⚡ New: cf CLI, open beta (28 Sep 2026)
What changed How cfadmin uses it
Entire API as commands cf d1 · kv · r2 · queues · workers · zones · dns · tunnels …
JSON by default pretty for humans, -q condensed for agents · no tables to parse
cf cli search natural-language discovery → 5 JSON matches → --help → cf schema
cloudflare.config.ts defineConfig + bindings.* + triggers.* · LSP-checked · mode envs
Vite default cf init / dev / deploy · HMR + Rolldown · Vitest plugin
cf migrate Wrangler → cf · wrangler kept as beta fallback (18-mo maintenance)
copy npm i -g cf
cf cli search "list D1 databases"
cf init && cf dev && cf deploy
▲ New: Vinext 1.0 — Next.js on Vite (28 Sep 2026)
What changed How cfadmin uses it
Drop-in Next.js on Vite keep app/ · pages/ · next.config.js · RSC · Server Actions · middleware
Full page lifecycle SSR · prerender · output export · page-level ISR (Workers Cache + KV)
Cache warming deploy to 0% traffic → warm high-traffic pages → promote
One-command migrate npx vinext check && npx vinext init (next dev keeps working)
copy npm create vinext-app@latest my-app
npx vinext check && npx vinext init
npx @vinext/cloudflare deploy --warm-cache
🪁 New: Kitesurf update — agentic browser (28 Sep 2026)
Workers-native browser for agents · WebMCP · full Browser Run coverage · free in beta ·
kitesurf.dev
What changed How cfadmin uses it
WebMCP support call searchFlights() style tools, not pixel clicks · one-switch site enablement
Full Browser Run API CDP · Playwright · Puppeteer · MCP · Quick Actions + BROWSER binding
730k+ WPT subtests CSS layout/OM · custom elements · import maps · iframes (+500k since launch)
Agent-tuned efficiency 3–7× less CPU/mem than Chromium · Wasm DOM reads · lazy fonts
Terminal rendering brew install cloudflare/cloudflare/kitesurf · Kitty + ANSI · scroll/click
copy cf browser-run quick-action screenshot --help
kitesurf https://example.com
✒ New: EmDash 1.0 — CMS on Workers (28 Sep 2026)
What changed How cfadmin uses it
WordPress successor, stable Astro SSR · passkey admin · runs the Cloudflare Blog (M views/wk)
Agent-friendly content layer admin UI · API/CLI · MCP server · EmDash Agent Skills
Sandboxed plugins declared abilities only · Dynamic Workers / workerd · decentralized registry
One-command scaffold npm create emdash@latest → Workers / Workers for Platforms
copy npm create emdash@latest
# deploy: Workers (KV cache · Hyperdrive) or --dispatch-namespace
🗄 New: Basin GA + K2 streams + KV Instant (Birthday Week, Oct 2026)
What changed How cfadmin uses it
Basin GA (ex-Data Platform) OLAP on open Iceberg tables, zero egress — D1 stays OLTP
Basin Pipelines / Catalog / SQL ingest via bindings+HTTP+Logpush → Iceberg REST (Spark/Snowflake/DuckDB) → serverless SQL ($2.50/TB scanned)
K2 event streams on R2 durable ordered logs, no Kafka to run · Queues = tasks, K2 = replayable logs
KV Instant (Quicksilver) sub-2ms p99 reads, 250ms global replication, same KV API
copy cf cli search "basin pipelines create"
npx wrangler basin sql query my-warehouse "SELECT * FROM default.events LIMIT 10"
🧠 New: AI Gateway search/router/insights + Clef + AI Search GA (Birthday Week, Oct 2026)
What changed How cfadmin uses it
Web Search API (beta) env.AI.websearch() or REST via Gateway · Ceramic/Exa/Linkup · BYOK · web_search tool pattern
Auto Router cloudflare/auto picks the model per request · cf-aig-allowed-* scope · routing-reason headers
User Insights (free) task/model/turn analytics · Potential Savings view · per-user spend + anomaly
Clef decision models @cf/cloudflare/clef[-flash] for classify-then-route · RL fine-tune on team data
AI Search GA visual embeddings · PDF OCR · 10 MiB files · any chat model · managed over hand-rolled RAG
copy const r = await env.AI.websearch({ gatewayId: "default", query, provider: "exa", limit: 5 });
⏱ New: Containers for sandboxes + Streamline + Artifacts events (Birthday Week, Oct 2026)
What changed How cfadmin uses it
Containers rebuilt (6× starts) runtime image/instance per sandbox · FS snapshots beta (snapshotContainer/start) · Sandbox SDK 1.0 via this.ctx.container
