Cloudflare Workers CD Rollback
mizchi/skills
GitHub Actions CD for Cloudflare Workers through cf with automatic traffic rollback on smoke failure, including JSON deployment snapshots, D1 migrations and prebuilt artifacts.
Agent skill
by LubomirGeorgiev in LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
$ npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LubomirGeorgiev/cloudflare-workers-nextjs-saas-template prepare-cloudflare-production-deployment --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/prepare-cloudflare-production-deployment .claude/skills/prepare-cloudflare-production-deployment && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "prepare-cloudflare-production-deployment" agent skill from https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template/tree/main/.agents/skills/prepare-cloudflare-production-deployment into .claude/skills/prepare-cloudflare-production-deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prepare-cloudflare-production-deployment", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template/tree/main/.agents/skills/prepare-cloudflare-production-deploymentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LubomirGeorgiev/cloudflare-workers-nextjs-saas-template prepare-cloudflare-production-deployment --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/prepare-cloudflare-production-deployment .agents/skills/prepare-cloudflare-production-deployment && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "prepare-cloudflare-production-deployment" agent skill from https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template/tree/main/.agents/skills/prepare-cloudflare-production-deployment into .agents/skills/prepare-cloudflare-production-deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prepare-cloudflare-production-deployment", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LubomirGeorgiev/cloudflare-workers-nextjs-saas-template prepare-cloudflare-production-deployment --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/prepare-cloudflare-production-deployment .cursor/skills/prepare-cloudflare-production-deployment && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "prepare-cloudflare-production-deployment" agent skill from https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template/tree/main/.agents/skills/prepare-cloudflare-production-deployment into .cursor/skills/prepare-cloudflare-production-deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prepare-cloudflare-production-deployment", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template.git --path .agents/skills/prepare-cloudflare-production-deployment--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LubomirGeorgiev/cloudflare-workers-nextjs-saas-template prepare-cloudflare-production-deployment --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/prepare-cloudflare-production-deployment .gemini/skills/prepare-cloudflare-production-deployment && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "prepare-cloudflare-production-deployment" agent skill from https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template/tree/main/.agents/skills/prepare-cloudflare-production-deployment into .gemini/skills/prepare-cloudflare-production-deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prepare-cloudflare-production-deployment", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LubomirGeorgiev/cloudflare-workers-nextjs-saas-template prepare-cloudflare-production-deploymentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/prepare-cloudflare-production-deployment .github/skills/prepare-cloudflare-production-deployment && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "prepare-cloudflare-production-deployment" agent skill from https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template/tree/main/.agents/skills/prepare-cloudflare-production-deployment into .github/skills/prepare-cloudflare-production-deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prepare-cloudflare-production-deployment", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LubomirGeorgiev/cloudflare-workers-nextjs-saas-template prepare-cloudflare-production-deployment --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/prepare-cloudflare-production-deployment .opencode/skills/prepare-cloudflare-production-deployment && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "prepare-cloudflare-production-deployment" agent skill from https://github.com/LubomirGeorgiev/cloudflare-workers-nextjs-saas-template/tree/main/.agents/skills/prepare-cloudflare-production-deployment into .opencode/skills/prepare-cloudflare-production-deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prepare-cloudflare-production-deployment", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
prepare-cloudflare-production-deploymentSource-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
Prepare Cloudflare Production Deployment is an agent skill from LubomirGeorgiev/cloudflare-workers-nextjs-saas-template. Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment. Use when setting up or auditing Cloudflare MCP resources, wrangler.jsonc bindings, Worker secrets, Turnstile, Email Sending, GitHub Actions secrets/variables, or GitHub CLI deployment wiring for this repository.
Its SKILL.md is about 5.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in DevOps & Cloud, covering Deployment, Transactional email and Runbooks and postmortems. It works with Cloudflare, Cloudflare Workers, Model Context Protocol and GitHub. The repository describes itself as: Cloudflare Workers/Next.js SaaS Template. The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8e0dbbf. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghpnpmwranglerFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
dash.cloudflare.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CLOUDFLARE_API_TOKENSTRIPE_SECRET_KEYTURNSTILE_SECRET_KEYGOOGLE_CLIENT_SECRETSTRIPE_WEBHOOK_SECRETNEXT_PUBLIC_STRIPE_PUBLISHABLE_KEYNEXT_PUBLIC_TURNSTILE_SITE_KEYTURNSTILE_SITE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Prepare Cloudflare Production Deployment loads about 5.9k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 2,826 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ipe:setup` needs `STRIPE_SECRET_KEY` in `.env`, refuses live keys unless `--live` is passed (required for production), aAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LubomirGeorgiev/cloudflare-workers-nextjs-saas-template at commit 8e0dbbf, republished under its MIT licence (© LubomirGeorgiev). 2,826 words, ~5,883 tokens.
