Your OpenCode agent that only speaks Cloudflare. No VPS, no Docker, no self-hosted databases — if it can’t cf deploy, cfadmin won’t build it that way. It refuses the wrong shape and hands you the Cloudflare-native design instead. Now cf-first: the agentic cf CLI open beta + cloudflare.config.ts.
Static docs at root + one Pages Function via env.ASSETS with exact Content-Types — zone content_converter needs a paid plan (Free PATCH → 1015), code wins anyway: versioned, locally testable.
Gotchas banked: deploy Pages production with --branch main; scanner rejects emptyauthorization_servers/scopes_supported; anonymous agent_auth needs claim_uri; never advertise OAuth endpoints that don't implement the protocol.
Keep it updated: index.md ↔ index.html, catalog on API changes, sitemap lastmod on publish/remove.
Merge mcp.cloudflare.json into your opencode.jsonc, complete OAuth on first use.
Restart OpenCode, verify with opencode agent list (expect cfadmin).
Recommended companion: Cloudflare’s security-audit-skill as a pre-deploy gate.
✔ Verification record
measured, not claimed
RED battery 5/5 REDIRECT — every skill refused a hurried non-Cloudflare demand (Docker+Postgres, VPS+systemd, Flask+pgvector, nginx+certbot) and redirected to the native design.
Deploy smoke test green — scratch Worker: wrangler types → wrangler dev → live deploy (both routes HTTP 200) → wrangler delete, account left clean.
Install validated on a second host — README steps executed verbatim found and fixed the missing mkdir -p.
Gotcha banked:compatibility_date newer than the bundled workerd breaks wrangler dev — pin at or below local runtime max.
Abuse gate proven (smartass): Turnstile siteverify on all paid POSTs — tokenless POST → 403, real-browser flow passes, demo stays public. The gate runs before every deploy with paid routes.
Worker Previews covered:wrangler preview per-branch isolation (Wrangler 4.135+) — DO/Containers auto-isolate, KV/D1/R2 rebound per Preview, Workflows/consumers/cron stay on prod. Version URLs are prod-only, never for branches.
Audit gate proven (smartass): first full security-audit run — 3 confirmed, 3 needs-validation, 1 correctly rejected. New projects get audited before their first upload.