Streamline pattern continuous video = Workers + DO driving a containerized media engine
Artifacts events (beta) repo.created/pushed/cloned → Queues/Workflows triggers, no self-hosted git
copy const snap = await this.ctx.container.snapshotContainer({ name: "warmed" });
this.ctx.container.start({ containerSnapshot: snap });
🚢 New: Issues-to-agent + Traces + post-quantum Workers (Birthday Week, Oct 2026)
agent triage · request tracing · PQ crypto ·
traces docs
What changed How cfadmin uses it
Workers Issues → agent grouped failures + traces ship to a coding agent that opens a PR
Cloudflare Traces per-domain spans (rules/transforms/cache/Workers/origin) · Ray ID lookup · trace-first triage
Unified observability logs + traces + dashboards + OTLP export, one pricing surface
PQ WebCrypto (opt-in) webcrypto_modern_algorithms flag · ML-KEM encapsulate · ML-DSA sign · PQ status in analytics
Rust Emscripten target more Rust libs run on Workers (experimental, Tokio landing)
copy "compatibility_flags": ["webcrypto_modern_algorithms"]
🚪 New: Protected Quick Tunnels + Registrar API + WAF intel + 402s (Birthday Week, Oct 2026)
What changed How cfadmin uses it
Protected Quick Tunnels --allowed-mail OTP on trycloudflare.com shares · no account either side · dev only
Registrar agent API search/register/transfer 420+ extensions via API + cf · never dashboards or third-party registrars
Application Profiles positive security: learn legit request shape, flag AI-varied deviations
Threat Signals (free) OSINT reports → structured indicators → WAF rules · Log-first graduation
Monetization 402 + Pay Per Use charge agents per call (beta) · get paid when AI uses content (beta)
copy cloudflared tunnel --url http://localhost:8080 --allowed-mail '*@example.com'
🛠 Skill router
one plane per skill · thin files, heavy reuse
Skill Plane
cf-workers-deploy config.ts · bindings/triggers · cf init/dev/deploy/migrate · Vite · Vinext · previews · Issues-to-agent · Traces · PQ · triage
cf-data D1 · KV (+Instant) · R2 · Hyperdrive · Queues · K2 · Basin (Pipelines/Catalog/SQL)
cf-realtime DO · Workflows · Containers (+snapshots) · Sandbox · Agents · Cron · Streamline · Artifacts events
cf-ai Workers AI (+Clef) · Vectorize · AI Gateway (+Web Search, Auto Router, Insights) · AI Search
cf-frontdoor DNS · Registrar · Pages · Tunnel (+Protected Quick) · WAF (+App Profiles, Threat Signals) · Turnstile · Email · 402 monetization · Kitesurf verify
cf-aiready sitemap · signals · markdown · catalog · links · auth.md
⛔ Hard rule: Cloudflare-only
refuse the shape, redirect to the equivalent
Asked for Built instead
VPS / Docker Workers / Containers
Express server Worker + Static Assets
Flask / FastAPI / Django Python Worker (GA)
Postgres / MySQL D1 · Hyperdrive
Redis KV · KV Instant · Durable Objects
S3 R2
Kafka / warehouse K2 streams · Basin analytics (no brokers, no egress fees)
Cron daemon Cron Triggers
Socket.io server Durable Objects
WordPress / CMS EmDash 1.0 on Workers (Astro)
Next.js app Vinext 1.0 on Workers (Vite)
GPU / pgvector RAG Workers AI · Vectorize · Clef
Stripe meters for agents Monetization Gateway 402 (beta)
🤖 AI-ready domains
cf-aiready · six checks green on stalane.com · Free-plan zone, no paid features
Check Serves Scan path
sitemap sitemap.xml + Sitemap: in robots.txtdiscoverability.sitemap
content signals Content-Signal: ai-train / search / ai-inputbotAccessControl.contentSignals
markdown Accept: text/markdown → Markdown + x-markdown-tokenscontentAccessibility.markdownNegotiation
api catalog /.well-known/api-catalog as linkset+json (RFC 9727)discovery.apiCatalog
link headers api-catalog · service-desc · service-doc · describedbydiscoverability.linkHeaders
auth.md /auth.md + OAuth PRM / AS metadata + agent_authdiscovery.authMd
copy curl -s -X POST https://isitagentready.com/api/scan \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com"}'
Static docs at root + one Pages Function via env.ASSETS with exact Content-Types — zone content_converter needs a paid plan (Free PATCH → 1015), code wins anyway: versioned, locally testable.