.claude/skills/prepare-cloudflare-production-deployment/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill as the source of truth for production deployment. Cloudflare MCP must be used for Cloudflare account/resource discovery, verification, and supported mutations before using Wrangler, raw API calls, dashboard instructions, or assumptions. Use gh for GitHub repository secrets/variables; edit repo files directly for project branding, wrangler.jsonc, and workflow changes.
Never print secret values. Ask for missing secret values instead of inventing placeholders, and confirm before creating paid, destructive, or externally visible resources.
wrangler.jsonc, package.json, .github/workflows/deploy.yml, src/constants.ts, src/utils/root-metadata.ts, src/components/footer.tsx, AGENTS.md, and cms.config.ts when relevant.MCP availability gate before any Cloudflare mutation:gh auth status
gh repo view --json nameWithOwner,urlReport the Cloudflare account id/name/email from MCP and the GitHub account/repository from gh, then ask whether both are correct. Stop if the user says either account is wrong.
Confirm or remind the user about the required production customization checklist:
src/constants.ts has project details.SITE_URL from src/constants.ts, derive the hostname, and check the domains/zones available in the authenticated Cloudflare account. Tell the user which matching or closest Cloudflare zone/domain was found and ask them to confirm it before proceeding. If the SITE_URL domain is not available in Cloudflare, stop and ask the user which Cloudflare zone/domain to use or whether they need to add the domain to Cloudflare first.SITE_URL hostname belongs to a Cloudflare zone in the authenticated account and is proxied or attached as the Worker custom domain/route that production will use. Then verify the account-level Images API works for that account with /accounts/{account_id}/images/v1/variants or /accounts/{account_id}/images/v1/stats. If custom-domain image delivery is expected, explicitly confirm the production zone can serve Images URLs at https://<SITE_URL_HOSTNAME>/cdn-cgi/imagedelivery/<ACCOUNT_HASH>/<IMAGE_ID>/<VARIANT_NAME>; Cloudflare supports this only for customer domains under the same account as the Images account. If the domain is in a different account, not proxied through Cloudflare, or not the domain being deployed to, stop and ask which zone/domain should be used before proceeding.package.json, tell the user the current name value, and ask them to confirm it is the intended production project name. This value controls generated deploy-size metrics and package metadata, so do not proceed if it still identifies the reused template. If the name is still cloudflare-workers-nextjs-saas-template, stop and ask the user for the real project name and production domain before editing Cloudflare resources, queue names, bindings, or deployment metadata.wrangler.jsonc, especially queues.producers[].queue and queues.consumers[].queue. Queue names must be renamed to match the new production project name; do not leave template queue names such as cloudflare-workers-nextjs-saas-template-scheduler in a production project unless the user explicitly confirms that is the real project name.Email Sending procedure below: use the production SITE_URL zone, expect notifications.<SITE_URL_HOSTNAME>, and get user confirmation before Cloudflare or wrangler.jsonc changes.AGENTS.md has the project specification for AI coding agents.src/components/footer.tsx has project links and details.src/app/globals.css color palette has been reviewed.src/utils/root-metadata.ts metadata has project details; both root layouts read it.meta titles and descriptions in every locale catalog under src/i18n/messages/*.json (for example Client.Landing.meta, plus the auth, legal, and blog meta blocks) still default to template copy. Explicitly ask the user for the production titles and descriptions, and help them update these values in all locale catalogs, not only en.json.cms.config.ts has been reviewed and updated if needed.Collect required inputs:
Required configuration buckets.Follow Deployment Verification after deployment-related file or runtime configuration changes.
