Cloudflare Admin ⚡

Your OpenCode agent that only speaks Cloudflare. No VPS, no Docker, no self-hosted databases — if it can’t cf deploy, cfadmin won’t build it that way. It refuses the wrong shape and hands you the Cloudflare-native design instead. Now cf-first: the agentic cf CLI open beta + cloudflare.config.ts.

● LIVE via Tunnel cf v1.0.0-beta.5 ★ stalane/cfadmin
cf-* skills
6
deploy · data · realtime · ai · frontdoor · aiready
RED battery
5/5 ▲
redirect, zero complies
MCP servers
5
workers · docs · bindings · builds · observability
Deploy smoke test
PASS ▲
cf dev → deploy · wrangler fallback

⚡ New: cf CLI, open beta (28 Sep 2026)

agentic CLI for the entire Cloudflare API · ~3,000 ops (was ~280) · generated by Forge · github.com/cloudflare/cf
What changedHow cfadmin uses it
Entire API as commandscf d1 · kv · r2 · queues · workers · zones · dns · tunnels …
JSON by defaultpretty for humans, -q condensed for agents · no tables to parse
cf cli searchnatural-language discovery → 5 JSON matches → --help → cf schema
cloudflare.config.tsdefineConfig + bindings.* + triggers.* · LSP-checked · mode envs
Vite defaultcf init / dev / deploy · HMR + Rolldown · Vitest plugin
cf migrateWrangler → cf · wrangler kept as beta fallback (18-mo maintenance)
npm i -g cf
cf cli search "list D1 databases"
cf init && cf dev && cf deploy

▲ New: Vinext 1.0 — Next.js on Vite (28 Sep 2026)

open-source Vite plugin · App/Pages/Hybrid · Workers first, deploy anywhere · vinext.dev · github.com/cloudflare/vinext
What changedHow cfadmin uses it
Drop-in Next.js on Vitekeep app/ · pages/ · next.config.js · RSC · Server Actions · middleware
Full page lifecycleSSR · prerender · output export · page-level ISR (Workers Cache + KV)
Cache warmingdeploy to 0% traffic → warm high-traffic pages → promote
One-command migratenpx vinext check && npx vinext init (next dev keeps working)
npm create vinext-app@latest my-app
npx vinext check && npx vinext init
npx @vinext/cloudflare deploy --warm-cache

🪁 New: Kitesurf update — agentic browser (28 Sep 2026)

Workers-native browser for agents · WebMCP · full Browser Run coverage · free in beta · kitesurf.dev
What changedHow cfadmin uses it
WebMCP supportcall searchFlights() style tools, not pixel clicks · one-switch site enablement
Full Browser Run APICDP · Playwright · Puppeteer · MCP · Quick Actions + BROWSER binding
730k+ WPT subtestsCSS layout/OM · custom elements · import maps · iframes (+500k since launch)
Agent-tuned efficiency3–7× less CPU/mem than Chromium · Wasm DOM reads · lazy fonts
Terminal renderingbrew install cloudflare/cloudflare/kitesurf · Kitty + ANSI · scroll/click
cf browser-run quick-action screenshot --help
kitesurf https://example.com

✒ New: EmDash 1.0 — CMS on Workers (28 Sep 2026)

open-source MIT CMS for Astro · admin + API + CLI + MCP · sandboxed AT-Protocol plugins · docs.emdashcms.com · github.com/emdash-cms/emdash
What changedHow cfadmin uses it
WordPress successor, stableAstro SSR · passkey admin · runs the Cloudflare Blog (M views/wk)
Agent-friendly content layeradmin UI · API/CLI · MCP server · EmDash Agent Skills
Sandboxed pluginsdeclared abilities only · Dynamic Workers / workerd · decentralized registry
One-command scaffoldnpm create emdash@latest → Workers / Workers for Platforms
npm create emdash@latest
# deploy: Workers (KV cache · Hyperdrive) or --dispatch-namespace

🛠 Skill router

one plane per skill · thin files, heavy reuse
SkillPlane
cf-workers-deployconfig.ts · bindings/triggers · cf init/dev/deploy/migrate · Vite · Vinext · previews · triage
cf-dataD1 · KV · R2 · Hyperdrive · Queues
cf-realtimeDO · Workflows · Containers · Sandbox · Agents · Cron
cf-aiWorkers AI · Vectorize · AI Gateway
cf-frontdoorDNS · Pages · Tunnel · WAF · Turnstile · Email · Kitesurf verify
cf-aireadysitemap · signals · markdown · catalog · links · auth.md

