[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"project-94365":3},{"id":4,"name":5,"fullName":6,"owner":7,"repo":5,"description":8,"homepage":9,"htmlUrl":10,"language":11,"languages":10,"totalLinesOfCode":10,"stars":12,"forks":13,"watchers":14,"openIssues":14,"contributorsCount":15,"subscribersCount":15,"size":15,"stars1d":15,"stars7d":15,"stars30d":16,"stars90d":15,"forks30d":15,"starsTrendScore":15,"compositeScore":17,"rankGlobal":10,"rankLanguage":10,"license":18,"archived":19,"fork":19,"defaultBranch":20,"hasWiki":19,"hasPages":19,"topics":21,"createdAt":10,"pushedAt":10,"updatedAt":22,"readmeContent":23,"aiSummary":24,"trendingCount":15,"starSnapshotCount":15,"syncStatus":25,"lastSyncTime":26,"discoverSource":27},94365,"cloudflare-os-starter","cloudflare\u002Fcloudflare-os-starter","cloudflare","A guide for customizing your Cloudflare OS deployment","https:\u002F\u002Fos.cloudflare.app",null,"JavaScript",166,41,1,0,58,50.67,"Apache License 2.0",false,"main",[],"2026-08-24 04:01:22","\u003Cp align=\"center\">\n  \u003Cimg src=\"docs\u002Fassets\u002FcloudflareOS.svg\" alt=\"Cloudflare OS\" width=\"480\">\n\u003C\u002Fp>\n\n\u003Ch1 align=\"center\">Customized for your Company\u003C\u002Fh1>\n\n\u003Cp align=\"center\">\n  Deploy a pinned Cloudflare OS release with branding, sign-in, integrations, routes, and upgrades under your control.\n\u003C\u002Fp>\n\n\u003Cp align=\"center\">\n  \u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002F\">\u003Cimg alt=\"Cloudflare Workers\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FCloudflare-Workers-F6821F?logo=cloudflare&logoColor=white\">\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fnodejs.org\u002F\">\u003Cimg alt=\"Node.js 24\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FNode.js-24-5FA04E?logo=nodedotjs&logoColor=white\">\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fpnpm.io\u002F\">\u003Cimg alt=\"pnpm 11\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fpnpm-11-F69220?logo=pnpm&logoColor=white\">\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fcloudflare-os\">\u003Cimg alt=\"Cloudflare OS upstream\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fupstream-Cloudflare_OS-24292F?logo=github\">\u003C\u002Fa>\n\u003C\u002Fp>\n\n> [!IMPORTANT]\n> Cloudflare OS is early-access software. Pin upstream releases, review changes, and verify the trust boundary before every production upgrade.\n\n## Four steps\n\n1. Install the dependencies and run `pnpm exec wrangler login`.\n2. Fill in `deployment.jsonc`: account ID, Worker names, hostname, Access audience, admin emails.\n3. Run `pnpm check`, then `pnpm deploy`.\n4. Open `\u002Fadmin` and set the site name, logo, and accent color; branding needs no redeploy.\n\n[Deploy](#deploy) and [Customization](#customization) expand each step. Everything else on this page is optional reading.\n\n## Overview\n\nThis repository adds deployment controls around a pinned [Cloudflare OS](https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fcloudflare-os) release without modifying the upstream source.\n\n| Control | What you own |\n| --- | --- |\n| Branding | Site name, logo, and accent color, changed in [`\u002Fadmin`](docs\u002Fcustomization.md#branding) without a deploy |\n| Identity | The sign-in method and administrator allowlist; this starter deploys [Cloudflare Access](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fcloudflare-one\u002Faccess-controls\u002Fapplications\u002Fhttp-apps\u002Fself-hosted-public-app\u002F) mode |\n| Routing | A production [Custom Domain](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fconfiguration\u002Frouting\u002Fcustom-domains\u002F) or a `workers.dev` evaluation route |\n| Data | Existing KV\u002FR2 resources or [automatic provisioning](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fwrangler\u002Fconfiguration\u002F#automatic-provisioning) |\n| Integrations | Wrapper-owned Gatekeepers and service bindings