Agent skill

Codflow Update

by bighadj22 in bighadj22/codflow

Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored…

Apache-2.0Auto-check: notesDevOps & Cloud

Install Codflow Update

skills CLI
$ npx skills add bighadj22/codflow --skill codflow-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bighadj22/codflow codflow-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/codflow-update .claude/skills/codflow-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codflow-update
GitHub stars
346
Token cost
~6.2k tokens
SKILL.md length
2,930 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored…

  • Works in 8 steps: Fetch and Assess (changes nothing yet) → Merge the Code → Sync the Gitignored Config with the New… → …
  • The developer already set CodFlow up (via the codflow-setup skill) and wants to update
  • SKILL.md covers Report EVERY step to the user…, What an update changes vs.…, Before Starting — State This… and Prerequisites — Gates, In Order, plus 9 more sections
  • Calls git, npm and wrangler; needs BETTER_AUTH_SECRET and MCP_LOGIN_TICKET_SECRET

What it does

Codflow Update is an agent skill from bighadj22/codflow. Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored wrangler.toml / .env / .dev.vars files with any template changes (keeping the user's resource IDs, worker names, and domains), creates ONLY the new Cloudflare resources an update introduces, applies new D1 migrations without touching data, and rebuilds + redeploys each updated worker (server, dashboard, or storefront theme) —…

Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Runbooks and postmortems and Plain language and style rules. It works with Cloudflare Workers, Cloudflare, GitHub and Model Context Protocol. The repository describes itself as: The open-source, COD-first e-commerce + delivery platform for Algeria built agentic-ready. The licence is Apache-2.0.

When your agent uses it

  • The developer already set CodFlow up (via the codflow-setup skill) and wants to update
  • Upgrade to the latest version from https://github.com/bighadj22/codflow (branch main)
  • Pull the latest changes/release
  • Apply new migrations after pulling

Example prompts

  • “/codflow-update”

Requirements

  • Node.js
  • A credential in BETTER_AUTH_SECRET
  • A credential in MCP_LOGIN_TICKET_SECRET

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Fetch and Assess (changes nothing yet)
  2. Merge the Code
  3. Sync the Gitignored Config with the New Templates
  4. New Resources and Secrets ONLY (conditional)
  5. Apply New D1 Migrations (BEFORE Deploying Code)
  6. Redeploy Affected Workers (Rebuild FIRST, Then Deploy)
  7. Verify (Do Not Skip Past a Failing Check)
  8. Closing Summary (Mandatory)

What it can do on your machine

Read from SKILL.md and the folder at commit ed79aa9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • wrangler
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm, wrangler and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BETTER_AUTH_SECRET
    • MCP_LOGIN_TICKET_SECRET
    • STORE_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codflow Update loads about 6.2k tokens when it runs. Until then it costs about 255 tokens; SKILL.md has 2,930 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~255
When it runs · the whole SKILL.md, loaded when a task matches
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:6
    ut, syncs the gitignored wrangler.toml / .env / .dev.vars
  • NoteMentions a .env fileSKILL.md:23
    kill: their `wrangler.toml` files, root `.env`, and
  • NoteMentions a .env fileSKILL.md:67
    | User config (gitignored) | root `.env`, `cod-client-astro/.env`, both `wrangler.toml`, all `.dev.vars` | **preserved**
  • NoteMentions a .env fileSKILL.md:77
    ate settings into your wrangler.toml and .env
  • NoteMentions a .env fileSKILL.md:87
    test -f .env && test -f cod-server/wrangler.toml && test -f cod-client-astro/wrangler.toml && echo OK
  • NoteMentions a .env fileSKILL.md:116
    as untracked/modified (`wrangler.toml`, `.env`,
  • NoteMentions a .env fileSKILL.md:118
    `git check-ignore .env cod-server/wrangler.toml` that they are ignored.
  • NoteMentions a .env fileSKILL.md:196
    `.env` key, the live files must be merged by hand (agent) or the next deploy
  • NoteMentions a .env fileSKILL.md:205
    | `.env.example` | `.env` (repo root) |
  • NoteMentions a .env fileSKILL.md:206
    -astro/.env.example` | `cod-client-astro/.env` |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bighadj22/codflow at commit ed79aa9, republished under its Apache-2.0 licence (© bighadj22). 2,930 words, ~6,237 tokens.

