Agent skill

Cloudflare Deploy

by mizchi in mizchi/skills

Deploy applications and infrastructure to Cloudflare with the cf CLI and typed cloudflare.config.ts.

Apache-2.0Auto-check: notesDevOps & Cloud

Install Cloudflare Deploy

skills CLI
$ npx skills add mizchi/skills --skill cloudflare-deploy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mizchi/skills cloudflare-deploy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mizchi/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cloudflare-deploy .claude/skills/cloudflare-deploy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare-deploy
GitHub stars
356
Token cost
~2.9k tokens
SKILL.md length
709 words
Files
373 (incl. references, assets)
Skills in repo
69
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploy applications and infrastructure to Cloudflare with the cf CLI and typed cloudflare.config.ts.

  • Deploying Workers
  • SKILL.md covers Prerequisites, Authentication (Required…, Discover Commands Before… and When to Read references/, plus 4 more sections
  • Calls pnpm; needs API_SECRET and CLOUDFLARE_API_TOKEN
  • Migrating a Wrangler project to cf

What it does

Cloudflare Deploy is an agent skill from mizchi/skills. Deploy applications and infrastructure to Cloudflare with the cf CLI and typed cloudflare.config.ts. Use when deploying Workers, migrating a Wrangler project to cf, or setting up Cloudflare resources and CI.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 377 other files, including reference files and assets (for example `README.md`, `agents/openai.yaml` and `references/agents-sdk/README.md`).

It sits in DevOps & Cloud. It works with Cloudflare and Cloudflare Workers. The repository describes itself as: Agent skills by mizchi, distributed via APM. The licence is Apache-2.0.

When your agent uses it

  • Deploying Workers
  • Migrating a Wrangler project to cf
  • Setting up Cloudflare resources and CI

Example prompts

  • “/cloudflare-deploy”

Requirements

  • Node.js
  • A credential in CLOUDFLARE_API_TOKEN
  • A credential in API_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 62f5808. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_SECRET
    • CLOUDFLARE_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudflare Deploy loads about 2.9k tokens when it runs, and up to ~345k if it reads all its reference files. Until then it costs about 56 tokens; SKILL.md has 709 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~345k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:93
    exec cf deploy --dry-run --secrets-file .env.production
  • NoteMentions a .env fileSKILL.md:94
    pnpm exec cf deploy --secrets-file .env.production
  • NoteMentions a .env fileSKILL.md:97
    Put `API_SECRET` in an ignored `.env.production` for deployment and `.dev.vars` for local development. Declaring `bindin

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mizchi/skills at commit 62f5808, republished under its Apache-2.0 licence (© mizchi). 709 words, ~2,859 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare-deploy/SKILL.md (or your agent's skills folder). This skill also uses 372 other files; get the full folder from GitHub.
name
cloudflare-deploy
description
Deploy applications and infrastructure to Cloudflare with the cf CLI and typed cloudflare.config.ts. Use when deploying Workers, migrating a Wrangler project to cf, or setting up Cloudflare resources and CI.

Cloudflare Deploy

Use cf for Cloudflare operations. Use the decision trees below to pick a product, then read its runtime/API references and the current cf CLI guide.

Prerequisites

  • Node.js 24+ and pnpm. Install the npm package cf, not @cloudflare/cf.
  • Keep cf in project devDependencies and commit the lockfile. The checked example uses cf@1.0.0-beta.5 and @cloudflare/vite-plugin@beta; recheck help and types when upgrading.
  • Workers use cloudflare.config.ts. For an existing Wrangler project, run cf migrate --dry-run, then cf migrate and resolve its follow-up items before project commands. Automatic configuration does not import the old bindings.

Authentication (Required Before Deploy)

Verify auth before publishing or mutating account resources:

bash
pnpm exec cf auth whoami

See authentication. Use pnpm exec cf auth login locally; cf has its own login credentials. In CI set CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID. A deploy dry run needs no credentials.

Discover Commands Before Running Them

bash
pnpm exec cf cli search "create a D1 database"
pnpm exec cf schema d1 create
pnpm exec cf d1 create --help

Describe only the operation and resource type in search queries. Pass names and IDs to the discovered command, not to search. API commands return JSON on stdout and progress on stderr. Resource commands usually use IDs and remote data; inspect --local support instead of copying Wrangler's --remote, --env, --json, or --yes flags.

When to Read references/

Current CLI, migration, configuration and build guidance lives in references/cf/. Product references retain SDK and runtime knowledge; files marked as legacy preserve old CLI/config examples only as migration input. Do not execute those Wrangler examples or generate new Wrangler configuration from them. Translate the intended operation using cf search/schema and typed bindings.