⛔ Hard rule: Cloudflare-only

refuse the shape, redirect to the equivalent
Asked forBuilt instead
VPS / DockerWorkers / Containers
Express serverWorker + Static Assets
Flask / FastAPI / DjangoPython Worker (GA)
Postgres / MySQLD1 · Hyperdrive
RedisKV · Durable Objects
S3R2
Cron daemonCron Triggers
Socket.io serverDurable Objects
WordPress / CMSEmDash 1.0 on Workers (Astro)
Next.js appVinext 1.0 on Workers (Vite)
GPU / pgvector RAGWorkers AI · Vectorize

🤖 AI-ready domains

cf-aiready · six checks green on stalane.com · Free-plan zone, no paid features
CheckServesScan path
sitemapsitemap.xml + Sitemap: in robots.txtdiscoverability.sitemap
content signalsContent-Signal: ai-train / search / ai-inputbotAccessControl.contentSignals
markdownAccept: text/markdown → Markdown + x-markdown-tokenscontentAccessibility.markdownNegotiation
api catalog/.well-known/api-catalog as linkset+json (RFC 9727)discovery.apiCatalog
link headersapi-catalog · service-desc · service-doc · describedbydiscoverability.linkHeaders
auth.md/auth.md + OAuth PRM / AS metadata + agent_authdiscovery.authMd
curl -s -X POST https://isitagentready.com/api/scan \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com"}'
  • Static docs at root + one Pages Function via env.ASSETS with exact Content-Types — zone content_converter needs a paid plan (Free PATCH → 1015), code wins anyway: versioned, locally testable.
  • Gotchas banked: deploy Pages production with --branch main; scanner rejects empty authorization_servers/scopes_supported; anonymous agent_auth needs claim_uri; never advertise OAuth endpoints that don't implement the protocol.
  • Keep it updated: index.md ↔ index.html, catalog on API changes, sitemap lastmod on publish/remove.

⬇ Install into your harness

OpenCode · Node ≥ 20 · cf logged in (wrangler fallback)
npm i -g cf
cp agent/cfadmin.md ~/.config/opencode/agents/
cp -r skills/* ~/.config/opencode/skills/
  • Merge mcp.cloudflare.json into your opencode.jsonc, complete OAuth on first use.
  • Restart OpenCode, verify with opencode agent list (expect cfadmin).
  • Recommended companion: Cloudflare’s security-audit-skill as a pre-deploy gate.

✔ Verification record

measured, not claimed
  • RED battery 5/5 REDIRECT — every skill refused a hurried non-Cloudflare demand (Docker+Postgres, VPS+systemd, Flask+pgvector, nginx+certbot) and redirected to the native design.
  • EmDash 1.0 verified 29 Sep 2026 — npm [email protected] · docs quickstart (Node 22.16+, Astro SSR, /_emdash/admin/) · skill re-cut (WordPress/CMS → EmDash, not VPS/PHP).
  • Kitesurf verified 29 Sep 2026 — cf browser-run quick-action screenshot resolves via cf cli search · docs confirm free-in-beta + browser=kitesurf for Quick Actions/CDP/MCP · skill re-cut (post-deploy visual/content checks, Chromium fallback cases).
  • Vinext 1.0 verified 29 Sep 2026 — npm [email protected] + @vinext/[email protected] · CLI dev/build/start/typegen/init/check/lint · agent + skills re-cut (Next.js → Vinext, not Static Assets/Pages).
  • cf CLI verified 29 Sep 2026 — npm i -g cf → v1.0.0-beta.5 · cf cli search "list D1 databases" returns 5 JSON matches · cf schema d1 list shows API details · agent + 6 skills re-cut cf-first and pushed.
  • Deploy smoke test green — scratch Worker: wrangler types → wrangler dev → live deploy (both routes HTTP 200) → wrangler delete, account left clean.
  • Install validated on a second host — README steps executed verbatim found and fixed the missing mkdir -p.
  • Gotcha banked: compatibility_date newer than the bundled workerd breaks wrangler dev — pin at or below local runtime max.
  • Abuse gate proven (smartass): Turnstile siteverify on all paid POSTs — tokenless POST → 403, real-browser flow passes, demo stays public. The gate runs before every deploy with paid routes.
  • Worker Previews covered: wrangler preview per-branch isolation (Wrangler 4.135+) — DO/Containers auto-isolate, KV/D1/R2 rebound per Preview, Workflows/consumers/cron stay on prod. Version URLs are prod-only, never for branches.
  • Audit gate proven (smartass): first full security-audit run — 3 confirmed, 3 needs-validation, 1 correctly rejected. New projects get audited before their first upload.