Download SKILL.mdSave it as .claude/skills/codflow-update/SKILL.md (or your agent's skills folder).
name
codflow-update
description
Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored wrangler.toml / .env / .dev.vars files with any template changes (keeping the user's resource IDs, worker names, and domains), creates ONLY the new Cloudflare resources an update introduces, applies new D1 migrations without touching data, and rebuilds + redeploys each updated worker (server, dashboard, or storefront theme) — never re-running the full setup, never regenerating secrets, never re-seeding a live store, and reporting every step to the user in plain language (they may be a non-developer). Use when the developer already set CodFlow up (via the codflow-setup skill) and wants to update or upgrade to the latest version from https://github.com/bighadj22/codflow (branch main), pull the latest changes/release, apply new migrations after pulling, or asks how to get updates for their existing install.

CodFlow Update — Agent Runbook

CodFlow self-hosters cloned the repo and completed setup with the codflow-setup skill: their wrangler.toml files, root .env, and .dev.vars files are filled with THEIR resource IDs and secrets and are all gitignored. This runbook brings such an install to the latest upstream code incrementally — no re-running setup, no re-creating resources, no data loss.

This skill ships inside the repo (.agents/skills/codflow-update/), so a plain git pull delivers it. The very first time, the developer can pull once by hand (git pull origin main) and then ask their agent to run this skill; every update after that is fully agent-driven.

Source of truth: updates come from https://github.com/bighadj22/codflow, branch main. Every fetch/merge in this runbook targets that repository and branch — never a fork, never another branch.

Report EVERY step to the user — devs and non-devs alike

The developer running this may be a non-developer ("vibe coder") who set CodFlow up with an agent and never touched git or wrangler themselves. After completing EACH step below, stop and tell the user what just happened, in plain language, before starting the next step:

  • Say what you did, what it changed, and why — one short paragraph per step.
  • Lead with the plain-language outcome, then the technical detail. Good:

    "✅ Step 2 of 8 done: I downloaded the latest CodFlow code (14 new versions since yours, including a fix for order tracking). Your files — database, images, settings, passwords — were not touched. Next: I'll check if the new version needs new settings added to your config files."

  • Never dump raw command output at a non-dev without a one-line explanation of what it means.
  • If a step needs a decision or a value only the user has (a password, a domain, a yes/no), ask clearly and wait — do not guess.
  • If a step fails, say plainly what broke and what you will do about it before doing anything.

Do not stay silent across multiple steps and summarize at the end — the user must be able to follow the update as it happens.

What an update changes vs. what it must never touch

CategoryFilesUpdate behavior
Tracked codeeverything except the rows belowreplaced by git merge
Migration filescod-server/src/db/migrations/new files arrive; applied incrementally
User config (gitignored)root .env, cod-client-astro/.env, both wrangler.toml, all .dev.varspreserved; only merged with new template keys (Step 3)
Cloudflare resourcesD1, R2 bucket, KV namespaces, worker namespreserved; only new bindings get new resources (Step 4)
Worker secretsBETTER_AUTH_SECRET, MCP_LOGIN_TICKET_SECRET, STORE_API_KEY, R2 keyspreserved, never regenerated; only new secrets are added (Step 4)
Database dataall rows in the user's D1preserved; migrations are additive; never re-seed a live store

Before Starting — State This Contract

State this to the developer before running anything:

"This update will fetch the latest CodFlow code and merge it into your checkout, merge any new template settings into your wrangler.toml and .env files while keeping your resource IDs, worker names, and domains, apply any new D1 migrations to your database (existing data is untouched), and redeploy the affected workers. Nothing is re-created from scratch, no secrets are regenerated, and no demo data is re-seeded."

