the developer — it is the config-level rollback.
diff cod-server/wrangler.toml.example cod-server/wrangler.toml
diff cod-client-astro/wrangler.toml.example cod-client-astro/wrangler.toml
diff .env.example .envThis catches cumulative drift (not just this update) and works even when
the developer already pulled the code themselves. Expect the live file to
differ in resource IDs, worker names, and real domains — those differences
are CORRECT. You are hunting only for things present in the template but
MISSING from the live file.
[vars] keys, new binding blocks
([[kv_namespaces]], [[r2_buckets]], [[d1_databases]], …), new
top-level settings.database_id, KV ids, bucket_name,
MEDIA_DOMAIN, all URL vars (WORKER_URL, BETTER_AUTH_URL,
PUBLIC_APP_URL, PUBLIC_API_URL, PUBLIC_TRUSTED_ORIGINS,
COD_SERVER_URL), and every name = worker name. Never reset a worker
name to the template default — that deploys onto (or creates) a DIFFERENT
worker.compatibility_date and compatibility_flags
changes — they are tied to what the new code expects. Note the change in
the summary.grep -rn "00000000-0000\|00000000000000000000000000000000" \
cod-server/wrangler.toml cod-client-astro/wrangler.toml.env.example → add to .env. Fill values derivable from the
install (e.g. a new COD_* key whose value equals an existing binding);
otherwise ask the developer. COD_SERVER_URL must stay the real deployed
origin — a loopback value blocks the theme01 deploy by design.git status --short .env cod-server/wrangler.toml cod-client-astro/wrangler.toml
# expected: nothing listedIf anything shows up, STOP — the .gitignore arrangement broke; fix before
continuing.
Skip entirely when Step 1 found no new bindings or secrets.
[[kv_namespaces]]/[[r2_buckets]]/etc. block
the live file lacked): create exactly that resource, nothing else, with the
install's <project> prefix —
env -u CLOUDFLARE_ACCOUNT_ID npx wrangler kv namespace create <name> —
following the setup skill's rules: fresh unique names, never reuse a
foreign existing resource, capture the real ID, bind it, re-run the
placeholder grep.cod-server/src/types/env.ts, or
secret put mentions in the updated docs/skills): ask the developer for
the value, then set with the setup skill's safe pattern — value via a
chmod-600 temp file or stdin redirect, never echo/heredoc:printf '<value>' | env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put <NAME> --name <server-worker-name>.dev.vars for local dev.BETTER_AUTH_SECRET and
MCP_LOGIN_TICKET_SECRET must remain the SAME values on both workers —
regenerating either invalidates every dashboard session and breaks
cross-worker auth. An update only ever ADDS secrets.Wrangler tracks applied migrations in the d1_migrations table inside the
user's D1, so re-running apply is incremental — it only runs files never
applied before. Existing rows are never touched; CodFlow migrations are
additive by policy.
cd cod-server
# Preview what is pending (works even if the developer already pulled earlier):
env -u CLOUDFLARE_ACCOUNT_ID node scripts/d1.mjs migrations list --remote
# Apply to the deployed database — MANDATORY before deploying new code:
env -u CLOUDFLARE_ACCOUNT_ID npm run db:migrate:remotefield "alg" does not exist in "jwkss" from migration 0011). Migrate first, deploy second.env -u CLOUDFLARE_ACCOUNT_ID npm run db:migrate:local
(persisted to <repo-root>/.wrangler-shared).d1_migrations table. Capture the full
error, identify the failing file in cod-server/src/db/migrations/, and
report to the developer (a fix usually means a corrected upstream migration
in a follow-up release).db:seed:remote re-inserts the
demo store, categories, and products (fixed IDs, INSERT OR REPLACE) and
seed:admin:remote resets the admin password — both wreck a production
install. Only run either when the developer explicitly asks for demo data
or a password reset.migrations list --remote again — expect no unapplied migrations.Redeploy every worker whose code OR config changed (Step 1 table + Step 3 merges). When in doubt, deploy all three — deploys are idempotent.
RULE — rebuild before deploy, no exceptions. Never deploy stale build output. Whatever was updated (server, dashboard, or storefront theme) must be rebuilt from the freshly merged code before it is deployed:
| Package | Rebuild before deploy | Why |
|---|---|---|
| cod-client-astro (dashboard) | handled by npm run deploy | Its deploy script builds first, parks .dev.vars so the production PUBLIC_API_URL from wrangler.toml [vars] is the one inlined, and aborts if the built bundle still contains a loopback URL. Run npm run build separately only to surface a build failure before deploying — that bare build uses the local API origin and must not be the artifact you ship. |
| cod-astro/theme01 (storefront) | npm run build | Its deploy script does build first, but run the build explicitly anyway so a build failure surfaces BEFORE any deploy attempt. |
| cod-server (API) | bundled by wrangler deploy itself | wrangler deploy compiles src/index.ts from source on every deploy — there is no stale dist/ to worry about. Still verify the deploy output references the NEW commit's code. |
cd cod-server && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy
cd ../cod-client-astro && env -u CLOUDFLARE_ACCOUNT_ID npm run build && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy
cd ../cod-astro/theme01 && env -u CLOUDFLARE_ACCOUNT_ID npm run build && env -u CLOUDFLARE_ACCOUNT_ID npm run deployA build that fails means the deploy must NOT proceed — report the error to the user, fix or stop. After each deploy, report to the user which worker was updated and to what version (per the reporting rule at the top).