Rules of thumb:

  • Picking a product? Use decision trees below, then load references/<picked-product>/
  • Writing cloudflare.config.ts? Read configuration first.
  • CI/CD setup? Read GitHub Actions.
  • Deploy fails? Read cf gotchas, then the product's runtime gotchas.
  • The minimal example below covers Workers + KV + secret — for anything beyond that, descend into references

Minimal Worker Example (copy-paste starter)

Start with this Worker, one KV binding and one secret. Apply the TypeScript setup from the configuration reference before typechecking:

ts
// cloudflare.config.ts
import { bindings, defineConfig } from "cf/config";
import * as entrypoint from "./src/index.ts" with { type: "cf-worker" };

export default defineConfig({
  worker: {
    name: "my-worker",
    entrypoint,
    compatibilityDate: "2026-09-30", // Today's date for a new Worker
    observability: { enabled: true },
    env: {
      CACHE: bindings.kv({ id: "REPLACE_WITH_KV_ID" }),
      API_SECRET: bindings.secret(),
    },
  },
});
ts
// vite.config.ts
import { cloudflare } from "@cloudflare/vite-plugin";
import { defineConfig } from "vite";
export default defineConfig({ plugins: [cloudflare()] });
ts
// src/index.ts
export default {
  async fetch(req: Request, env: Env): Promise<Response> {
    const hit = await env.CACHE.get("greeting");
    return new Response(hit ?? "hello");
  }
} satisfies ExportedHandler<Env>;

Bootstrap commands:

bash
pnpm add -D cf @cloudflare/vite-plugin@beta vite typescript
pnpm exec cf kv namespaces create --title CACHE # Copy the returned ID into config
pnpm exec cf workers types                      # Generates .cloudflare/types/index.d.ts
pnpm exec cf dev                                # Vite reports the local URL
pnpm exec cf deploy --dry-run --secrets-file .env.production
pnpm exec cf deploy --secrets-file .env.production

Put API_SECRET in an ignored .env.production for deployment and .dev.vars for local development. Declaring bindings.secret() makes that value required at deploy validation; dotenvx values in the CLI process are not automatically Worker secrets. Include .cloudflare/types in tsconfig.json; see the configuration reference for the full TypeScript setup. Change an existing Worker's compatibility date deliberately.

Live log streaming and legacy Pages asset deployment are not implemented in the checked cf beta, even when a command appears in search/help. Use Workers Logs in the dashboard for inspection and Workers static assets for new web projects. For a legacy Pages project, keep its deployment working while planning migration; do not invent a cf pages deploy replacement. See limitations.

For Pages / D1 / Durable Objects / multi-env / CI — descend into references/.

Show full SKILL.md (265 more words)Show less

Quick Decision Trees

"I need to run code"
Need to run code?
├─ Serverless functions at the edge → workers/
├─ Full-stack web app with Git deploys → workers/ (framework) + static-assets/
├─ Maintain or migrate an existing Pages app → pages/ (legacy reference)
├─ Stateful coordination/real-time → durable-objects/
├─ Long-running multi-step jobs → workflows/
├─ Run containers → containers/
├─ Multi-tenant (customers deploy code) → workers-for-platforms/
├─ Scheduled tasks (cron) → cron-triggers/
├─ Lightweight edge logic (modify HTTP) → snippets/
├─ Process Worker execution events (logs/observability) → tail-workers/
└─ Optimize latency to backend infrastructure → smart-placement/
"I need to store data"
Need storage?
├─ Key-value (config, sessions, cache) → kv/
├─ Relational SQL → d1/ (SQLite) or hyperdrive/ (existing Postgres/MySQL)
├─ Object/file storage (S3-compatible) → r2/
├─ Message queue (async processing) → queues/
├─ Vector embeddings (AI/semantic search) → vectorize/
├─ Strongly-consistent per-entity state → durable-objects/ (DO storage)
├─ Secrets management → secrets-store/
├─ Streaming ETL to R2 → pipelines/
└─ Persistent cache (long-term retention) → cache-reserve/
"I need AI/ML"
Need AI?
├─ Run inference (LLMs, embeddings, images) → workers-ai/
├─ Vector database for RAG/search → vectorize/
├─ Build stateful AI agents → agents-sdk/
├─ Gateway for any AI provider (caching, routing) → ai-gateway/
└─ AI-powered search widget → ai-search/
"I need networking/connectivity"
Need networking?
├─ Expose local service to internet → tunnel/
├─ TCP/UDP proxy (non-HTTP) → spectrum/
├─ WebRTC TURN server → turn/
├─ Private network connectivity → network-interconnect/
├─ Optimize routing → argo-smart-routing/
├─ Optimize latency to backend (not user) → smart-placement/
└─ Real-time video/audio → realtimekit/ or realtime-sfu/
"I need security"
Need security?
├─ Web Application Firewall → waf/
├─ DDoS protection → ddos/
├─ Bot detection/management → bot-management/
├─ API protection → api-shield/
├─ CAPTCHA alternative → turnstile/
└─ Credential leak detection → waf/ (managed ruleset)
"I need media/content"
Need media?
├─ Image optimization/transformation → images/
├─ Video streaming/encoding → stream/
├─ Browser automation/screenshots → browser-rendering/
└─ Third-party script management → zaraz/
"I need infrastructure-as-code"
Need IaC? → pulumi/ (Pulumi), terraform/ (Terraform), or api/ (REST API)