Prerequisites — Gates, In Order

  1. This must be an existing install. Verify, from the repo root:

    bash
    test -f .env && test -f cod-server/wrangler.toml && test -f cod-client-astro/wrangler.toml && echo OK

    If any is missing, STOP — this is not a completed setup. Run the codflow-setup skill instead.

  2. Correct upstream remote.

    bash
    git remote get-url origin    # expect .../bighadj22/codflow.git

    If origin points elsewhere (a fork, another copy), ask the developer where they track CodFlow updates. If upstream is not configured:

    bash
    git remote add upstream https://github.com/bighadj22/codflow.git

    and use upstream in place of origin throughout this runbook.

  3. Cloudflare auth still valid.

    bash
    env -u CLOUDFLARE_ACCOUNT_ID npx wrangler whoami

    Same trap as setup: if the shell exports a stale CLOUDFLARE_ACCOUNT_ID the OAuth token cannot access, EVERY wrangler command fails with Authentication error [code: 10000]. Prefix every wrangler invocation with env -u CLOUDFLARE_ACCOUNT_ID (done throughout below).

  4. Clean working tree.

    bash
    git status --porcelain
    • Gitignored files showing as untracked/modified (wrangler.toml, .env, .dev.vars) are expected and fine — confirm with git check-ignore .env cod-server/wrangler.toml that they are ignored.
    • Modified TRACKED files block the merge. Do not reset --hard on your own. Present the git status list to the developer and offer:
      • git stash push -m "local edits before codflow update" -- <files> (pop after the update, expect conflicts if the same lines changed upstream),
      • committing them to a local branch, or
      • discarding them — only with explicit confirmation.
  5. Record the rollback point (mandatory).

    bash
    git rev-parse --short HEAD | tee /tmp/codflow-update-old-head
    git describe --tags HEAD 2>/dev/null || echo "(untagged)"

    Keep this for Step 8. Cloudflare also keeps each worker's previous deployment, so workers can be rolled back independently of the database.

Step 1 — Fetch and Assess (changes nothing yet)

bash
git fetch origin main --tags
git rev-list --count HEAD..origin/main        # commits behind
git log --oneline HEAD..origin/main           # what's incoming

If the count is 0, the code is already current — but the install may still be stale (pulled but never migrated/deployed). Do NOT exit yet: run the assessment table below plus migrations list in Step 5; if everything is clean, report "fully up to date" and stop.

Capture the assessment BEFORE merging — after the merge these diff ranges are empty. Fill this in and show the resulting plan to the developer:

CheckCommandIf anything listed →
Migrationsgit diff --name-only HEAD..origin/main -- cod-server/src/db/migrationsStep 5 is mandatory
Dependenciesgit diff --name-only HEAD..origin/main -- package.json package-lock.jsonnpm ci in Step 2
Server config templategit diff --name-only HEAD..origin/main -- cod-server/wrangler.toml.exampleStep 3 merge
Dashboard config templatesgit diff --name-only HEAD..origin/main -- cod-client-astro/wrangler.toml.example cod-client-astro/.env.exampleStep 3 merge
Root env templategit diff --name-only HEAD..origin/main -- .env.exampleStep 3 merge
New secrets/env surfacegit diff HEAD..origin/main -- cod-server/src/types/env.ts (also skim CHANGELOG.md, README.md, and skill diffs for secret put mentions)Step 4
Server codegit diff --name-only HEAD..origin/main -- cod-server cod-shareddeploy cod-server (Step 6)
Dashboard codegit diff --name-only HEAD..origin/main -- cod-client-astrorebuild + deploy dashboard (Step 6)
Storefront codegit diff --name-only HEAD..origin/main -- cod-astro/theme01deploy theme01 (Step 6)

If CHANGELOG.md changed, read its new sections and summarize the user-visible changes for the developer before proceeding.