Gotchas banked: deploy Pages production with --branch main; scanner rejects empty authorization_servers/scopes_supported; anonymous agent_auth needs claim_uri; never advertise OAuth endpoints that don't implement the protocol.
Keep it updated: index.md ↔ index.html, catalog on API changes, sitemap lastmod on publish/remove.
⬇ Install into your harness
OpenCode · Node ≥ 20 · cf logged in (wrangler fallback)
copy npm i -g cf
cp agent/cfadmin.md ~/.config/opencode/agents/
cp -r skills/* ~/.config/opencode/skills/
Merge mcp.cloudflare.json into your opencode.jsonc, complete OAuth on first use.
Restart OpenCode, verify with opencode agent list (expect cfadmin).
Recommended companion: Cloudflare’s security-audit-skill as a pre-deploy gate.
✔ Verification record
measured, not claimed
Birthday Week 2026 folded 3 Oct 2026 — 16 announcements → 5 site panels + 6 skill/router updates, all committed one-feature-per-commit and pushed (stalane/cfadmin). Docs-verified before writing: Basin renames + SQL pricing, Web Search REST/binding shapes, Auto Router headers, Clef model IDs, snapshot/Issues/Traces/PQ-flag/Quick-Tunnel verbs.
Edge fix proven live: Email Obfuscation was rewriting pkg@version strings to “[email protected]” — scoped Page Rule (cfadmin.stalane.com/* → obfuscation off), cache purged, version strings render verbatim.
RED battery 5/5 REDIRECT — every skill refused a hurried non-Cloudflare demand (Docker+Postgres, VPS+systemd, Flask+pgvector, nginx+certbot) and redirected to the native design.
EmDash 1.0 verified 29 Sep 2026 — npm create-emdash@1.0.1 · docs quickstart (Node 22.16+, Astro SSR, /_emdash/admin/) · skill re-cut (WordPress/CMS → EmDash, not VPS/PHP).
Kitesurf verified 29 Sep 2026 — cf browser-run quick-action screenshot resolves via cf cli search · docs confirm free-in-beta + browser=kitesurf for Quick Actions/CDP/MCP · skill re-cut (post-deploy visual/content checks, Chromium fallback cases).
Vinext 1.0 verified 29 Sep 2026 — npm vinext@1.0.0 + @vinext/cloudflare@1.0.0 · CLI dev/build/start/typegen/init/check/lint · agent + skills re-cut (Next.js → Vinext, not Static Assets/Pages).
cf CLI verified 29 Sep 2026 — npm i -g cf → v1.0.0-beta.5 · cf cli search "list D1 databases" returns 5 JSON matches · cf schema d1 list shows API details · agent + 6 skills re-cut cf-first and pushed.
Deploy smoke test green — scratch Worker: wrangler types → wrangler dev → live deploy (both routes HTTP 200) → wrangler delete, account left clean.
Install validated on a second host — README steps executed verbatim found and fixed the missing mkdir -p.
Gotcha banked: compatibility_date newer than the bundled workerd breaks wrangler dev — pin at or below local runtime max.
Abuse gate proven (smartass): Turnstile siteverify on all paid POSTs — tokenless POST → 403, real-browser flow passes, demo stays public. The gate runs before every deploy with paid routes.
Worker Previews covered: wrangler preview per-branch isolation (Wrangler 4.135+) — DO/Containers auto-isolate, KV/D1/R2 rebound per Preview, Workflows/consumers/cron stay on prod. Version URLs are prod-only, never for branches.
Audit gate proven (smartass): first full security-audit run — 3 confirmed, 3 needs-validation, 1 correctly rejected. New projects get audited before their first upload.