All skills
openai avatar

/cloudflare-deploy

@bf9e226 official
by openaiopenai/skills28k stars
1,891

Deploy applications and infrastructure to Cloudflare using Workers, Pages, and related platform services. Use when the user asks to deploy, host, publish, or set up a project on Cloudflare.

Use this Skill: https://skilld.dev/gh/openai/skills/cloudflare-deploy

This session only. Nothing lands on disk.

referencescache-reserveREADME.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cloudflare Cache Reserve

Persistent cache storage built on R2 for long-term content retention

Smart Shield Integration

Cache Reserve is part of Smart Shield, Cloudflare's comprehensive security and performance suite:

  • Smart Shield Advanced tier: Includes 2TB Cache Reserve storage
  • Standalone purchase: Available separately if not using Smart Shield
  • Migration: Existing standalone customers can migrate to Smart Shield bundles

Decision: Already on Smart Shield Advanced? Cache Reserve is included. Otherwise evaluate standalone purchase vs Smart Shield upgrade.

Overview

Cache Reserve is Cloudflare's persistent, large-scale cache storage layer built on R2. It acts as the ultimate upper-tier cache, storing cacheable content for extended periods (30+ days) to maximize cache hits, reduce origin egress fees, and shield origins from repeated requests for long-tail content.

Core Concepts

What is Cache Reserve?

  • Persistent storage layer: Built on R2, sits above tiered cache hierarchy
  • Long-term retention: 30-day default retention, extended on each access
  • Automatic operation: Works seamlessly with existing CDN, no code changes required
  • Origin shielding: Dramatically reduces origin egress by serving cached content longer
  • Usage-based pricing: Pay only for storage + read/write operations

Cache Hierarchy

Visitor Request
    ↓
Lower-Tier Cache (closest to visitor)
    ↓ (on miss)
Upper-Tier Cache (closest to origin)
    ↓ (on miss)
Cache Reserve (R2 persistent storage)
    ↓ (on miss)
Origin Server

How It Works

  1. On cache miss: Content fetched from origin �� written to Cache Reserve + edge caches simultaneously
  2. On edge eviction: Content may be evicted from edge cache but remains in Cache Reserve
  3. On subsequent request: If edge cache misses but Cache Reserve hits → content restored to edge caches
  4. Retention: Assets remain in Cache Reserve for 30 days since last access (configurable via TTL)

When to Use Cache Reserve

Need persistent caching?
├─ High origin egress costs → Cache Reserve ✓
├─ Long-tail content (archives, media libraries) → Cache Reserve ✓
├─ Already using Smart Shield Advanced → Included! ✓
├─ Video streaming with seeking (range requests) → ✗ Not supported
├─ Dynamic/personalized content → ✗ Use edge cache only
├─ Need per-request cache control from Workers → ✗ Use R2 directly
└─ Frequently updated content (< 10hr lifetime) → ✗ Not eligible

Asset Eligibility

Cache Reserve only stores assets meeting ALL criteria:

  • Cacheable per Cloudflare's standard rules
  • Minimum 10-hour TTL (36000 seconds)
  • Content-Length header present
  • Original files only (not transformed images)

Eligibility Checklist

Use this checklist to verify if an asset is eligible:

  • Zone has Cache Reserve enabled
  • Zone has Tiered Cache enabled (required)
  • Asset TTL ≥ 10 hours (36,000 seconds)
  • Content-Length header present on origin response
  • No Set-Cookie header (or uses private directive)
  • Vary header is NOT * (can be Accept-Encoding)
  • Not an image transformation variant (original images OK)
  • Not a range request (no HTTP 206 support)
  • Not O2O (Orange-to-Orange) proxied request

All boxes must be checked for Cache Reserve eligibility.

Not Eligible

  • Assets with TTL < 10 hours
  • Responses without Content-Length header
  • Image transformation variants (original images are eligible)
  • Responses with Set-Cookie headers
  • Responses with Vary: * header
  • Assets from R2 public buckets on same zone
  • O2O (Orange-to-Orange) setup requests
  • Range requests (video seeking, partial content downloads)

Quick Start

# Enable via Dashboard
https://dash.cloudflare.com/caching/cache-reserve
# Click "Enable Storage Sync" or "Purchase" button

Prerequisites:

  • Paid Cache Reserve plan or Smart Shield Advanced required
  • Tiered Cache required for optimal performance

Essential Commands

# Check Cache Reserve status
curl -X GET "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/cache/cache_reserve" \
  -H "Authorization: Bearer $API_TOKEN"

# Enable Cache Reserve
curl -X PATCH "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/cache/cache_reserve" \
  -H "Authorization: Bearer $API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"value": "on"}'

# Check asset cache status
curl -I https://example.com/asset.jpg | grep -i cache

In This Reference

Task Files
Evaluate if Cache Reserve fits your use case README.md (this file)
Enable Cache Reserve for your zone README.md + configuration.md
Use with Workers (understand limitations) api.md
Setup via SDKs or IaC (TypeScript, Python, Terraform) configuration.md
Optimize costs and debug issues patterns.md + gotchas.md
Understand eligibility and troubleshoot gotchas.md → patterns.md

Files:

  • configuration.md - Setup, API, SDKs, and Cache Rules
  • api.md - Purging, monitoring, Workers integration
  • patterns.md - Best practices, cost optimization, debugging
  • gotchas.md - Common issues, limitations, troubleshooting

See Also

  • r2 - Cache Reserve built on R2 storage
  • workers - Workers integration with Cache API

Source: SKILL.md on GitHub

2 warnings17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides comprehensive guidance for deploying and managing infrastructure on the Cloudflare platform. It includes extensive educational material on secure development practices, such as preventing SQL injection and managing secrets effectively. No malicious patterns or security risks were identified.

  • Socket17d

    2 alerts: gptAnomaly

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    310/310 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at bf9e226. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Activeupdated 8 months ago

README badge

README badge for openai/skills/cloudflare-deploy

Deploys applications and infrastructure to Cloudflare's platform, including Workers, Pages, D1, R2, Durable Objects, KV, and other services. Use decision trees to route to the right Cloudflare product based on compute, storage, AI, networking, security, or media needs.

Generated from the current SKILL.md.

Does this skill cover all Cloudflare products?
The skill is a consolidated index covering compute, storage, AI, networking, security, media, and developer tools on Cloudflare. It uses decision trees to route you to the right product reference, then loads detailed guidance for that product.
What authentication is required before deploying?
Run `npx wrangler whoami` to check if authenticated. For local deployment, use `wrangler login` (one-time OAuth). For CI/CD, set the `CLOUDFLARE_API_TOKEN` environment variable.
What should I do if deployment fails due to network issues?
Rerun the deploy with `sandbox_permissions=require_escalated` to grant elevated network access, which is required for outbound requests to Cloudflare during deployment.
How long does a Cloudflare deployment typically take?
Deployments may take several minutes. Use appropriate timeout values in your configuration or CI/CD environment.

Generated from the current SKILL.md. These answers refresh after source changes.