Present the plan ("I will merge N commits, apply migrations X–Y, add var Z to both wrangler.toml files, and redeploy cod-server + dashboard") and get a go-ahead. Migrations and redeploys touch their live store — never surprise them.

Step 2 — Merge the Code

bash
git merge --ff-only origin/main
  • --ff-only succeeds when the checkout has no local commits — the normal self-host case. If it refuses, the developer has local commits: git log --oneline origin/main..HEAD shows them. Offer to git rebase origin/main or stop and let the developer decide. Do not force the merge.
  • If dependencies changed (Step 1 table), reinstall at the repo root:
    bash
    npm ci
    One root lockfile covers all workspaces — never create per-package lockfiles. If a dev server later dies with Missing field 'moduleType', a second Vite major crept in: rm -rf node_modules && npm ci, then npm ls vite must show a single major (the root overrides pin enforces it).

Step 3 — Sync the Gitignored Config with the New Templates

This is the step self-hosters miss. git pull updates wrangler.toml.example and .env.example, but NEVER the user's live gitignored files. When upstream adds a binding, a [vars] key, or a new .env key, the live files must be merged by hand (agent) or the next deploy breaks or the feature silently fails.

Work over these pairs:

Template (tracked, just updated)Live file (gitignored, user's)
cod-server/wrangler.toml.examplecod-server/wrangler.toml
cod-client-astro/wrangler.toml.examplecod-client-astro/wrangler.toml
.env.example.env (repo root)
cod-client-astro/.env.examplecod-client-astro/.env
<pkg>/.dev.vars.example (each package)<pkg>/.dev.vars
1. Back up every live config file first

Into a directory OUTSIDE the repo (survives resets, never hits git):

bash
BK="$HOME/.codflow-backups/$(date +%Y%m%d-%H%M%S)" && mkdir -p "$BK" && \
cp .env cod-client-astro/.env cod-server/wrangler.toml cod-client-astro/wrangler.toml "$BK/" && \
cp cod-server/.dev.vars cod-client-astro/.dev.vars cod-astro/theme01/.dev.vars "$BK/" 2>/dev/null; ls -la "$BK"

Report this path to the developer — it is the config-level rollback.

2. Diff live file against the CURRENT template
bash
diff cod-server/wrangler.toml.example cod-server/wrangler.toml
diff cod-client-astro/wrangler.toml.example cod-client-astro/wrangler.toml
diff .env.example .env

This catches cumulative drift (not just this update) and works even when the developer already pulled the code themselves. Expect the live file to differ in resource IDs, worker names, and real domains — those differences are CORRECT. You are hunting only for things present in the template but MISSING from the live file.

3. Merge rules
  • Add to the live file: new [vars] keys, new binding blocks ([[kv_namespaces]], [[r2_buckets]], [[d1_databases]], …), new top-level settings.
  • Keep the user's value for: database_id, KV ids, bucket_name, MEDIA_DOMAIN, all URL vars (WORKER_URL, BETTER_AUTH_URL, PUBLIC_APP_URL, PUBLIC_API_URL, PUBLIC_TRUSTED_ORIGINS, COD_SERVER_URL), and every name = worker name. Never reset a worker name to the template default — that deploys onto (or creates) a DIFFERENT worker.
  • Adopt upstream's compatibility_date and compatibility_flags changes — they are tied to what the new code expects. Note the change in the summary.
  • A binding block copied from the template carries placeholder IDs. A genuinely NEW binding means a new resource — create it in Step 4, then bind the real ID. Never leave a placeholder. After merging, re-run the setup placeholder check and expect zero hits:
    bash
    grep -rn "00000000-0000\|00000000000000000000000000000000" \
      cod-server/wrangler.toml cod-client-astro/wrangler.toml
  • Keys removed from a template: leave them in the live file, note it in the summary, and only remove after the developer confirms (removals are rare and may be staged rollouts).
  • New keys in .env.example → add to .env. Fill values derivable from the install (e.g. a new COD_* key whose value equals an existing binding); otherwise ask the developer. COD_SERVER_URL must stay the real deployed origin — a loopback value blocks the theme01 deploy by design.
4. Confirm the live files are still ignored
bash
git status --short .env cod-server/wrangler.toml cod-client-astro/wrangler.toml
# expected: nothing listed

If anything shows up, STOP — the .gitignore arrangement broke; fix before continuing.