| Deployment task | Primary tool | Agent handling |
|---|---|---|
| Confirm production customization checklist | File reads and user confirmation | Required before deployment. Remind the user about any unchecked items and update files when they provide project details. |
Customize src/constants.ts, package.json, AGENTS.md, footer, palette, metadata, cms.config.ts | File edits | Automatable after project details are known. |
Update meta titles/descriptions in src/i18n/messages/*.json | File edits | Ask the user for production titles/descriptions, then update every locale catalog. |
| Create D1, KV, R2, or Queue resources | Cloudflare MCP | Use MCP patterns below: list by final production name, reuse exact matches, create only when approved, and write returned ids/names to wrangler.jsonc. Queue names must use the final project name. |
| Enable or verify Cloudflare Images | Cloudflare MCP | Verify both the account-level Images API and the production SITE_URL zone/domain. Billing acceptance may still require dashboard interaction. |
| Verify/onboard Email Sending and update sender config | Cloudflare MCP and file edits | Follow Email Sending. Verify the production-zone subdomain before file edits, and edit sender values only after user confirmation. |
| Create/update Turnstile widget | Cloudflare MCP, then dashboard if blocked | Follow the TURNSTILE_SECRET_KEY section: verify domains before reuse, preserve existing widget settings, and put site key/secret in the correct configuration buckets. |
Update wrangler.jsonc account id, bindings, vars, and project name | File edits | Automatable. Run pnpm run cf-typegen if bindings change. |
| Configure GitHub and Worker secrets/variables | gh, Cloudflare MCP, or wrangler.jsonc | Follow Required configuration buckets. GitHub Actions config and Worker runtime config are separate. |
Push to main and deploy | Git and GitHub Actions | Automatable only after user approval for push/deploy. Use gh run list, gh run watch, and gh run view --log-failed to monitor. |
Cloudflare MCP is not optional for Cloudflare operations. Always try it first for account/resource reads and supported writes. Wrangler, raw curl, and dashboard instructions are fallback paths only.
At the start of deployment prep, before any Cloudflare mutation:
Only continue with Wrangler/raw API/dashboard fallback after the user explicitly approves that fallback or MCP cannot support the needed product operation.
Use idempotent create-or-reuse behavior:
wrangler.jsonc.Common endpoint families to search and use:
Zones/domains: /zones
D1: /accounts/{account_id}/d1/database
KV: /accounts/{account_id}/storage/kv/namespaces
R2: /accounts/{account_id}/r2/buckets
Queues: /accounts/{account_id}/queues
Turnstile: /accounts/{account_id}/challenges/widgets
Worker secrets: /accounts/{account_id}/workers/scripts/{script_name}/secrets
API tokens: /accounts/{account_id}/tokens
Email Sending: /zones/{zone_id}/email/sending/subdomains
Images: /accounts/{account_id}/images/v1
Images variants and stats: /accounts/{account_id}/images/v1/variants, /accounts/{account_id}/images/v1/stats
Images custom-domain delivery check: resolve SITE_URL hostname to a same-account zone, then verify or document delivery through https://<hostname>/cdn-cgi/imagedelivery/<ACCOUNT_HASH>/<IMAGE_ID>/<VARIANT_NAME>
Cache purge: /zones/{zone_id}/purge_cacheWhen a Cloudflare step is blocked by billing, product enablement, token permissions, DNS propagation, or account approval, report the exact blocker and give the smallest dashboard action needed.
Do not print secret values in chat, logs, diffs, or command output. Secret creation/provisioning is a user-only manual step unless the secret is returned by an explicitly approved product API flow, such as creating a new Turnstile widget. Prefer secure prompts and never invent placeholders.
Before pushing or deploying through GitHub Actions, explicitly tell the user which values belong in each bucket and whether they already exist:
CLOUDFLARE_API_TOKEN; the user must create/provide it manually and paste it into the secure gh prompt.CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_ZONE_ID, enabled NEXT_PUBLIC_* values, and remember the deploy workflow auto-forwards repository NEXT_PUBLIC_* variables into the build.CLOUDFLARE_API_TOKEN, TURNSTILE_SECRET_KEY, STRIPE_SECRET_KEY, and GOOGLE_CLIENT_SECRET through secure prompts or supported MCP secret writes.CLOUDFLARE_ACCOUNT_ID in wrangler.jsonc under vars (see the CLOUDFLARE_ACCOUNT_ID section). Prefer vars for other stable values such as GOOGLE_CLIENT_ID; otherwise use Cloudflare MCP/dashboard/API.After setting repository configuration, verify without exposing values:
gh secret list --repo OWNER/REPO
gh variable list --repo OWNER/REPOAfter setting Worker secrets, verify behavior by exercising the relevant feature or checking the Worker dashboard secret names. Do not attempt to read secret values back.