PUBLIC_API_URL is
decided — it is inlined into the client bundle. npm run deploy parks
.dev.vars so the production value from wrangler.toml [vars] wins, and
refuses to upload a bundle that still contains a loopback URL. Never deploy a
dist/ produced by a bare npm run build on a developer machine: .dev.vars
outranks every .env file, so that artifact points at localhost.COD_SERVER_URL from the root .env; it refuses a
loopback value unless --force-local is passed (a deployed Worker can
never reach http://localhost:8787).Use the worker names from the live configs:
grep -E '^name' cod-server/wrangler.toml cod-client-astro/wrangler.toml and
grep '"name"' cod-astro/theme01/wrangler.jsonc.
| Worker | Check | Expectation |
|---|---|---|
| cod-server | curl -s -o /dev/null -w "%{http_code}" https://<api-domain>/api/docs | 200 |
| dashboard sign-in API | curl -s -X POST https://<dashboard-url>/api/auth/sign-in/email -H "Content-Type: application/json" -H "Origin: https://<dashboard-url>" -d '{"email":"<admin>","password":"<pass>"}' | 200 + user JSON (500 = missing migration or config; 403 INVALID_ORIGIN = PUBLIC_TRUSTED_ORIGINS drift; 401 = credentials) |
| dashboard UI | open the dashboard URL | new version loads, login works |
| cod-astro/theme01 | open the storefront URL | homepage renders with products |
| database | env -u CLOUDFLARE_ACCOUNT_ID node scripts/d1.mjs migrations list --remote (from cod-server/) | no unapplied migrations |
The Origin header in the sign-in check is mandatory — without it the check
passes while every real browser request fails. If anything fails, diagnose
with env -u CLOUDFLARE_ACCOUNT_ID npx wrangler tail <worker-name> --format pretty while retrying the failing request. If the changelog highlighted a
specific fix or feature, exercise it once before declaring success.
Print:
<old-HEAD-or-tag> → <new-HEAD-or-tag> (git describe --tags HEAD), commit count merged, one-line summary of user-visible
changes from CHANGELOG.md.compatibility_date changes if any.~/.codflow-backups/<timestamp> path from Step 3.env -u CLOUDFLARE_ACCOUNT_ID npx wrangler rollback <worker-name> — instantly reverts that worker to its previous deployment.git checkout <old-HEAD-from-prerequisites> then redeploy the
affected workers.d1_migrations or dropping objects by hand.| Problem | Cause | Solution |
|---|---|---|
git merge --ff-only refuses | Local commits exist in the checkout | Show git log --oneline origin/main..HEAD; offer git rebase origin/main or let the developer decide. Never force. |
| Merge conflicts on tracked files | Tracked files were locally modified | Resolve from the stash taken in Prerequisites, or with the developer. Never reset --hard without explicit confirmation. |
Sign-in returns 500 field "alg" does not exist in "jwkss" (or similar missing-column errors) | New code deployed before its migration ran | Run npm run db:migrate:remote in cod-server (Step 5); the error names the missing column → find its migration file. |
| New feature 500s or "… is not set" | A new secret or var from the update was never set | Re-check the cod-server/src/types/env.ts diff and Step 4; set the missing secret/var, redeploy. |
| Dashboard still shows the old UI | A stale dist/ was shipped | cd cod-client-astro && npm run deploy — it rebuilds before uploading. |
Live dashboard calls http://localhost:8787 | A bare npm run build artifact was deployed; .dev.vars outranks every .env file | cd cod-client-astro && npm run deploy — it parks .dev.vars for the build and aborts on a loopback URL. |
Dev server dies with Missing field 'moduleType' | Two Vite majors after a dependency update | rm -rf node_modules && npm ci at the root; npm ls vite must show one major. |
theme01 deploy refuses: loopback COD_SERVER_URL | Root .env still has the localhost default | Set the real deployed cod-server origin in .env, retry. --force-local only for intentional local deploys. |
| Storefront renders but products empty | Worker→Worker fetch between two *.workers.dev hosts is blocked (CF error 1042), or COD_SERVER_URL points at the wrong origin | Put cod-server on a custom domain/route, set COD_SERVER_URL, redeploy theme01. |
Sign-in 403 INVALID_ORIGIN in browser but curl passes without Origin | Dashboard origin missing from PUBLIC_TRUSTED_ORIGINS (e.g. domain changed during config merge) | Add the dashboard URL to PUBLIC_TRUSTED_ORIGINS in cod-client-astro/wrangler.toml, redeploy, retest WITH the Origin header. |
| Every API call 401 after update although sign-in works | BETTER_AUTH_SECRET differs between the two workers (someone regenerated it) | Restore the identical original secret on both workers — check the Step 3 backups or the credentials file from setup. |
migrations apply fails mid-file | Upstream migration bug or schema conflict | STOP (Step 5 rule): no deploy, no hand-editing; capture the error and the file name, report to the developer / upstream issue. |
All wrangler commands fail Authentication error [code: 10000] | Stale CLOUDFLARE_ACCOUNT_ID exported in the shell | Prefix commands with env -u CLOUDFLARE_ACCOUNT_ID (see Prerequisites). |
| Local dev broken after update (missing tables) | Local shared D1 not migrated | cd cod-server && env -u CLOUDFLARE_ACCOUNT_ID npm run db:migrate:local — local state lives in <repo-root>/.wrangler-shared. |
© bighadj22, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/codflow-update of bighadj22/codflow.