without patching upstream |\n| AI | No platform model by default; opt into [Workers AI](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers-ai\u002F) and [AI Gateway](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fai-gateway\u002F) when needed |\n| Operations | [Structured logs, traces, explicit error reports](docs\u002Fobservability.md), validation, deployment order, and upgrades |\n\n### Architecture\n\n\u003Cimg src=\"docs\u002Fassets\u002Farchitecture.svg\" alt=\"Cloudflare OS deployment architecture: users sign in and reach the pinned Cloudflare OS release, holding the Workshop kernel, Gadgets, Blueprints, and the default Gatekeepers. Service bindings connect it to the Workers this repository owns: optional AI, custom Gatekeepers, the Error Reporter, and KV and R2 storage.\">\n\nThe deploy command derives temporary Wrangler files from upstream base configs, builds the frontend in Cloudflare Access mode, deploys the private Error Reporter and Gatekeepers before the Workshop, and removes generated files even on failure. Secrets never enter tracked configuration.\n\n### If you only want branding\n\nA hosted flow deploys the same upstream release to your Cloudflare account without this repository. It builds nothing locally, configures sign-in and your admin emails for you, and leaves the whole `\u002Fadmin` surface intact: site name, logo, accent color, announcements, agent instructions, featured blueprints, and which connectors your users can reach. Built-in Gatekeepers such as GitHub and Google are still yours to connect with your own OAuth credentials.\n\n\u003Ca href=\"https:\u002F\u002Fos.cloudflare.app\u002Fdeploy\">\u003Cimg src=\"https:\u002F\u002Fdeploy.workers.cloudflare.com\u002Fbutton\" alt=\"Deploy to Cloudflare\">\u003C\u002Fa>\n\nAnything past that needs your own code or settings, which is what this repository is for: custom Gatekeepers, customized error reporting, your own Worker names, reusing storage you already have, choosing how much logging to keep, and a pinned version you upgrade when you decide. Hosted deployments also run on a `workers.dev` address, so deploy from here if you want the app on your own domain, or the email Gatekeeper, which needs a zone. Come back when branding stops being enough.\n\n## Deploy\n\n### 1. Prepare the workspace\n\nInstall [Node.js 24](https:\u002F\u002Fnodejs.org\u002F), [pnpm 11](https:\u002F\u002Fpnpm.io\u002Finstallation), and authenticate [Wrangler](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fwrangler\u002Fcommands\u002F#login):\n\n```sh\ngit submodule update --init\npnpm install\npnpm --dir cloudflare-os install\npnpm exec wrangler login\n```\n\nYour account needs [Workers](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002F), [KV](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fkv\u002F), [R2](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fr2\u002F), [Browser Rendering](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fbrowser-rendering\u002F), and [Dynamic Worker Loaders](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fruntime-apis\u002Fbindings\u002Fworker-loader\u002F). AI products are optional.\n\n### 2. Configure sign-in\n\nCloudflare OS supports several sign-in methods. This starter deploys [Cloudflare Access](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fcloudflare-one\u002Faccess-controls\u002Fapplications\u002Fhttp-apps\u002Fself-hosted-public-app\u002F) mode, which verifies identity before a request reaches the Worker. See [Sign-in methods](docs\u002Fcustomization.md#sign-in-methods) for the alternatives and what switching involves.\n\n1. Choose a Workshop hostname in an [active Cloudflare zone](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fdns\u002Fzone-setups\u002F), such as `os.example.com`.\n2. Create a [self-hosted Access application](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fcloudflare-one\u002Faccess-controls\u002Fapplications\u002Fhttp-apps\u002Fself-hosted-public-app\u002F) for that hostname.