Best for
- Publishing HTML files to a public URL (too large for GitHub)
- Setting up a new Cloudflare Workers static site
- Troubleshooting a failed Cloudflare deploy
terrylica/cc-skills/plugins/devops-tools/skills/cloudflare-workers-publish/SKILL.md
Deploy static HTML files to Cloudflare Workers with 1Password credential management.
Decision brief
Deploy static HTML files (Bokeh charts, dashboards, reports) to Cloudflare Workers with Static Assets, using 1Password for credential management.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/terrylica/cc-skills --skill "plugins/devops-tools/skills/cloudflare-workers-publish"Inspect the Agent Skill "cloudflare-workers-publish" from https://github.com/terrylica/cc-skills/blob/a5f847b22ee5afa35677e446973a903d098cd1d4/plugins/devops-tools/skills/cloudflare-workers-publish/SKILL.md at commit a5f847b22ee5afa35677e446973a903d098cd1d4. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
Review the “Template A - New Static Site (First-Time Setup)” section in the pinned source before continuing.
1. Go to 2. Click Create Token Custom token 3. Set permissions: Account Workers Scripts Edit (CFW-11) 4. Account Resources: Include your account 5. Copy the token (shown only once)
1. Go to 2. Click Create Token Custom token 3. Set permissions: Account Workers Scripts Edit (CFW-11) 4. Account Resources: Include your account 5. Copy the token (shown only once)
CRITICAL (CFW-02): 1Password service accounts can only READ items. They CANNOT CREATE new items. Create the item manually first.
See wrangler setup guide.
Permission review
The documentation asks the agent to run terminal commands or scripts.
npx wrangler deployThe documentation includes network, browsing, or remote request actions.
https://{name}.{slug}.workers.dev/The documentation asks the agent to create, modify, or delete local files.
[Execute] Create publish directory with wrangler.toml (3 fields only)The documentation asks the agent to run terminal commands or scripts.
[Execute] Create deploy script from skill template (parameterize 4 vars)The documentation includes network, browsing, or remote request actions.
[Verify] Run first deploy and verify URL in browser (NOT curl)Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 94/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 62 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Deploy static HTML files (Bokeh charts, dashboards, reports) to Cloudflare Workers with Static Assets, using 1Password for credential management.
Scope: Static-only deployments on workers.dev. No dynamic Workers, no R2 object storage.
Prerequisite: 1Password CLI (brew install 1password-cli) + Node.js (npx wrangler)
Self-Evolving Skill: This skill improves through use. If instructions are wrong, parameters drifted, or a workaround was needed — fix this file immediately, don't defer. Only update for real, reproducible issues.
Do NOT use for: Dynamic Workers (JavaScript/TypeScript logic), Cloudflare Pages (deprecated April 2025 - CFW-01), R2 object storage, or custom domains (advanced setup not covered).
Local project/
├── results/published/ # Deploy root (contains wrangler.toml)
│ ├── wrangler.toml # Workers config (name + assets)
│ ├── index.html # Auto-generated directory listing
│ └── gen800/ # Subdirectories with HTML files
│ └── XRPUSDT_750/
│ └── equity_plot.html # 13MB Bokeh chart
└── scripts/
└── publish_findings.sh # Deploy script (3 phases)
Credential flow:
1Password (Claude Automation vault)
├── account_id (TEXT) → CLOUDFLARE_ACCOUNT_ID env var
└── credential (CONCEALED) → CLOUDFLARE_API_TOKEN env var
↓
npx wrangler deploy
↓
https://{name}.{slug}.workers.dev/
1. [Preflight] Verify Node.js and 1Password CLI installed
2. [Preflight] Create Cloudflare API token (Workers Scripts Edit permission)
3. [Execute] Pre-provision 1Password item in Claude Automation vault (biometric)
4. [Execute] Store token + account ID in 1Password item fields
5. [Execute] Create publish directory with wrangler.toml (3 fields only)
6. [Execute] Create deploy script from skill template (parameterize 4 vars)
7. [Execute] Create mise task wrapper in tasks/publish.toml
8. [Execute] Add .wrangler/ to .gitignore
9. [Execute] Add LFS tracking for large HTML files in .gitattributes
10. [Verify] Enable workers.dev subdomain in Cloudflare dashboard
11. [Verify] Run first deploy and verify URL in browser (NOT curl)
12. [Verify] Document the workers.dev URL in project docs
1. [Preflight] Verify files are real content, not LFS pointers (head -1)
2. [Execute] Copy HTML files to published/{generation}/{symbol_threshold}/
3. [Execute] Run deploy script (index.html auto-regenerates)
4. [Verify] Verify new files appear at workers.dev URL in browser
1. [Preflight] Choose worker name ({name}.{slug}.workers.dev)
2. [Execute] Create 1Password item OR reuse existing Cloudflare credentials
