All skills
openai avatar

/cloudflare-deploy

@bf9e226 official
by openaiopenai/skills28k stars
1,891

Deploy applications and infrastructure to Cloudflare using Workers, Pages, and related platform services. Use when the user asks to deploy, host, publish, or set up a project on Cloudflare.

Use this Skill: https://skilld.dev/gh/openai/skills/cloudflare-deploy

This session only. Nothing lands on disk.

referencesr2-data-cataloggotchas.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Gotchas & Troubleshooting

Common problems → causes → solutions.

Permission Errors

401 Unauthorized

Error: "401 Unauthorized"
Cause: Token missing R2 Data Catalog permissions.
Solution: Use "Admin Read & Write" token (includes catalog + storage permissions). Test with catalog.list_namespaces().

403 Forbidden

Error: "403 Forbidden" on data files
Cause: Token lacks storage permissions.
Solution: Token needs both R2 Data Catalog + R2 Storage Bucket Item permissions.

Token Rotation Issues

Error: New token fails after rotation.
Solution: Create new token → test in staging → update prod → monitor 24h → revoke old.

Catalog URI Issues

404 Not Found

Error: "404 Catalog not found"
Cause: Catalog not enabled or wrong URI.
Solution: Run wrangler r2 bucket catalog enable <bucket>. URI must be HTTPS with /iceberg/ and case-sensitive bucket name.

Wrong Warehouse

Error: Cannot create/load tables.
Cause: Warehouse ≠ bucket name.
Solution: Set warehouse="bucket-name" to match bucket exactly.

Table and Schema Issues

Table/Namespace Already Exists

Error: "TableAlreadyExistsError"
Solution: Use try/except to load existing or check first.

Namespace Not Found

Error: Cannot create table.
Solution: Create namespace first: catalog.create_namespace("ns")

Schema Evolution Errors

Error: "422 Validation" on schema update.
Cause: Incompatible change (required field, type shrink).
Solution: Only add nullable columns, compatible type widening (int→long, float→double).

Data and Query Issues

Empty Scan Results

Error: Scan returns no data.
Cause: Incorrect filter or partition column.
Solution: Test without filter first: table.scan().to_pandas(). Verify partition column names.

Slow Queries

Error: Performance degrades over time.
Cause: Too many small files.
Solution: Check file count, compact if >1000 or avg <10MB. See api.md.

Type Mismatch

Error: "Cannot cast" on append.
Cause: PyArrow types don't match Iceberg schema.
Solution: Cast to int64 (Iceberg default), not int32. Check table.schema().

Compaction Issues

Compaction Issues

Problem: File count unchanged or compaction takes hours.
Cause: Target size too large, or table too big for PyIceberg.
Solution: Only compact if avg <50MB. For >1TB tables, use Spark. Run during low-traffic periods.

Maintenance Issues

Snapshot/Orphan Issues

Problem: Expiration fails or orphan cleanup deletes active data.
Cause: Too aggressive retention or wrong order.
Solution: Always expire snapshots first with retain_last=10, then cleanup orphans with 3+ day threshold.

Concurrency Issues

Concurrent Write Conflicts

Problem: CommitFailedException with multiple writers.
Cause: Optimistic locking - simultaneous commits.
Solution: Add retry with exponential backoff (see patterns.md).

Stale Metadata

Problem: Old schema/data after external update.
Cause: Cached metadata.
Solution: Reload table: table = catalog.load_table(("ns", "table"))

Performance Optimization

Performance Tips

Scans: Use row_filter and selected_fields to reduce data scanned.
Partitions: 100-1000 optimal. Avoid high cardinality (millions) or low (<10).
Files: Keep 100-500MB avg. Compact if <10MB or >10k files.

Limits

Resource Recommended Impact if Exceeded
Tables/namespace <10k Slow list ops
Files/table <100k Slow query planning
Partitions/table 100-1k Metadata overhead
Snapshots/table Expire >7d Metadata bloat

Common Error Messages Reference

Error Message Likely Cause Fix
401 Unauthorized Missing/invalid token Check token has catalog+storage permissions
403 Forbidden Token lacks storage permissions Add R2 Storage Bucket Item permission
404 Not Found Catalog not enabled or wrong URI Run wrangler r2 bucket catalog enable
409 Conflict Table/namespace already exists Use try/except or load existing
422 Unprocessable Entity Schema validation failed Check type compatibility, required fields
CommitFailedException Concurrent write conflict Add retry logic with backoff
NamespaceAlreadyExistsError Namespace exists Use try/except or load existing
NoSuchTableError Table doesn't exist Check namespace+table name, create first
TypeError: Cannot cast PyArrow type mismatch Cast data to match Iceberg schema

Debugging Checklist

When things go wrong, check in order:

  1. ✅ Catalog enabled: npx wrangler r2 bucket catalog status <bucket>
  2. ✅ Token permissions: Both R2 Data Catalog + R2 Storage in dashboard
  3. ✅ Connection test: catalog.list_namespaces() succeeds
  4. ✅ URI format: HTTPS, includes /iceberg/, correct bucket name
  5. ✅ Warehouse name: Matches bucket name exactly
  6. ✅ Namespace exists: Create before create_table()
  7. ✅ Enable debug logging: logging.basicConfig(level=logging.DEBUG)
  8. ✅ PyIceberg version: pip install --upgrade pyiceberg (≥0.5.0)
  9. ✅ File health: Compact if >1000 files or avg <10MB
  10. ✅ Snapshot count: Expire if >100 snapshots

Enable Debug Logging

import logging
logging.basicConfig(level=logging.DEBUG)
# Now operations show HTTP requests/responses

Resources

Next Steps

Source: SKILL.md on GitHub

2 warnings17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides comprehensive guidance for deploying and managing infrastructure on the Cloudflare platform. It includes extensive educational material on secure development practices, such as preventing SQL injection and managing secrets effectively. No malicious patterns or security risks were identified.

  • Socket17d

    2 alerts: gptAnomaly

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    310/310 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at bf9e226. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Activeupdated 8 months ago

README badge

README badge for openai/skills/cloudflare-deploy

Deploys applications and infrastructure to Cloudflare's platform, including Workers, Pages, D1, R2, Durable Objects, KV, and other services. Use decision trees to route to the right Cloudflare product based on compute, storage, AI, networking, security, or media needs.

Generated from the current SKILL.md.

Does this skill cover all Cloudflare products?
The skill is a consolidated index covering compute, storage, AI, networking, security, media, and developer tools on Cloudflare. It uses decision trees to route you to the right product reference, then loads detailed guidance for that product.
What authentication is required before deploying?
Run `npx wrangler whoami` to check if authenticated. For local deployment, use `wrangler login` (one-time OAuth). For CI/CD, set the `CLOUDFLARE_API_TOKEN` environment variable.
What should I do if deployment fails due to network issues?
Rerun the deploy with `sandbox_permissions=require_escalated` to grant elevated network access, which is required for outbound requests to Cloudflare during deployment.
How long does a Cloudflare deployment typically take?
Deployments may take several minutes. Use appropriate timeout values in your configuration or CI/CD environment.

Generated from the current SKILL.md. These answers refresh after source changes.