\n3. Copy its [application audience tag](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fcloudflare-one\u002Faccess-controls\u002Fapplications\u002Fhttp-apps\u002Fauthorization-cookie\u002Fvalidating-json\u002F#get-your-aud-tag).\n4. Open [`deployment.jsonc`](deployment.jsonc) and replace the active placeholders. Every control is annotated in place.\n\nWrangler creates DNS and TLS for the custom domain at deploy time. For an evaluation without a zone, switch the annotated route to `{ \"workersDev\": true }`.\n\n### 3. Validate and deploy\n\n```sh\npnpm check\npnpm deploy\n```\n\nWith resource values left as `null`, Wrangler creates the three KV namespaces and R2 bucket automatically and reconnects them on later deploys. Set explicit IDs or a bucket name when the deployment must reuse existing resources.\n\nAI is disabled by default. The application can deploy without an AI Gateway or token; see [AI models](docs\u002Fcustomization.md#ai-models) to enable deployment-funded models.\n\nBackend error reporting is enabled without a vendor account. Explicit upstream issue events become structured logs in the private Error Reporter Worker; see [Observability and error reporting](docs\u002Fobservability.md).\n\n### 4. Verify the deployment\n\n- Open the Workshop hostname and confirm Access signs in with the expected identity.\n- Open `\u002Fadmin`, confirm the email is an administrator, and set Context and Custom Gatekeepers to disabled, optional, or enabled.\n- Enable the Custom Gatekeeper, ask for deployment information, and confirm its read appears as an observation.\n- Open the Error Reporter Worker's [Workers Logs](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fobservability\u002Flogs\u002Fworkers-logs\u002F) and verify its structured `error_report` query surface.\n- Review logs for the Workshop, Context, custom Gatekeeper, and Error Reporter Workers.\n\n## Customization\n\n| Customize | Best place | Deploy required |\n| --- | --- | --- |\n| Site name, logo, color, announcements, instructions, connectors | `\u002Fadmin` | No |\n| Sign-in, routes, AI, storage, observability, Worker identities | [`deployment.jsonc`](deployment.jsonc) | Yes |\n| Logs, traces, error destinations, browser reporting | [Observability guide](docs\u002Fobservability.md) | Sometimes |\n| Organization APIs and capabilities | [`packages\u002Fcustom-gatekeeper`](packages\u002Fcustom-gatekeeper\u002FREADME.md) | Yes |\n| Product behavior unavailable through Worker boundaries | Pinned upstream fork\u002Fcommit | Yes |\n\nThe complete control reference and recipes live in [Customization](docs\u002Fcustomization.md). The upstream [`write-gatekeeper` skill](https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fcloudflare-os\u002Fblob\u002Fmain\u002F.agents\u002Fskills\u002Fwrite-gatekeeper\u002FSKILL.md) covers richer integrations.\n\n## Operations and upgrades\n\n- Stream production events with [`wrangler tail`](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fobservability\u002Flogs\u002Freal-time-logs\u002F).\n- Triage explicit failures and choose export destinations with the [observability guide](docs\u002Fobservability.md).\n- Roll a Worker back from its dashboard deployment history or with [`wrangler rollback`](https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fversions-and-deployments\u002Frollbacks\u002F).\n- Follow the [upgrade checklist](docs\u002Fcustomization.md#upgrade) before changing the pinned submodule.\n- Review the upstream Cloudflare OS documentation and release history before adopting behavior changes.\n","Cloudflare OS Starter 是一个用于定制化部署 Cloudflare OS 的脚手架项目，帮助企业在自有域名下快速搭建受控的 Cloudflare OS 实例。它提供开箱即用的部署流程（含身份认证、路由配置、品牌定制、资源绑定与可观测性支持），所有定制均通过配置文件和管理界面实现，不修改上游源码；底层基于 Cloudflare Workers 运行，支持 Cloudflare Access 鉴权、KV\u002FR2 数据集成及可选 Workers AI 扩展。适用于需要私有化部署内部开发者门户、内部工具平台或企业级 SaaS 前端控制台的场景。",2,"2026-08-07 02:30:08","CREATED_QUERY"]