CLOUDFLARE_API_TOKEN:
https://dash.cloudflare.com/profile/api-tokens.Account:AI Gateway:EditAccount:Workers AI:EditAccount:Workers AI:ReadAccount:Queues:EditAccount:Vectorize:EditAccount:D1:EditAccount:Cloudflare Images:EditAccount:Workers KV Storage:EditAccount:Email Sending:EditAccount:Turnstile Sites:Edit or Account:Turnstile Sites:Read plus dashboard access if only reading existing widgetsZone:Cache Purge:PurgeCLOUDFLARE_API_TOKEN for deploy, D1 migrations, and cache purge.CLOUDFLARE_API_TOKEN for the admin scheduled jobs page to preview Cloudflare Queue payloads, and for the admin "Purge Cloudflare CDN Cache" action. Native Queue binding metrics do not need this token, but payload preview and the purge do. The purge needs Zone:Cache Purge:Purge, resolves its zone from the Workers domain of the site host, and is hidden in the panel when the token is absent.gh secret set CLOUDFLARE_API_TOKEN --repo OWNER/REPOPaste the token only into the secure gh prompt. Verify the secret exists with:
gh secret list --repo OWNER/REPOpnpm wrangler secret put CLOUDFLARE_API_TOKENCLOUDFLARE_ACCOUNT_ID:
CLOUDFLARE_ACCOUNT_ID as a GitHub Actions variable for deploy/migrations:gh variable set CLOUDFLARE_ACCOUNT_ID --body "$ACCOUNT_ID" --repo OWNER/REPOSet CLOUDFLARE_ACCOUNT_ID in wrangler.jsonc under vars, with the same value as the top-level account_id. The deployed Worker needs it for these features:
getWorkerZoneId (src/lib/cloudflare-api.ts). Without the var, the lookup fails with a getWorkerZoneId: zone lookup failed warning. The CMS publish then purges stored HTML only in one data center, and the admin "Purge Cloudflare CDN Cache" action is hidden. Setting CLOUDFLARE_ZONE_ID skips this lookup.Do not set it as a Worker secret. The account id is not a secret, and a secret with the same name as a vars entry makes wrangler deploy fail. If a Worker secret CLOUDFLARE_ACCOUNT_ID already exists, delete it before the deploy that adds the var:
pnpm wrangler secret delete CLOUDFLARE_ACCOUNT_IDgetWorkerZoneId: zone lookup failed warning after a CMS publish.TURNSTILE_SECRET_KEY:
First determine whether Turnstile is enabled by inspecting src/flags.ts, forms using src/components/captcha.tsx, and the presence of TURNSTILE_SECRET_KEY in the target environment. If disabled, say the Turnstile values are optional until the feature is enabled.
Prefer reusing an intended existing widget only when its name and allowed domains match the production hostname. Do not copy a site key from another repo or environment unless the user confirms the widget is intended for the new production hostname.
If Cloudflare MCP/API execution is available, use docs search before execute, then list/inspect/update widgets through /accounts/{account_id}/challenges/widgets. Preserve existing widget settings and domains; add the production hostname only after user confirmation because this changes an externally visible security control.