Open the folder on GitHubat commit ed79aa9
Codflow Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codflow Update this skillbighadj22/codflow | 346 | — | ~6.2k | Automated safety check: Notes | Apache-2.0 | |
| Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template | 786 | — | ~5.9k | Automated safety check: Notes | MIT | |
| GreptimeDB Release RunbookGreptimeTeam/greptimedb | 6.7k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Observability Triageevery-app/open-seo | 23k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Building MCP Server On CloudflareCommandCodeAI/agent-skills | 132 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Release Processscragnog/HOT-Step-CPP | 171 | — | ~5.1k | Automated safety check: Pass | MIT |
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
GreptimeTeam/greptimedb
Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.
every-app/open-seo
Triage OpenSEO production errors in Cloudflare Workers Observability — verified query recipes, counting gotchas, and a known-noise filter list applied automatically.
CommandCodeAI/agent-skills
Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment.
scragnog/HOT-Step-CPP
Runbook for cutting and publishing a HOT-Step CPP release via a v git tag that triggers the multi-platform CI build and drafts a GitHub Release.
secondsky/claude-skills
Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.
bighadj22/codflow
Wires an app to the Yalidine (Guepex) Algerian courier API: parcels, zone lookups, delivery fees and verified delivery-status webhooks.
bighadj22/codflow
Bundles Meta's official Pixel and Conversions API documentation so tracking changes, event deduplication and conversion events are checked against the real spec.
bighadj22/codflow
A step-by-step workflow for changing the CodFlow repository: read the AGENTS.md contract, respect package boundaries, verify before claiming done and keep PRs small.
bighadj22/codflow
Guides an agent through eight customer tools in a cash-on-delivery CRM for Algerian e-commerce: search, profiles, phone lookup, order history, groups, tags and deletion.
bighadj22/codflow
Guides connecting and maintaining the EcoTrack courier adapter in CodFlow, one API shared by 82 Algerian couriers, using the official API reference and a rollout plan.
bighadj22/codflow
Creates new API endpoints, and converts older ones, with the defineRoute() pattern used in cod-server, including auth strategies, scopes and OpenAPI output.
Categories
Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored…. Codflow Update is an agent skill from bighadj22/codflow.
Codflow Update fits situations like: the developer already set CodFlow up (via the codflow-setup skill) and wants to update; upgrade to the latest version from https://github.com/bighadj22/codflow (branch main); pull the latest changes/release; apply new migrations after pulling.
Run `npx skills add bighadj22/codflow --skill codflow-update -a claude-code`. Or copy the skill folder (.agents/skills/codflow-update in bighadj22/codflow) into .claude/skills/codflow-update in your project. Claude Code loads it when a task matches its description.
Run `npx skills add bighadj22/codflow --skill codflow-update -a codex`. Or copy the skill folder (.agents/skills/codflow-update in bighadj22/codflow) into .agents/skills/codflow-update in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bighadj22/codflow --skill codflow-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codflow-update, .gemini/skills/codflow-update, .github/skills/codflow-update and .opencode/skills/codflow-update in your project.
Going by SKILL.md and its folder, Codflow Update needs the command-line tools its instructions call (git, npm, wrangler and curl) and credentials named BETTER_AUTH_SECRET, MCP_LOGIN_TICKET_SECRET and STORE_API_KEY. Our summary lists: Node.js; A credential in BETTER_AUTH_SECRET; A credential in MCP_LOGIN_TICKET_SECRET.
SKILL.md contains no URLs. Its commands use git, npm and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Codflow Update is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Codflow Update: Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), GreptimeDB Release Runbook (GreptimeTeam/greptimedb, 6.7k stars), Observability Triage (every-app/open-seo, 23k stars) and Building MCP Server On Cloudflare (CommandCodeAI/agent-skills, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
bighadj22 (a GitHub user) maintains it in bighadj22/codflow, which has 346 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 6, 2026.
Source: bighadj22/codflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.