3. [Execute] Create wrangler.toml with chosen name and today's date
4. [Execute] Create parameterized deploy script from skill template
5. [Execute] Create mise task wrapper
6. [Verify] Deploy and discover actual workers.dev URL via wrangler output
1. [Execute] Create new API token in Cloudflare dashboard (Workers Scripts Edit)
2. [Execute] Update 1Password item credential field (biometric required)
3. [Verify] Run deploy script to verify new token works
4. [Execute] Revoke old token in Cloudflare dashboard
1. Is wrangler.toml in current directory? (CFW-10)
2. Are credentials populated? Print first 8 chars of account ID
3. Is --reveal present for CONCEALED fields? (CFW-03)
4. Is workers.dev subdomain registered in CF dashboard? (CFW-07)
5. Does token have Workers Scripts Edit permission? (CFW-11)
6. Are HTML files real content or LFS pointers? head -1 file (CFW-12)
7. SSL handshake error? Verify in browser, not curl (CFW-08)
8. Is npx wrangler installed? npx wrangler --version
CRITICAL (CFW-02): 1Password service accounts can only READ items. They CANNOT CREATE new items. Create the item manually first.
See 1Password setup guide for step-by-step instructions.
After provisioning, the item should have:
| Field | Type | --reveal | Content |
|---|---|---|---|
account_id | TEXT | No | Cloudflare acct ID |
credential | CONCEALED | YES | API token |
See wrangler setup guide.
# Minimal Workers Static Assets config (CFW-09)
name = "my-project-name"
compatibility_date = "2026-02-18"
[assets]
directory = "."
Copy the bundled template and edit the 4 config variables:
cp "$(skill-path)/scripts/publish_static.sh" scripts/publish_myproject.sh
# Edit: PUBLISH_DIR, OP_ITEM_ID, SITE_TITLE, PROJECT_URL
Or reference the working implementation: rangebar-patterns/scripts/publish_findings.sh
# tasks/publish.toml (CFW-13: bash in .sh file, not inline TOML)
["publish:site"]
description = "Deploy published files to Cloudflare Workers (static)"
run = "bash scripts/publish_myproject.sh"
Add to .mise.toml [task_config] includes:
[task_config]
includes = [
"tasks/publish.toml",
]
.gitignore:
# Wrangler temp files (Cloudflare Workers deploy)
.wrangler/
results/published/.wrangler/
.gitattributes (for large HTML files):
results/published/**/*.html filter=lfs diff=lfs merge=lfs -text
First-time Cloudflare accounts must enable the workers.dev route:
The subdomain is NOT predictable (CFW-06). Discover yours after deploy:
npx wrangler whoami
mise run publish:site
Verify in BROWSER, not curl (CFW-08). macOS LibreSSL can fail TLS handshake with Cloudflare but browsers handle it fine.
Full details with code examples: references/anti-patterns.md
| ID | Severity | Gotcha | Fix |
|---|---|---|---|
| CFW-01 | HIGH | Cloudflare Pages deprecated (April 2025) | Use Workers with Static Assets |
| CFW-02 | HIGH | 1P service account creating items | Pre-provision via biometric/web UI |
| CFW-03 | HIGH | Missing --reveal for CONCEALED fields | Always pass --reveal for API tokens |
| CFW-04 | MEDIUM | SC2155 export VAR=$(cmd) | Split: VAR=$(cmd) then export VAR |
| CFW-05 | LOW | Bash 4+ ${var^^} on macOS | Use tr '[:lower:]' '[:upper:]' |
| CFW-06 | MEDIUM | Assuming workers.dev URL format | Run npx wrangler whoami to discover slug |
| CFW-07 | HIGH | workers.dev subdomain not registered | Enable in Cloudflare dashboard first |
| CFW-08 | LOW | curl SSL/TLS handshake failure on macOS | Verify in browser instead |
| CFW-09 | MEDIUM | Overcomplicating wrangler.toml | Only name, compatibility_date, [assets] |
| CFW-10 | HIGH | Running wrangler from wrong directory | Always cd to directory with wrangler.toml |
| CFW-11 | MEDIUM | Excessive token permissions | Workers Scripts Edit (Account) only |
| CFW-12 | HIGH | Deploying LFS pointers instead of files | Run git lfs pull before deploy |
| CFW-13 | MEDIUM | Tera template conflict in mise TOML | Complex bash in standalone .sh files |
| CFW-14 | MEDIUM | Pipe subshell data loss in while-read | Use < <(find ...) process substitution |
| CFW-15 | LOW | No directory listing page | Auto-generate index.html before each deploy |
| CFW-16 | HIGH | Asset > 25 MiB → Asset too large deploy error | Workers Static Assets hard-caps each file at 25 MiB. Host large ZIPs/binaries off a large-file host (R2, GitHub Release, own server); keep only ≤25 MiB files on Workers. See large files & ZIP delivery |
| CFW-17 | LOW | Want a bulk-download ZIP, but it exceeds the cap | Downscale the ZIP tier to fit (e.g. heic-to-jpeg-bundle --zip-cap-mib 25), or split hosts: gallery + small ZIP on Workers, full-res ZIP on R2 |
This skill also covers serving downloadable files (a ZIP bundle, a dataset) from Workers — within the 25 MiB/file cap — and the password-on-the-gateway pattern for gating an otherwise-unlisted download. Full guide: references/large-files-and-zip-delivery.md.