Step 4 — New Resources and Secrets ONLY (conditional)

Skip entirely when Step 1 found no new bindings or secrets.

  • New resource bindings (a [[kv_namespaces]]/[[r2_buckets]]/etc. block the live file lacked): create exactly that resource, nothing else, with the install's <project> prefix — env -u CLOUDFLARE_ACCOUNT_ID npx wrangler kv namespace create <name> — following the setup skill's rules: fresh unique names, never reuse a foreign existing resource, capture the real ID, bind it, re-run the placeholder grep.
  • New secrets (new fields in cod-server/src/types/env.ts, or secret put mentions in the updated docs/skills): ask the developer for the value, then set with the setup skill's safe pattern — value via a chmod-600 temp file or stdin redirect, never echo/heredoc:
    bash
    printf '<value>' | env -u CLOUDFLARE_ACCOUNT_ID npx wrangler secret put <NAME> --name <server-worker-name>
    Also add it to the matching .dev.vars for local dev.
  • NEVER regenerate existing secrets. BETTER_AUTH_SECRET and MCP_LOGIN_TICKET_SECRET must remain the SAME values on both workers — regenerating either invalidates every dashboard session and breaks cross-worker auth. An update only ever ADDS secrets.
  • Optional features (Sendili email, WhatsApp OTP, Turnstile, …) stay opt-in. An update never configures them silently — mention them in the summary if the changelog announces them.
Show full SKILL.md (1,261 more words)Show less

Step 5 — Apply New D1 Migrations (BEFORE Deploying Code)

Wrangler tracks applied migrations in the d1_migrations table inside the user's D1, so re-running apply is incremental — it only runs files never applied before. Existing rows are never touched; CodFlow migrations are additive by policy.

bash
cd cod-server
# Preview what is pending (works even if the developer already pulled earlier):
env -u CLOUDFLARE_ACCOUNT_ID node scripts/d1.mjs migrations list --remote

# Apply to the deployed database — MANDATORY before deploying new code:
env -u CLOUDFLARE_ACCOUNT_ID npm run db:migrate:remote
  • Order matters. Deploying code that expects a new column before its migration runs produces live 500s (the classic: field "alg" does not exist in "jwkss" from migration 0011). Migrate first, deploy second.
  • If the developer also runs the stack locally, migrate the shared local state too: env -u CLOUDFLARE_ACCOUNT_ID npm run db:migrate:local (persisted to <repo-root>/.wrangler-shared).
  • If a migration fails: STOP. Do not deploy, do not retry blindly, do not hand-edit the database or the d1_migrations table. Capture the full error, identify the failing file in cod-server/src/db/migrations/, and report to the developer (a fix usually means a corrected upstream migration in a follow-up release).
  • NEVER re-run seeders on a live store. db:seed:remote re-inserts the demo store, categories, and products (fixed IDs, INSERT OR REPLACE) and seed:admin:remote resets the admin password — both wreck a production install. Only run either when the developer explicitly asks for demo data or a password reset.
  • Verify: migrations list --remote again — expect no unapplied migrations.

Step 6 — Redeploy Affected Workers (Rebuild FIRST, Then Deploy)

Redeploy every worker whose code OR config changed (Step 1 table + Step 3 merges). When in doubt, deploy all three — deploys are idempotent.