If Cloudflare MCP/API execution is not available or the token lacks Turnstile permissions, this is a user-only manual step. Do not keep retrying with Wrangler or unrelated APIs. Tell the user that the active Cloudflare MCP/API token needs Turnstile Sites Write or Account Settings Write to update widgets automatically; without that permission, they must add the hostname manually in the dashboard:
https://dash.cloudflare.com/?to=/:account/turnstile.0x4AAAAAAA5QtwiAltpKMppM, or click Add widget if creating a new one.SITE_URL, for example test-nextjs-saas-template.lubomirgeorgiev.com.Set the public sitekey as a GitHub repository variable so GitHub Actions can inject it into the production build:
gh variable set NEXT_PUBLIC_TURNSTILE_SITE_KEY --body "$TURNSTILE_SITE_KEY" --repo OWNER/REPO
gh variable list --repo OWNER/REPOpnpm wrangler secret put TURNSTILE_SECRET_KEYTURNSTILE_SECRET_KEY stops working for that widget once rotation takes effect.STRIPE_SECRET_KEY, NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY, STRIPE_WEBHOOK_SECRET, and the plan price IDs:
STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, and NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY are all set (see isBillingEnabled() in src/flags.ts).NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY and the plan price IDs (STRIPE_PRICE_PRO, STRIPE_PRICE_ENTERPRISE) as GitHub repository variables so the production build receives them. If the price IDs do not exist yet, ask the user whether the agent should run pnpm stripe:setup on their behalf or whether they prefer to run it themselves; do not run it without confirmation because it creates products and prices in their Stripe account. If they choose the manual route, give them the exact command and flags: pnpm stripe:setup needs STRIPE_SECRET_KEY in .env, refuses live keys unless --live is passed (required for production), and supports --dry-run to preview.STRIPE_SECRET_KEY and STRIPE_WEBHOOK_SECRET as Worker runtime secrets with pnpm wrangler secret put STRIPE_SECRET_KEY and pnpm wrangler secret put STRIPE_WEBHOOK_SECRET. The webhook secret comes from the Stripe webhook endpoint for /api/stripe/webhook. Do not add Stripe secret keys to GitHub Actions secrets unless the workflow is explicitly changed to sync them into Worker secrets.SITE_URL_HOSTNAME from src/constants.ts and the expected sending subdomain notifications.<SITE_URL_HOSTNAME>.SITE_URL_HOSTNAME to list /zones/{zone_id}/email/sending/subdomains. Confirm notifications.<SITE_URL_HOSTNAME> exists and is enabled. Do not assume a subdomain on a different zone (for example the template's old domain) satisfies production requirements.wrangler.jsonc email settings: vars.EMAIL_FROM, vars.EMAIL_FROM_NAME, vars.EMAIL_REPLY_TO, and send_email[].allowed_sender_addresses.notifications.<SITE_URL_HOSTNAME> and explicitly ask the user to confirm they are ok with it.no-reply@notifications.<SITE_URL_HOSTNAME> and explicitly ask the user to confirm they are ok with it.vars.EMAIL_FROM_NAME; explicitly ask the user what production sender display name to use, even if wrangler.jsonc already has a value.vars.EMAIL_REPLY_TO; explicitly ask the user what production reply-to address to use, even if wrangler.jsonc already has a value.POST /zones/{zone_id}/email/sending/subdomains with { "name": "notifications.<SITE_URL_HOSTNAME>" }), then use preview/fix/status endpoints until DNS is healthy.wrangler.jsonc:vars.EMAIL_FROMvars.EMAIL_FROM_NAMEvars.EMAIL_REPLY_TOsend_email[].allowed_sender_addresses to include EMAIL_FROMpnpm run cf-typegen after wrangler.jsonc email var changes.GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET:
https://<SITE_URL_HOSTNAME>/sso/google/callback.GOOGLE_CLIENT_ID as a Worker runtime variable, preferably under vars in wrangler.jsonc for stable project config. This value is not secret, but the user should still confirm it belongs to the intended Google OAuth client.GOOGLE_CLIENT_SECRET as a Worker runtime secret with pnpm wrangler secret put GOOGLE_CLIENT_SECRET. The user must paste the secret manually into the secure Wrangler prompt; never print it in chat.Prefer gh for repository secrets/variables. Use gh secret set from stdin or an environment variable when handling sensitive values, and do not place secrets in shell history or command output. Do not add individual NEXT_PUBLIC_* entries to .github/workflows/deploy.yml; the deploy workflow already forwards repository variables with that prefix.
Apply the repo rules from AGENTS.md:
wrangler.jsonc, not worker-configuration.d.ts; run pnpm run cf-typegen after binding changes..github/workflows/deploy.yml, src/flags.ts, and integrations before deciding which GitHub variables/secrets are needed.Deployment Verification when deployment-related files change and time permits.After configuration:
pnpm run lint
pnpm run typecheck
pnpm run check:vinext
pnpm run buildgh run list --workflow deploy.yml --limit 5
gh run watch RUN_ID --exit-status
gh run view RUN_ID --log-failed© LubomirGeorgiev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/prepare-cloudflare-production-deployment of LubomirGeorgiev/cloudflare-workers-nextjs-saas-template.