Quick rules:
> 25 MiB is a hard deploy error (CFW-16) — use R2 / a GitHub Release /
your own host for those.heic-to-jpeg-bundle skill produces exactly this kind of capped, optionally-encrypted
ZIP.The working production deployment lives in rangebar-patterns:
| File | Purpose |
|---|---|
results/published/wrangler.toml | Minimal Workers config |
scripts/publish_findings.sh | 3-phase deploy script |
tasks/publish.toml | mise task wrapper |
.gitignore (.wrangler/) | Ignore wrangler temp files |
.gitattributes | LFS tracking for HTML |
Live URL: https://rangebar-findings.terry-301.workers.dev/
After modifying this skill:
set -euo pipefailbash -n syntax check./references/...)| Issue | Cause | Solution |
|---|---|---|
op item get returns masked | Missing --reveal flag (CFW-03) | Add --reveal for CONCEALED fields |
op item create fails | Service account can't create (CFW-02) | Use biometric op or web UI to create item first |
| wrangler: config not found | Not in correct directory (CFW-10) | cd to directory containing wrangler.toml before deploy |
| SSL handshake failure | macOS LibreSSL (CFW-08) | Verify in browser; ignore curl errors |
| 403 on workers.dev URL | Subdomain not enabled (CFW-07) | Enable in Cloudflare dashboard > Workers & Pages |
| Deploy succeeds, files missing | LFS pointers deployed (CFW-12) | Run git lfs pull before deploy |
${var^^} syntax error | Bash 3 on macOS (CFW-05) | Use tr '[:lower:]' '[:upper:]' |
| mise TOML parse error | Tera template conflict (CFW-13) | Move complex bash to standalone .sh file |
| Empty index.html | No gen*/*.html files found | Check file paths match find . -path './gen*/*.html' pattern |
| Token permission denied | Wrong token scope (CFW-11) | Recreate with Account > Workers Scripts > Edit permission |
After this skill completes, reflect before closing the task:
Frequently asked questions
Deploy static HTML files (Bokeh charts, dashboards, reports) to Cloudflare Workers with Static Assets, using 1Password for credential management.
The source record exposes this install command: npx skills add https://github.com/terrylica/cc-skills --skill "plugins/devops-tools/skills/cloudflare-workers-publish". Inspect the command and pinned source before running it.
Static rules flagged exec-script, network, write-files in the source; the page lists the matching lines and excerpts.
Alternatives
vasilyu1983/AI-Agents-public
Guides iOS testing with XCTest, XCUITest, Swift Testing, simctl, and xcresult. Use when choosing destinations, controlling flakes, or parsing test artifacts for native apps.
garrytan/gbrain
Generate a publication-quality PDF from any brain page via the gstack make-pdf binary. Strips YAML frontmatter, sanitizes emoji, applies running headers and page numbers. Brain page is always the source of truth; PDF is a rendering.
NVIDIA/skills
How to swap the DeepStream CV detection model in the VSS Alerts Blueprint verification (2d_cv) mode - covers ONNX export, custom bbox parsers, compose mount gotchas, nvinfer config, runtime TRT engine build, deployment, and a segmentation-capable model addendum handoff.
vasilyu1983/AI-Agents-public
Scans public GitHub repos for agent skills, dev practices, and code patterns. Use when enriching skills, setting team policy, or researching a build domain.