RULE — rebuild before deploy, no exceptions. Never deploy stale build output. Whatever was updated (server, dashboard, or storefront theme) must be rebuilt from the freshly merged code before it is deployed:

PackageRebuild before deployWhy
cod-client-astro (dashboard)handled by npm run deployIts deploy script builds first, parks .dev.vars so the production PUBLIC_API_URL from wrangler.toml [vars] is the one inlined, and aborts if the built bundle still contains a loopback URL. Run npm run build separately only to surface a build failure before deploying — that bare build uses the local API origin and must not be the artifact you ship.
cod-astro/theme01 (storefront)npm run buildIts deploy script does build first, but run the build explicitly anyway so a build failure surfaces BEFORE any deploy attempt.
cod-server (API)bundled by wrangler deploy itselfwrangler deploy compiles src/index.ts from source on every deploy — there is no stale dist/ to worry about. Still verify the deploy output references the NEW commit's code.
bash
cd cod-server           && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy
cd ../cod-client-astro  && env -u CLOUDFLARE_ACCOUNT_ID npm run build && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy
cd ../cod-astro/theme01 && env -u CLOUDFLARE_ACCOUNT_ID npm run build && env -u CLOUDFLARE_ACCOUNT_ID npm run deploy

A build that fails means the deploy must NOT proceed — report the error to the user, fix or stop. After each deploy, report to the user which worker was updated and to what version (per the reporting rule at the top).

  • The dashboard deploy builds, and the build is where PUBLIC_API_URL is decided — it is inlined into the client bundle. npm run deploy parks .dev.vars so the production value from wrangler.toml [vars] wins, and refuses to upload a bundle that still contains a loopback URL. Never deploy a dist/ produced by a bare npm run build on a developer machine: .dev.vars outranks every .env file, so that artifact points at localhost.
  • theme01's deploy reads COD_SERVER_URL from the root .env; it refuses a loopback value unless --force-local is passed (a deployed Worker can never reach http://localhost:8787).

Step 7 — Verify (Do Not Skip Past a Failing Check)

Use the worker names from the live configs: grep -E '^name' cod-server/wrangler.toml cod-client-astro/wrangler.toml and grep '"name"' cod-astro/theme01/wrangler.jsonc.

WorkerCheckExpectation
cod-servercurl -s -o /dev/null -w "%{http_code}" https://<api-domain>/api/docs200
dashboard sign-in APIcurl -s -X POST https://<dashboard-url>/api/auth/sign-in/email -H "Content-Type: application/json" -H "Origin: https://<dashboard-url>" -d '{"email":"<admin>","password":"<pass>"}'200 + user JSON (500 = missing migration or config; 403 INVALID_ORIGIN = PUBLIC_TRUSTED_ORIGINS drift; 401 = credentials)
dashboard UIopen the dashboard URLnew version loads, login works
cod-astro/theme01open the storefront URLhomepage renders with products
databaseenv -u CLOUDFLARE_ACCOUNT_ID node scripts/d1.mjs migrations list --remote (from cod-server/)no unapplied migrations

The Origin header in the sign-in check is mandatory — without it the check passes while every real browser request fails. If anything fails, diagnose with env -u CLOUDFLARE_ACCOUNT_ID npx wrangler tail <worker-name> --format pretty while retrying the failing request. If the changelog highlighted a specific fix or feature, exercise it once before declaring success.

Step 8 — Closing Summary (Mandatory)

Print:

  1. Version move: <old-HEAD-or-tag> → <new-HEAD-or-tag> (git describe --tags HEAD), commit count merged, one-line summary of user-visible changes from CHANGELOG.md.
  2. Database: migrations applied (file names), migrations pending (should be none).
  3. Config: keys/bindings added to each live file; worker names confirmed unchanged; compatibility_date changes if any.
  4. Cloudflare: new resources created (name + ID + where bound), new secrets set (names only, never values).
  5. Deploys: workers redeployed + all smoke checks green.
  6. Backups: the ~/.codflow-backups/<timestamp> path from Step 3.
Rollback (only if something is broken)
  • Workers only: env -u CLOUDFLARE_ACCOUNT_ID npx wrangler rollback <worker-name> — instantly reverts that worker to its previous deployment.
  • Code: git checkout <old-HEAD-from-prerequisites> then redeploy the affected workers.
  • Config: restore files from the Step 3 backup directory.
  • Database: D1 has no down-migrations. CodFlow migrations are additive, so rolled-back code runs fine on the newer schema — never un-apply by deleting rows from d1_migrations or dropping objects by hand.