Product Index

Compute & Runtime
ProductReference
Workersreferences/workers/
Pagesreferences/pages/
Pages Functionsreferences/pages-functions/
Durable Objectsreferences/durable-objects/
Workflowsreferences/workflows/
Containersreferences/containers/
Workers for Platformsreferences/workers-for-platforms/
Cron Triggersreferences/cron-triggers/
Tail Workersreferences/tail-workers/
Snippetsreferences/snippets/
Smart Placementreferences/smart-placement/
Storage & Data
ProductReference
KVreferences/kv/
D1references/d1/
R2references/r2/
Queuesreferences/queues/
Hyperdrivereferences/hyperdrive/
DO Storagereferences/do-storage/
Secrets Storereferences/secrets-store/
Pipelinesreferences/pipelines/
R2 Data Catalogreferences/r2-data-catalog/
R2 SQLreferences/r2-sql/
AI & Machine Learning
ProductReference
Workers AIreferences/workers-ai/
Vectorizereferences/vectorize/
Agents SDKreferences/agents-sdk/
AI Gatewayreferences/ai-gateway/
AI Searchreferences/ai-search/
Networking & Connectivity
ProductReference
Tunnelreferences/tunnel/
Spectrumreferences/spectrum/
TURNreferences/turn/
Network Interconnectreferences/network-interconnect/
Argo Smart Routingreferences/argo-smart-routing/
Workers VPCreferences/workers-vpc/
Security
ProductReference
WAFreferences/waf/
DDoS Protectionreferences/ddos/
Bot Managementreferences/bot-management/
API Shieldreferences/api-shield/
Turnstilereferences/turnstile/
Media & Content
ProductReference
Imagesreferences/images/
Streamreferences/stream/
Browser Renderingreferences/browser-rendering/
Zarazreferences/zaraz/
Real-Time Communication
ProductReference
RealtimeKitreferences/realtimekit/
Realtime SFUreferences/realtime-sfu/
Developer Tools
ProductReference
cf CLIreferences/cf/
Miniflarereferences/miniflare/
C3references/c3/
Observabilityreferences/observability/
Analytics Enginereferences/analytics-engine/
Web Analyticsreferences/web-analytics/
Sandboxreferences/sandbox/
Workerdreferences/workerd/
Workers Playgroundreferences/workers-playground/
Infrastructure as Code
ProductReference
Pulumireferences/pulumi/
Terraformreferences/terraform/
APIreferences/api/
Other Services
ProductReference
Email Routingreferences/email-routing/
Email Workersreferences/email-workers/
Static Assetsreferences/static-assets/
Bindingsreferences/bindings/
Cache Reservereferences/cache-reserve/

Troubleshooting

Escalated Network Access

If deployment fails due to network issues (timeouts, DNS errors, connection resets), rerun the deploy with escalated permissions (use sandbox_permissions=require_escalated). The deploy requires escalated network access when sandbox networking blocks outbound requests.

Example guidance to the user:

The deploy needs escalated network access to deploy to Cloudflare. I can rerun the command with escalated permissions—want me to proceed?

© mizchi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 372 other files (references, assets) in cloudflare-deploy of mizchi/skills.