Open the folder on GitHubat commit 8e0dbbf
Prepare Cloudflare Production Deployment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Prepare Cloudflare Production Deployment this skillLubomirGeorgiev/cloudflare-workers-nextjs-saas-template | 786 | — | ~5.9k | Automated safety check: Notes | MIT | |
| Cloudflare Workers CD Rollbackmizchi/skills | 360 | — | ~1.2k | Automated safety check: Notes | None | |
| Codflow Updatebighadj22/codflow | 354 | — | ~6.2k | Automated safety check: Notes | Apache-2.0 | |
| Cloudflare Workers CI CDsecondsky/claude-skills | 227 | — | ~4k | Automated safety check: Pass | MIT | |
| Cloudflare PagesaAAaqwq/AGI-Super-Team | 105 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Deploy Agentsundial-org/awesome-openclaw-skills | 663 | — | ~1.6k | Automated safety check: Pass | None |
mizchi/skills
GitHub Actions CD for Cloudflare Workers through cf with automatic traffic rollback on smoke failure, including JSON deployment snapshots, D1 migrations and prebuilt artifacts.
bighadj22/codflow
Update runbook for a self-hosted CodFlow install — an AI agent following it fetches the latest code from the CodFlow GitHub repo, merges it into an EXISTING checkout, syncs the gitignored…
secondsky/claude-skills
Complete CI/CD guide for Cloudflare Workers using GitHub Actions and GitLab CI.
aAAaqwq/AGI-Super-Team
Deploy static sites to Cloudflare Pages with custom domains and CI/CD.
sundial-org/awesome-openclaw-skills
Multi-step deployment agent for full-stack apps. An agent skill from sundial-org/awesome-openclaw-skills.
cloudflare/skills
Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.
Categories
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment. Prepare Cloudflare Production Deployment is an agent skill from LubomirGeorgiev/cloudflare-workers-nextjs-saas-template. Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
Prepare Cloudflare Production Deployment fits situations like: auditing Cloudflare MCP resources; wrangler.jsonc bindings; GitHub Actions secrets/variables; GitHub CLI deployment wiring for this repository.
Run `npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a claude-code`. Or copy the skill folder (.agents/skills/prepare-cloudflare-production-deployment in LubomirGeorgiev/cloudflare-workers-nextjs-saas-template) into .claude/skills/prepare-cloudflare-production-deployment in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a codex`. Or copy the skill folder (.agents/skills/prepare-cloudflare-production-deployment in LubomirGeorgiev/cloudflare-workers-nextjs-saas-template) into .agents/skills/prepare-cloudflare-production-deployment in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LubomirGeorgiev/cloudflare-workers-nextjs-saas-template --skill prepare-cloudflare-production-deployment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/prepare-cloudflare-production-deployment, .gemini/skills/prepare-cloudflare-production-deployment, .github/skills/prepare-cloudflare-production-deployment and .opencode/skills/prepare-cloudflare-production-deployment in your project.
Going by SKILL.md and its folder, Prepare Cloudflare Production Deployment needs the command-line tools its instructions call (gh, pnpm and wrangler) and credentials named CLOUDFLARE_API_TOKEN, STRIPE_SECRET_KEY, TURNSTILE_SECRET_KEY and GOOGLE_CLIENT_SECRET. Our summary lists: A credential in TURNSTILE_SECRET_KEY; A credential in CLOUDFLARE_API_TOKEN.
SKILL.md names 1 domain. In commands or code: dash.cloudflare.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Prepare Cloudflare Production Deployment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.9k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Prepare Cloudflare Production Deployment: Cloudflare Workers CD Rollback (mizchi/skills, 360 stars), Codflow Update (bighadj22/codflow, 354 stars), Cloudflare Workers CI CD (secondsky/claude-skills, 227 stars) and Cloudflare Pages (aAAaqwq/AGI-Super-Team, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LubomirGeorgiev (a GitHub user) maintains it in LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, which has 786 GitHub stars. The repository was last updated on October 9, 2026.
Source: LubomirGeorgiev/cloudflare-workers-nextjs-saas-template on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.