Troubleshooting

ProblemCauseSolution
git merge --ff-only refusesLocal commits exist in the checkoutShow git log --oneline origin/main..HEAD; offer git rebase origin/main or let the developer decide. Never force.
Merge conflicts on tracked filesTracked files were locally modifiedResolve from the stash taken in Prerequisites, or with the developer. Never reset --hard without explicit confirmation.
Sign-in returns 500 field "alg" does not exist in "jwkss" (or similar missing-column errors)New code deployed before its migration ranRun npm run db:migrate:remote in cod-server (Step 5); the error names the missing column → find its migration file.
New feature 500s or "… is not set"A new secret or var from the update was never setRe-check the cod-server/src/types/env.ts diff and Step 4; set the missing secret/var, redeploy.
Dashboard still shows the old UIA stale dist/ was shippedcd cod-client-astro && npm run deploy — it rebuilds before uploading.
Live dashboard calls http://localhost:8787A bare npm run build artifact was deployed; .dev.vars outranks every .env filecd cod-client-astro && npm run deploy — it parks .dev.vars for the build and aborts on a loopback URL.
Dev server dies with Missing field 'moduleType'Two Vite majors after a dependency updaterm -rf node_modules && npm ci at the root; npm ls vite must show one major.
theme01 deploy refuses: loopback COD_SERVER_URLRoot .env still has the localhost defaultSet the real deployed cod-server origin in .env, retry. --force-local only for intentional local deploys.
Storefront renders but products emptyWorker→Worker fetch between two *.workers.dev hosts is blocked (CF error 1042), or COD_SERVER_URL points at the wrong originPut cod-server on a custom domain/route, set COD_SERVER_URL, redeploy theme01.
Sign-in 403 INVALID_ORIGIN in browser but curl passes without OriginDashboard origin missing from PUBLIC_TRUSTED_ORIGINS (e.g. domain changed during config merge)Add the dashboard URL to PUBLIC_TRUSTED_ORIGINS in cod-client-astro/wrangler.toml, redeploy, retest WITH the Origin header.
Every API call 401 after update although sign-in worksBETTER_AUTH_SECRET differs between the two workers (someone regenerated it)Restore the identical original secret on both workers — check the Step 3 backups or the credentials file from setup.
migrations apply fails mid-fileUpstream migration bug or schema conflictSTOP (Step 5 rule): no deploy, no hand-editing; capture the error and the file name, report to the developer / upstream issue.
All wrangler commands fail Authentication error [code: 10000]Stale CLOUDFLARE_ACCOUNT_ID exported in the shellPrefix commands with env -u CLOUDFLARE_ACCOUNT_ID (see Prerequisites).
Local dev broken after update (missing tables)Local shared D1 not migratedcd cod-server && env -u CLOUDFLARE_ACCOUNT_ID npm run db:migrate:local — local state lives in <repo-root>/.wrangler-shared.

© bighadj22, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/codflow-update of bighadj22/codflow.

Open the folder on GitHubat commit ed79aa9

Compare with similar skills

Codflow Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codflow Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codflow Update this skillbighadj22/codflow346—~6.2kAutomated safety check: NotesApache-2.0
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
GreptimeDB Release RunbookGreptimeTeam/greptimedb6.7k—~1.4kAutomated safety check: PassApache-2.0
Observability Triageevery-app/open-seo23k—~1.7kAutomated safety check: PassMIT
Building MCP Server On CloudflareCommandCodeAI/agent-skills132—~1.5kAutomated safety check: PassMIT
Release Processscragnog/HOT-Step-CPP171—~5.1kAutomated safety check: PassMIT

Similar skills

  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Release Runbook

    GreptimeTeam/greptimedb

    Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.

    6.7k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Observability Triage

    every-app/open-seo

    Triage OpenSEO production errors in Cloudflare Workers Observability — verified query recipes, counting gotchas, and a known-noise filter list applied automatically.