  • SKILL.md
  • LICENSE.txt
  • README.md
  • agents/openai.yaml
  • assets/cloudflare-small.svg
  • assets/cloudflare.png
  • references/agents-sdk/README.md
  • references/agents-sdk/api.md
  • references/agents-sdk/configuration.md
  • references/agents-sdk/gotchas.md
  • references/agents-sdk/patterns.md
  • references/ai-gateway/README.md
  • references/ai-gateway/configuration.md
  • references/ai-gateway/dynamic-routing.md
  • references/ai-gateway/features.md
  • references/ai-gateway/sdk-integration.md
  • … and 357 more

Open the folder on GitHubat commit 62f5808

Compare with similar skills

Cloudflare Deploy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare Deploy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare Deploy this skillmizchi/skills356—~2.9kAutomated safety check: NotesApache-2.0
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Nextjs On Cloudflarecloudflare/skills3k2 repos~678Automated safety check: PassApache-2.0
Cloudflaredmmulroy/cloudflare-skill728—~1.6kAutomated safety check: PassMIT
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
Workers Best Practicescloudflare/skills3k2 repos~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Nextjs On Cloudflare

    cloudflare/skills

    Official

    Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.

    3k GitHub starsUsed in 2 repos~678 tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    728 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Workers Best Practices

    cloudflare/skills

    Official

    Cloudflare Workers best practices for production applications.

    3k GitHub starsUsed in 2 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • Observability Triage

    every-app/open-seo

    Triage OpenSEO production errors in Cloudflare Workers Observability — verified query recipes, counting gotchas, and a known-noise filter list applied automatically.

    23k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from mizchi/skills

All 69 skills in this repo
  • Publish Agent Skill

    mizchi/skills

    Package, publish, verify and update an agent skill through a Claude Code plugin marketplace, APM or the npx skills CLI.

    356 GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • AI Index

    mizchi/skills

    Method and tooling for measuring how AI-generated a piece of prose reads, in Japanese or English.

    356 GitHub stars~3.6k tokensUpdated 5 days ago
    Auto-check passed
  • Review Image

    mizchi/skills

    Review screenshots or other images with OpenRouter vision models via bundled Deno scripts.

    356 GitHub stars~1.3k tokensUpdated 5 days ago
    Auto-check passed
  • Post-generation safety checks for sqlc-gen-moonbit + Cloudflare D1.

    356 GitHub stars~995 tokensUpdated 5 days ago
    Auto-check passed
  • Apm Usage

    mizchi/skills

    Reference for APM (Agent Package Manager) — apm.yml syntax, install / uninstall / update commands, target detection, lockfile workflow.

    356 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed
  • Ast Grep Practice

    mizchi/skills

    Operate ast-grep as a project lint tool. An agent skill from mizchi/skills.

    356 GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Cloudflare Deploy

What does Cloudflare Deploy do?

Deploy applications and infrastructure to Cloudflare with the cf CLI and typed cloudflare.config.ts. Cloudflare Deploy is an agent skill from mizchi/skills.ts.

When should I use Cloudflare Deploy?

Cloudflare Deploy fits situations like: deploying Workers; migrating a Wrangler project to cf; setting up Cloudflare resources and CI.

How do I install Cloudflare Deploy in Claude Code?

Run `npx skills add mizchi/skills --skill cloudflare-deploy -a claude-code`. Or copy the skill folder (cloudflare-deploy in mizchi/skills) into .claude/skills/cloudflare-deploy in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare Deploy in Codex?

Run `npx skills add mizchi/skills --skill cloudflare-deploy -a codex`. Or copy the skill folder (cloudflare-deploy in mizchi/skills) into .agents/skills/cloudflare-deploy in your project. Codex loads it when a task matches its description.

Can I use Cloudflare Deploy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mizchi/skills --skill cloudflare-deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-deploy, .gemini/skills/cloudflare-deploy, .github/skills/cloudflare-deploy and .opencode/skills/cloudflare-deploy in your project.

What does Cloudflare Deploy need to run?

Going by SKILL.md and its folder, Cloudflare Deploy needs the command-line tools its instructions call (pnpm) and credentials named API_SECRET and CLOUDFLARE_API_TOKEN. Our summary lists: Node.js; A credential in CLOUDFLARE_API_TOKEN; A credential in API_SECRET.

Does Cloudflare Deploy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cloudflare Deploy safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cloudflare Deploy use?

Cloudflare Deploy is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare Deploy use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 342k tokens, read only when the agent opens those files.

What are the alternatives to Cloudflare Deploy?

Skills that share tags, products or a category with Cloudflare Deploy: Cloudflare (hodgef/apiker, 127 stars), Nextjs On Cloudflare (cloudflare/skills, 3k stars), Cloudflare (dmmulroy/cloudflare-skill, 728 stars) and Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare Deploy?

mizchi (a GitHub user) maintains it in mizchi/skills, which has 356 GitHub stars. The repository holds 69 skills in this directory. The repository was last updated on October 2, 2026.

Source: mizchi/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.