    23k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Building MCP Server On Cloudflare

    CommandCodeAI/agent-skills

    Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment.

    132 GitHub stars~1.5k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Release Process

    scragnog/HOT-Step-CPP

    Runbook for cutting and publishing a HOT-Step CPP release via a v git tag that triggers the multi-platform CI build and drafts a GitHub Release.

    171 GitHub stars~5.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed

More from bighadj22/codflow

All 11 skills in this repo
  • Wires an app to the Yalidine (Guepex) Algerian courier API: parcels, zone lookups, delivery fees and verified delivery-status webhooks.

    346 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Bundles Meta's official Pixel and Conversions API documentation so tracking changes, event deduplication and conversion events are checked against the real spec.

    346 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • CodFlow Change Workflow

    bighadj22/codflow

    A step-by-step workflow for changing the CodFlow repository: read the AGENTS.md contract, respect package boundaries, verify before claiming done and keep PRs small.

    346 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Guides an agent through eight customer tools in a cash-on-delivery CRM for Algerian e-commerce: search, profiles, phone lookup, order history, groups, tags and deletion.

    346 GitHub stars~3.2k tokensUpdated 2 days ago
    Auto-check passed
  • Guides connecting and maintaining the EcoTrack courier adapter in CodFlow, one API shared by 82 Algerian couriers, using the official API reference and a rollout plan.

    346 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • defineRoute Route Builder

    bighadj22/codflow

    Creates new API endpoints, and converts older ones, with the defineRoute() pattern used in cod-server, including auth strategies, scopes and OpenAPI output.

    346 GitHub stars~924 tokensUpdated 2 days ago
    Auto-check passed

Questions about Codflow Update

What does Codflow Update do?

Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored…. Codflow Update is an agent skill from bighadj22/codflow.

When should I use Codflow Update?

Codflow Update fits situations like: the developer already set CodFlow up (via the codflow-setup skill) and wants to update; upgrade to the latest version from https://github.com/bighadj22/codflow (branch main); pull the latest changes/release; apply new migrations after pulling.

How do I install Codflow Update in Claude Code?

Run `npx skills add bighadj22/codflow --skill codflow-update -a claude-code`. Or copy the skill folder (.agents/skills/codflow-update in bighadj22/codflow) into .claude/skills/codflow-update in your project. Claude Code loads it when a task matches its description.

How do I install Codflow Update in Codex?

Run `npx skills add bighadj22/codflow --skill codflow-update -a codex`. Or copy the skill folder (.agents/skills/codflow-update in bighadj22/codflow) into .agents/skills/codflow-update in your project. Codex loads it when a task matches its description.

Can I use Codflow Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bighadj22/codflow --skill codflow-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codflow-update, .gemini/skills/codflow-update, .github/skills/codflow-update and .opencode/skills/codflow-update in your project.

What does Codflow Update need to run?

Going by SKILL.md and its folder, Codflow Update needs the command-line tools its instructions call (git, npm, wrangler and curl) and credentials named BETTER_AUTH_SECRET, MCP_LOGIN_TICKET_SECRET and STORE_API_KEY. Our summary lists: Node.js; A credential in BETTER_AUTH_SECRET; A credential in MCP_LOGIN_TICKET_SECRET.

Does Codflow Update access the network?

SKILL.md contains no URLs. Its commands use git, npm and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codflow Update safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Codflow Update use?

Codflow Update is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codflow Update use?

About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codflow Update?

Skills that share tags, products or a category with Codflow Update: Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), GreptimeDB Release Runbook (GreptimeTeam/greptimedb, 6.7k stars), Observability Triage (every-app/open-seo, 23k stars) and Building MCP Server On Cloudflare (CommandCodeAI/agent-skills, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codflow Update?

bighadj22 (a GitHub user) maintains it in bighadj22/codflow, which has 346 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 6, 2026.

Source: bighadj22/codflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.